Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Win32: Lmir - PG {RTK}  (Read 10893 times)

0 Members and 1 Guest are viewing this topic.

chriscool9

    Topic Starter


    Apprentice

    Thanked: 4
    • Experience: Beginner
    • OS: Mac OS
    Win32: Lmir - PG {RTK}
    « on: November 02, 2007, 01:20:33 PM »
    Hey guys,
    Basically I haven't been on my laptop for a good few days, and suddenly I get a message from my Avast! that basically tells me that I am infected with, Win32: Lmir - PG {RTK} (http://img256.imageshack.us/img256/2972/virusgb4.jpg). I haven't downloaded anything recently (bar a few MP3's using Frostwire), or not to my knowledge so it's a comeplete mystery as to how its got into my laptop.
    As for the virus I told Avast! to move it to the virus vault, and that is where it is currently hiding. Im running XP SP2, with Avast! for my anti virus. As for a firewall i just use the one built into the router.
    I have posted a HJT log for you to save time, just to see if it is still hiding somewhere.
    Also I know I should get the password's changed immediately, but what's the point if the virus is still on my laptop?!
    Thanks alot guys

    Chris

    99 Problems and London's one of them

    chriscool9

      Topic Starter


      Apprentice

      Thanked: 4
      • Experience: Beginner
      • OS: Mac OS
      Re: Win32: Lmir - PG {RTK}
      « Reply #1 on: November 02, 2007, 01:21:16 PM »
      Logfile of HijackThis v1.99.1
      Scan saved at 19:18:22, on 02/11/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5730.0011)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\System32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Acer\eManager\anbmServ.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\LogMeIn\x86\RaMaint.exe
      C:\Program Files\LogMeIn\x86\LogMeIn.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\UPHClean\uphclean.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\Arcade\PCMService.exe
      C:\Program Files\Launch Manager\QtZgAcer.EXE
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\WINDOWS\system32\Rundll32.exe
      C:\WINDOWS\system32\keyhook.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
      C:\Program Files\Multimedia Card Reader\shwicon2k.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\RocketDock\RocketDock.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\WINDOWS\system32\sistray.exe
      C:\Program Files\acer\eRecovery\Monitor.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Documents and Settings\Chris'\My Documents\My Downloads\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/weather/5day.shtml?id=3981
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      O1 - Hosts: 65.54.239.80 dp.msnmessenger.akadns.net
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O4 - HKLM\..\Run: [LaunchApp] Alaunch
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
      O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
      O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
      O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
      O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
      O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [\\SARAHS\EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P40 "\\SARAHS\EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
      O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX420 Series on SARAHS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P46 "Auto EPSON Stylus Photo RX420 Series on SARAHS" /O14 "\\SARAHS\Rx425" /M "Stylus Photo RX420"
      O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
      O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
      O4 - HKCU\..\Run: [] "C:\Program Files\Internet Explorer\csrss.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: KService - Unknown owner - C:\Program Files\KService\KService.exe (file missing)
      O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
      O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
      O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe


      99 Problems and London's one of them

      Broni


        Mastermind
      • Kraków my love :)
      • Thanked: 614
        • Computer Help Forum
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 8
      Re: Win32: Lmir - PG {RTK}
      « Reply #2 on: November 02, 2007, 07:05:00 PM »
      I'll take a look...

      Broni


        Mastermind
      • Kraków my love :)
      • Thanked: 614
        • Computer Help Forum
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 8
      Re: Win32: Lmir - PG {RTK}
      « Reply #3 on: November 02, 2007, 07:17:43 PM »
      First off all, you shouldn't rely on your router firewall only. It's not safe.
      I recommend, you install, free Comodo firewall:
      http://www.personalfirewall.comodo.com/

      Secondly, your HJT log is NOT clean. You have some infection(s).

      1. Print this post out, since you won't have an access to it, at some point.

      2. Download, and install Spybot (if you don't have it) from here: http://www.safer-networking.org/en/download/index.html

      3. Close all windows, except for HJT.

      4. Put a checkmark next to following HJT entries:

      - O1 - Hosts: 65.54.239.80 dp.msnmessenger.akadns.net

      - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

      - O4 - HKCU\..\Run: [] "C:\Program Files\Internet Explorer\csrss.exe"

      5. Click on "Fix It" button.

      6. Restart your computer in Safe Mode (F8)

      7. Run Spybot (click on updates, first), and fix whatever it asks you to fix.

      8. Open Windows Explorer. Go Tools>Folder Options, put a checkmark next to "Show hidden files, and folders".

      9. Delete following files (if they still exist):

      - csrss.exe from C:\Program Files\Internet Explorer\

      10. Turn off System Restore.

      11. Restart in Normal Mode.

      12. Turn System Restore on.

      13. Run HJT again, and post back its log back here.

      chriscool9

        Topic Starter


        Apprentice

        Thanked: 4
        • Experience: Beginner
        • OS: Mac OS
        Re: Win32: Lmir - PG {RTK}
        « Reply #4 on: November 04, 2007, 03:23:29 AM »
        Things just got a whole lot worse....
        I did what you told me to and then when I rebooted into Windows it just locks itself up. It takes forever to load up, and then after 2 minuites it becomes completely unresponsive. I am writing this in Safemode which seems pretty much ok, but my Ubuntu also is having serious problems.
        I really have no idea what to do, so anyhelp would be appreciated
        Thanks

        Chris

        99 Problems and London's one of them

        chriscool9

          Topic Starter


          Apprentice

          Thanked: 4
          • Experience: Beginner
          • OS: Mac OS
          Re: Win32: Lmir - PG {RTK}
          « Reply #5 on: November 04, 2007, 10:50:47 AM »
          Ok so after a bit more analysis it appears the laptop doesn't lock up but it's the Keyboard and Touch pad that both come unresponsive. Ive also tried a USB mouse but that still doesn't work. Any help appreciated.
          Thanks

          Chris

          99 Problems and London's one of them

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: Win32: Lmir - PG {RTK}
          « Reply #6 on: November 05, 2007, 11:05:20 PM »
          I apologize for no reply, but my computer was down. Please post new HJT log.

          chriscool9

            Topic Starter


            Apprentice

            Thanked: 4
            • Experience: Beginner
            • OS: Mac OS
            Re: Win32: Lmir - PG {RTK}
            « Reply #7 on: November 06, 2007, 11:10:46 AM »
            Logfile of HijackThis v1.99.1
            Scan saved at 18:10:10, on 06/11/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.5730.0011)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\System32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Acer\eManager\anbmServ.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\LogMeIn\x86\RaMaint.exe
            C:\Program Files\LogMeIn\x86\LogMeIn.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\UPHClean\uphclean.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
            C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
            C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\WINDOWS\system32\Rundll32.exe
            C:\WINDOWS\system32\keyhook.exe
            C:\Program Files\Arcade\PCMService.exe
            C:\Program Files\Launch Manager\QtZgAcer.EXE
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\WINDOWS\AGRSMMSG.exe
            C:\Program Files\RocketDock\RocketDock.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Windows Media Player\WMPNSCFG.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\MSN Messenger\msnmsgr.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Documents and Settings\Chris'\My Documents\My Downloads\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/weather/5day.shtml?id=3981
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
            O4 - HKLM\..\Run: [\\SARAHS\EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P40 "\\SARAHS\EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
            O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX420 Series on SARAHS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P46 "Auto EPSON Stylus Photo RX420 Series on SARAHS" /O14 "\\SARAHS\Rx425" /M "Stylus Photo RX420"
            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
            O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
            O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
            O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
            O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
            O4 - HKLM\..\Run: [LaunchApp] Alaunch
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
            O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
            O11 - Options group: [INTERNATIONAL] International*
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
            O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
            O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
            O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
            O23 - Service: KService - Unknown owner - C:\Program Files\KService\KService.exe (file missing)
            O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
            O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
            O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe


            99 Problems and London's one of them

            chriscool9

              Topic Starter


              Apprentice

              Thanked: 4
              • Experience: Beginner
              • OS: Mac OS
              Re: Win32: Lmir - PG {RTK}
              « Reply #8 on: November 06, 2007, 11:11:39 AM »
              Just out of interest, what 'nasties' did I have?!
              Thanks alot for all this!!

              Chris

              99 Problems and London's one of them

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Win32: Lmir - PG {RTK}
              « Reply #9 on: November 06, 2007, 01:22:44 PM »
              Is the computer still booting up wrong?

              Quote
              9. Delete following files (if they still exist):

              - csrss.exe from C:\Program Files\Internet Explorer\

              Quote
              Process File:  csrss.exe or csrss
              Process Name: Microsoft Client/Server Runtime Server Subsystem
              csrss.exe is the main executable for the Microsoft Client/Server Runtime Server Subsystem. This process manages most graphical commands in Windows. This program is important for the stable and secure running of your computer and should not be terminated.

              Quote
              10. Turn off System Restore.

              11. Restart in Normal Mode.

              12. Turn System Restore on.

              You had the user remove a possibly critical windows component, then wipe the restore points before knowing the system was stable.

              Quote
              Things just got a whole lot worse....
              I did what you told me to and then when I rebooted into Windows it just locks itself up.

              An infected Restore Point is better then NO restore point.

              C:\Documents and Settings\Chris'\My Documents\My Downloads\HijackThis.exe
              There should be a backup of everything removed in that folder. If needed you can restore the items removed and hopefully get back what is needed.

              chriscool9

                Topic Starter


                Apprentice

                Thanked: 4
                • Experience: Beginner
                • OS: Mac OS
                Re: Win32: Lmir - PG {RTK}
                « Reply #10 on: November 06, 2007, 03:34:55 PM »
                Yea it's still booting up wrong :(
                I found the restore CRSS.exe function so I have done that, let me boot into Normal Mode now. Ill give an update in a couple of minutes.
                Thanks

                Chris

                99 Problems and London's one of them

                chriscool9

                  Topic Starter


                  Apprentice

                  Thanked: 4
                  • Experience: Beginner
                  • OS: Mac OS
                  Re: Win32: Lmir - PG {RTK}
                  « Reply #11 on: November 06, 2007, 03:45:06 PM »
                  Still booting up wrong...
                  Maybe I should restore EVERYTHING I removed??
                  Thanks

                  Chris

                  99 Problems and London's one of them

                  evilfantasy

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Calm like a bomb
                  • Thanked: 493
                  • Experience: Experienced
                  • OS: Windows 11
                  Re: Win32: Lmir - PG {RTK}
                  « Reply #12 on: November 06, 2007, 03:50:20 PM »
                  Do you have your XP CD?

                  If so You should attempt a repair install. Instructions here: http://www.michaelstevenstech.com/XPrepairinstall.htm

                  Note: A Repair Install will replace the system files with the files on the XP CD used for the Repair Install. It will leave your applications and settings intact, but Windows updates will need to be reapplied.

                  A Repair Install will replace files altered by adware and malware, but will not fix an adware, malware problem. (if there)

                  Broni


                    Mastermind
                  • Kraków my love :)
                  • Thanked: 614
                    • Computer Help Forum
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 8
                  Re: Win32: Lmir - PG {RTK}
                  « Reply #13 on: November 06, 2007, 04:19:28 PM »
                  Quote
                  You had the user remove a possibly critical windows component
                  I don't know why you're often acting like you know everything better, but you are obviously wrong on this one.

                  The legitimate csrss.exe process is always located in the System (9x/Me) or System32 (NT/2K/XP)

                  Not in Program Files\Internet Explorer!

                  Broni


                    Mastermind
                  • Kraków my love :)
                  • Thanked: 614
                    • Computer Help Forum
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 8
                  Re: Win32: Lmir - PG {RTK}
                  « Reply #14 on: November 06, 2007, 04:21:38 PM »
                  Quote
                  I found the restore CRSS.exe function so I have done that
                  That O4 entry should remain removed!

                  Your problem lies somewhere else, and we'll have to find where.