Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Lurking Virus HTJ Log


  • Please log in to reply
4 replies to this topic

#1 dansun1222

dansun1222

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:04:49 PM

Posted 07 October 2005 - 09:18 AM

I have just spent a week trying to rid my computer of a virus that woudl survive a reformat of my computer. I woudl reformat it (using teh XP disc and deleting the C partition and installing a new in the empty spot) and when I booted up there would be the same virus/hacker tool. I had TASKESV and "windows drivers32" as services and my windows task manager would not work and the internet would not work.

Anyway I think I have gotten past that point, and now I am able to use my computer a bit, however at random seeming times, I feel another virus is kicking in. Task Manager no longer opens (although I can see it in the system tray) and the internet crashes. I have a HJT log for when this point happens, as well as from when I originally start up the computer. Any helpwould be greatly appreciaed. Thanks.

HJT Log immediatly after reboot:

Logfile of HijackThis v1.99.1
Scan saved at 7:10:16 AM, on 10/7/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\taskmgr.exe
C:\WINDOWS\System32\devldr32.exe
D:\Spyware\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1128608455867
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1128608908913
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

HJT Log after problems began (could no longer open websites/ task manager would not open. In fact, HJT crashes as it writes the log file, but I still get all of it I think)

Logfile of HijackThis v1.99.1
Scan saved at 7:05:58 AM, on 10/7/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\taskmgr.exe
D:\Spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1128608455867
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1128608908913
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

Thanks.



I have since had AVG and Norton detect viruses called "setup_22748.exe" and "eraseme_80274.exe" in my Windows/System32 folder.

I also ran Trend Microsystem's scanner and this is the log:


/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2005-10-06, 00:13:39, Auto-clean mode specified.
2005-10-06, 00:13:39, Running scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN"...
2005-10-06, 00:13:52, Scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN" has finished running.
2005-10-06, 00:13:52, TSC Log:

Damage Cleanup Engine (DCE) 3.9(Build 1020)
Windows XP(Build 2600: )

Start time : Thu Oct 06 2005 00:13:39

Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Administrator\Desktop\tsc.ptn" (version 660) [success]
TROJ_ROOTKIT.N[virus found]
-->delete registry key("HKEY_LOCAL_MACHINE","SYSTEM\CurrentControlSet\Services\hpdriver","") success
-->reboot delete file("C:\WINDOWS\system32\hpdriver.sys","","") success
TROJ_ROOTKIT.S[virus found]
-->delete registry key("HKEY_LOCAL_MACHINE","SYSTEM\CurrentControlSet\Services\remon","") success
-->reboot delete file("C:\WINDOWS\system32\remon.sys","","") success

Complete time : Thu Oct 06 2005 00:13:46
Execute pattern count(4419), Virus found count(2), Virus clean count(2), Clean failed count(0)

2005-10-06, 00:13:52, An error occurred while scanning file "C:\Documents and Settings\Administrator\NTUSER.DAT": Access is denied.
2005-10-06, 00:13:52, An error occurred while scanning file "C:\Documents and Settings\Administrator\ntuser.dat.LOG": Access is denied.
2005-10-06, 00:13:53, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 00:13:53, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\NTUSER.DAT": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\ntuser.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 00:14:37, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\AVG70FREE_344A618.EXE-08078EF3.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\CHCP.COM-18156052.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\EDJGZIBPCZH.EXE-2B50515D.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-0637684A.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MMC.EXE-04908CDF.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\ROOTKITREVEALER.EXE-2DB196BC.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-42C4EDF2.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.COM-34F56E5D.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.EXE-22393993.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.BIN-34D78FF4.pf": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Access is denied.
2005-10-06, 00:19:22, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-06, 00:25:27, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 00:19:23
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

C:\WINDOWS\system32\eraseme_04542.exe [WORM_SDBOT.CGY]
C:\WINDOWS\system32\eraseme_07708.exe [WORM_SDBOT.CGY]
C:\WINDOWS\system32\hpdriver.sys [TROJ_ROOTKIT.N]
C:\WINDOWS\system32\remon.sys [TROJ_ROOTKIT.S]
12997 files have been read.
12997 files have been checked.
11093 files have been scanned.
12426 files have been scanned. (including files in archived)
4 files containing viruses.
Found 4 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 00:25:27
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 00:25:27, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 00:19:23
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

Success Clean [ WORM_SDBOT.CGY]( 1) from C:\WINDOWS\system32\eraseme_04542.exe
Success Clean [ WORM_SDBOT.CGY]( 1) from C:\WINDOWS\system32\eraseme_07708.exe
Success Clean [ TROJ_ROOTKIT.N]( 1) from C:\WINDOWS\system32\hpdriver.sys
Success Clean [ TROJ_ROOTKIT.S]( 1) from C:\WINDOWS\system32\remon.sys
12997 files have been read.
12997 files have been checked.
11093 files have been scanned.
12426 files have been scanned. (including files in archived)
4 files containing viruses.
Found 4 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 00:25:27 6 minutes 3 seconds (362.86 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 00:25:27, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 00:19:23
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

12997 files have been read.
12997 files have been checked.
11093 files have been scanned.
12426 files have been scanned. (including files in archived)
4 files containing viruses.
Found 4 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 00:25:27 6 minutes 3 seconds (362.86 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 00:25:27, Scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN" has finished running.
2005-10-06, 01:07:51, An error was detected on "D:\System Volume Information\*.*": Access is denied.
2005-10-06, 01:19:13, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-06, 01:22:41, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 01:19:14
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11910 files have been read.
11910 files have been checked.
10638 files have been scanned.
12014 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 01:22:41
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 01:22:41, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 01:19:14
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11910 files have been read.
11910 files have been checked.
10638 files have been scanned.
12014 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 01:22:41 3 minutes 26 seconds (206.84 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 01:22:41, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 01:19:14
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11910 files have been read.
11910 files have been checked.
10638 files have been scanned.
12014 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 01:22:41 3 minutes 26 seconds (206.84 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 01:22:41, Scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN" has finished running.


/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2005-10-06, 20:01:32, Auto-clean mode specified.
2005-10-06, 20:01:32, Running scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN"...
2005-10-06, 20:02:35, Scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN" has finished running.
2005-10-06, 20:02:35, TSC Log:

2005-10-06, 20:02:39, An error occurred while scanning file "C:\Documents and Settings\Administrator\NTUSER.DAT": Access is denied.
2005-10-06, 20:02:39, An error occurred while scanning file "C:\Documents and Settings\Administrator\ntuser.dat.LOG": Access is denied.
2005-10-06, 20:04:27, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 20:04:27, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.


/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2005-10-07, 07:25:50, Auto-clean mode specified.
2005-10-07, 07:25:50, Running scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN"...
2005-10-07, 07:26:19, Scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN" has finished running.
2005-10-07, 07:26:19, TSC Log:

Damage Cleanup Engine (DCE) 3.9(Build 1020)
Windows XP(Build 2600: )

Start time : Fri Oct 07 2005 07:25:54

Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Administrator\Desktop\tsc.ptn" (version 660) [success]

Complete time : Fri Oct 07 2005 07:26:18
Execute pattern count(4419), Virus found count(0), Virus clean count(0), Clean failed count(0)

2005-10-07, 07:26:19, An error occurred while scanning file "C:\Documents and Settings\Administrator\NTUSER.DAT": Access is denied.
2005-10-07, 07:26:19, An error occurred while scanning file "C:\Documents and Settings\Administrator\ntuser.dat.LOG": Access is denied.
2005-10-07, 07:26:24, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-07, 07:26:24, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\NTUSER.DAT": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\ntuser.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-07, 07:30:32, Could not set file for reading on "C:\Program Files\Symantec AntiVirus\SAVRT\0391NAV~.TMP": Access is denied.
2005-10-07, 07:30:35, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVG70FREE_344A618.EXE-08078EF3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGAMSVR.EXE-13835775.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGCC.EXE-12C08071.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGEMC.EXE-0BA2F01F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGINET.EXE-3038B75E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGINET.EXE-3B0744C3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGSETUP.EXE-1C44C95B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGUPSVC.EXE-28C59C55.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGW.EXE-00A2F684.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGW.EXE-011FD837.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGWB.DAT-01D5CE53.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGWB.DAT-25B8DD3B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\BITSINST.EXE-2CB4826B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CCAPP.EXE-1207B2A5.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CCEVTMGR.EXE-24B7A008.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CCSETMGR.EXE-399BF976.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CHCP.COM-18156052.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFRAG.EXE-273F131E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFWATCH.EXE-072A5A71.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DEVLDR32.EXE-2CF621DF.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DRMUPGDS.EXE-145D2D37.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DWHWIZRD.EXE-1D638167.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\EDJGZIBPCZH.EXE-2B50515D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\FTP.EXE-0FFFB5A3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\GMAILINSTALLER.EXE-316701F3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\GNOTIFY.EXE-12E1F66C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-0637684A.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IDRIVER.EXE-20D017F5.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IDRIVERT.EXE-28903C83.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IE6.0-KB834707-WINDOWSXP-X86--3A7EF1B6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IPODSERVICE.EXE-3192DE38.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IS-SPILK.TMP-01BADAB9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNES.EXE-1A268432.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNESSETUP.EXE-0365EDA1.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNESSETUP.EXE-374DDAC8.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\JS56NEN.EXE-192922DD.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\KLMCODEC138.EXE-0C640055.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Layout.ini": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGAGENT.EXE-027AF92B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGON.SCR-151EFAEA.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LSETUP.EXE-0800EE26.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LUALL.EXE-2BCC229F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LUCOMS~1.EXE-02DB5950.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LUSETUP.EXE-3175C013.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MIGRATE.EXE-3A41124D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MMC.EXE-04908CDF.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MP10SETUP.EXE-2AD31E6C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MPLAYERC.EXE-06A9CBF3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSI76.TMP-30842353.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSI7D.TMP-28483EC4.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSIEXEC.EXE-2F8A8CAE.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q323255_X86_EN.EXE-18BCF5B9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329048_XP.EXE-0C05766F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329115_WXP_SP2_X86_ENU.EXE-041C661A.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329170_WXP_SP2_EN.EXE-0893FBE2.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329390_WXP.EXE-37C51BF6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329834_WXP_SP2_EN.EXE-05608540.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q810577_WXP_EN.EXE-15E35A2A.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q810833_WXP_SP2_X86_ENU.EXE-194F31C6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q811630_WXP_SP2_EN.EXE-1E639A55.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q817606_WXP_SP2_X86_ENU.EXE-0907B567.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QTPLUGININSTALLER.EXE-30539ABC.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QTTASK.EXE-085F7C4C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QTTASK.EXE-2FCE56F5.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QUICKTIMEINSTALLER.EXE-17CE5FD7.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QUICKTIMEPLAYER.EXE-221AD8B3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ROOTKITREVEALER.EXE-2DB196BC.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RTVSCAN.EXE-1D887DCC.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-26DA8C9B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-28EEC8F7.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-3DB12343.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-42C4EDF2.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-445649BB.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SAVCE_10.EXE-1F243F40.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP.EXE-02182199.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP_WM.EXE-0AB3B7DA.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SEVINST.EXE-1B62D49D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.COM-34F56E5D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.EXE-22393993.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\TASKMGR.EXE-20256C55.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.BIN-34D78FF4.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UNREGMP2.EXE-2D619A25.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-01EA7A76.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-06AB547E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-103B105E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-108BE778.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1129BF8E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1339A893.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1D175346.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1DA3AB04.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1E4F605C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-252B7790.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2726CBE7.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2A7C8836.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2BE3980D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-32F25CFE.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-35BBDDD6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-3B194009.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VIDCCLEANER.EXE-305CB5C8.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VPC32.EXE-2E9C8D92.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VPDN_LU.EXE-0A29B4CE.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VPTRAY.EXE-2D128BA2.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VSCANTM.BIN-0E7AF771.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB329441-X86-ENU.EX-32632D31.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB823559-X86-ENU.EX-1F644FC0.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB828741-X86-ENU.EX-0E012BC9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB835732-X86-ENU.EX-1F4E66F5.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WINPFIND.EXE-21186B3E.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-05601BEB.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-05CE4FB0.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-062AED92.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-06565957.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-08DB1F21.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-0AB8F0BC.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-12C8D73B.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-1580BBB0.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-27C02FA0.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-2A55B041.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-31E61C88.pf": Access is denied.
2005-10-07, 07:33:30, An error occurred while scanning file "C:\WINDOWS\system32\eraseme_80274.exe": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Access is denied.
2005-10-07, 07:42:23, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-07, 07:57:06, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 07:42:24
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

18618 files have been read.
18618 files have been checked.
15818 files have been scanned.
18209 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 07:57:06
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 07:57:06, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 07:42:24
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

18618 files have been read.
18618 files have been checked.
15818 files have been scanned.
18209 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 07:57:06 14 minutes 41 seconds (881.35 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 07:57:06, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 07:42:24
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

18618 files have been read.
18618 files have been checked.
15818 files have been scanned.
18209 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 07:57:06 14 minutes 41 seconds (881.35 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 07:57:06, Scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN" has finished running.
2005-10-07, 09:20:06, An error was detected on "D:\System Volume Information\*.*": Access is denied.
2005-10-07, 09:31:41, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-07, 09:36:23, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 09:31:43
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11911 files have been read.
11911 files have been checked.
10639 files have been scanned.
12015 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 09:36:23
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 09:36:23, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 09:31:43
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11911 files have been read.
11911 files have been checked.
10639 files have been scanned.
12015 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 09:36:23 4 minutes 40 seconds (279.86 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 09:36:23, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 09:31:43
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11911 files have been read.
11911 files have been checked.
10639 files have been scanned.
12015 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 09:36:23 4 minutes 40 seconds (279.86 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 09:36:23, Scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN" has finished running.

Edited by dansun1222, 07 October 2005 - 08:00 PM.


BC AdBot (Login to Remove)

 


#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:05:49 PM

Posted 14 October 2005 - 07:56 AM

Hello dansun1222 and welcome to the BC HijackThis forum. The first thing we need to do is update the operating system on this computer.

Your operating system is extremely out of date. By not keeping the OS updated the computer is vulnerable to every infection on the net and in emails today and trying to repair an unpatched system is virtually impossible. For update purposes, Microsoft has even stopped supporting a system that is this far out of date. Go to the Microsoft Windows XP Service Pack 1.a site and install Service Pack 1a.

Once that is done, go back to the Windows Update site and install all available Critical Updates but do not install SP2 at this time. This will patch the system with the most current security fixes and plug all the known holes which are present on this system. If you are not on a broadband connection the Service Pack can be obtained from Microsoft for a nominal shipping fee.

After all of the updates have been performed post a new HijackThis log back here using the Add Reply button and I will review it when it comes in.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#3 dansun1222

dansun1222
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:04:49 PM

Posted 16 October 2005 - 11:06 AM

Thanks OT for the help. I ran HJT, and also WinPFind (in safe mode). Logs are below:

Logfile of HijackThis v1.99.1
Scan saved at 8:06:12 AM, on 10/16/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\PROGRA~1\AIM95\aim.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\taskmgr.exe
D:\Spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1128608455867
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1128608908913
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe



WinPFind.exe (from safe mode) Log:

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

Windows OS and Versions
Product Name: Microsoft Windows XP Current Build: Service Pack 1 Current Build Number: 2600
Internet Explorer Version: 6.0.2800.1106

Checking Selected Standard Folders

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...

Checking %System% folder...
PEC2 8/23/2001 5:00:00 AM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
PTech 7/12/2005 6:04:22 PM 520456 C:\WINDOWS\SYSTEM32\LegitCheckControl.dll
PECompact2 10/2/2005 7:40:46 PM 2293088 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 10/2/2005 7:40:46 PM 2293088 C:\WINDOWS\SYSTEM32\MRT.exe
Umonitor 8/29/2002 3:41:10 AM 631808 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 8/23/2001 5:00:00 AM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu

Checking %System%\Drivers folder and sub-folders...
UPX! 10/6/2005 6:42:44 AM 726016 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
FSG! 10/6/2005 6:42:44 AM 726016 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
PEC2 10/6/2005 6:42:44 AM 726016 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
aspack 10/6/2005 6:42:44 AM 726016 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
10/14/2005 5:49:10 PM RHS 53807 C:\WINDOWS\80xFire.exe
10/16/2005 8:50:32 AM S 2048 C:\WINDOWS\bootstat.dat
10/5/2005 10:03:34 PM RH 749 C:\WINDOWS\WindowsShell.Manifest
10/15/2005 12:27:44 AM RHS 80384 C:\WINDOWS\windrvrs32.exe
10/5/2005 10:03:46 PM H 65 C:\WINDOWS\Downloaded Program Files\desktop.ini
10/5/2005 10:05:14 PM HS 67 C:\WINDOWS\Fonts\desktop.ini
10/6/2005 7:21:24 AM H 0 C:\WINDOWS\inf\oem0.inf
10/5/2005 10:03:46 PM H 65 C:\WINDOWS\Offline Web Pages\desktop.ini
10/5/2005 10:04:26 PM RHS 242478 C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1.cab
10/5/2005 10:04:26 PM RHS 19959 C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2.cab
10/5/2005 10:04:26 PM RHS 727 C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3.cab
10/14/2005 6:09:38 PM RHS 70111 C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_5.cab
10/14/2005 6:09:42 PM RHS 27774 C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_6.cab
10/5/2005 10:06:16 PM H 241664 C:\WINDOWS\repair\ntuser.dat
10/5/2005 10:03:34 PM RH 749 C:\WINDOWS\system32\cdplayer.exe.manifest
10/5/2005 10:03:46 PM RH 488 C:\WINDOWS\system32\logonui.exe.manifest
10/5/2005 10:03:34 PM RH 749 C:\WINDOWS\system32\ncpa.cpl.manifest
10/5/2005 10:03:34 PM RH 749 C:\WINDOWS\system32\nwc.cpl.manifest
10/5/2005 10:03:34 PM RH 749 C:\WINDOWS\system32\sapi.cpl.manifest
10/5/2005 10:03:46 PM RH 488 C:\WINDOWS\system32\WindowsLogon.manifest
10/5/2005 10:03:34 PM RH 749 C:\WINDOWS\system32\wuaucpl.cpl.manifest
10/4/2005 1:16:36 PM S 20086 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896688-IE6SP1-20051004.130236.cat
8/17/2005 7:19:32 PM S 11084 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB899589.cat
9/28/2005 11:53:30 AM S 17402 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB900725.cat
9/9/2005 7:15:08 PM S 11084 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB901017.cat
8/29/2005 9:25:44 PM S 11084 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB904706.cat
8/22/2005 11:48:28 AM S 11084 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB905414.cat
8/24/2005 7:03:20 PM S 9798 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB905495.cat
8/22/2005 9:03:36 PM S 11084 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB905749.cat
10/16/2005 8:50:24 AM H 8192 C:\WINDOWS\system32\config\default.LOG
10/16/2005 8:51:14 AM H 1024 C:\WINDOWS\system32\config\SAM.LOG
10/16/2005 8:50:34 AM H 12288 C:\WINDOWS\system32\config\SECURITY.LOG
10/16/2005 8:51:42 AM H 69632 C:\WINDOWS\system32\config\software.LOG
10/16/2005 8:50:36 AM H 823296 C:\WINDOWS\system32\config\system.LOG
10/5/2005 1:43:04 AM H 1024 C:\WINDOWS\system32\config\TempKey.LOG
10/5/2005 1:43:04 AM H 1024 C:\WINDOWS\system32\config\userdiff.LOG
10/15/2005 7:47:54 PM H 1024 C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
10/5/2005 1:44:48 AM HS 62 C:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini
10/5/2005 1:44:48 AM HS 62 C:\WINDOWS\system32\config\systemprofile\Local Settings\desktop.ini
10/5/2005 10:04:40 PM HS 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\desktop.ini
10/5/2005 10:04:40 PM HS 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\desktop.ini
10/5/2005 10:04:40 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini
10/5/2005 10:04:40 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini
10/5/2005 10:04:40 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ART2D48M\desktop.ini
10/5/2005 10:04:40 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\POOVXD0T\desktop.ini
10/5/2005 10:04:40 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\U6GX5QFW\desktop.ini
10/5/2005 10:04:40 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ZAUGJEZ4\desktop.ini
10/5/2005 10:03:50 PM HS 181 C:\WINDOWS\system32\config\systemprofile\SendTo\desktop.ini
10/5/2005 1:44:48 AM HS 62 C:\WINDOWS\system32\config\systemprofile\Start Menu\desktop.ini
10/5/2005 10:06:12 PM HS 206 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\desktop.ini
10/5/2005 10:06:12 PM HS 482 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\desktop.ini
10/5/2005 10:06:12 PM HS 348 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\desktop.ini
10/5/2005 10:06:12 PM HS 84 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Entertainment\desktop.ini
10/5/2005 10:06:12 PM HS 84 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini
10/15/2005 12:17:18 AM HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\5e58e453-4590-4826-afb7-b4cdc6d515dc
10/15/2005 12:17:18 AM HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\Preferred
10/14/2005 11:44:06 PM HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\2f6aaa97-fe7d-465f-8f22-ca06adca301d
10/14/2005 11:44:06 PM HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
10/16/2005 8:49:40 AM H 6 C:\WINDOWS\Tasks\SA.DAT

Checking for CPL files...
Microsoft Corporation 8/23/2001 5:00:00 AM 66048 C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation 8/29/2002 3:41:28 AM 578560 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 8/29/2002 3:41:28 AM 129024 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 150016 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 8/29/2002 3:41:28 AM 292352 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 8/29/2002 3:41:28 AM 121856 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 8/29/2002 3:41:28 AM 65536 C:\WINDOWS\SYSTEM32\joy.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 559616 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 256000 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
8/2/2005 4:35:00 PM 73728 C:\WINDOWS\SYSTEM32\nvtuicpl.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 36864 C:\WINDOWS\SYSTEM32\nwc.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 36864 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 109056 C:\WINDOWS\SYSTEM32\powercfg.cpl
Microsoft Corporation 8/29/2002 3:41:28 AM 268288 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 90112 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 5/26/2005 4:16:30 AM 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 66048 C:\WINDOWS\SYSTEM32\dllcache\access.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 150016 C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 187904 C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 559616 C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 256000 C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 36864 C:\WINDOWS\SYSTEM32\dllcache\nwc.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 36864 C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 109056 C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
Microsoft Corporation 8/23/2001 5:00:00 AM 90112 C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl

Checking Selected Startup Folders

Checking files in %ALLUSERSPROFILE%\Startup folder...
10/11/2005 9:34:58 PM 1762 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk
10/5/2005 10:06:12 PM HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini

Checking files in %ALLUSERSPROFILE%\Application Data folder...
10/5/2005 1:44:48 AM HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
10/10/2005 7:10:58 PM 1359 C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache

Checking files in %USERPROFILE%\Startup folder...
10/5/2005 10:06:12 PM HS 84 C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\desktop.ini

Checking files in %USERPROFILE%\Application Data folder...
10/5/2005 1:44:48 AM HS 62 C:\Documents and Settings\Administrator\Application Data\desktop.ini

Checking Selected Registry Keys

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG7 Shell Extension
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu
{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG7 Shell Extension
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu
{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
ButtonText = AOL Instant Messenger (SM) : C:\PROGRA~1\AIM95\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ButtonText = Messenger : C:\Program Files\Messenger\MSMSGS.EXE

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
Media Band = %SystemRoot%\System32\browseui.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
AVG7_CC C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
AVG7_EMC C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
ccApp "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
vptray C:\PROGRA~1\SYMANT~1\VPTray.exe
{0228e555-4f9c-4e35-a3ec-b109a192b4c2} C:\Program Files\Google\Gmail Notifier\gnotify.exe
iTunesHelper "C:\Program Files\iTunes\iTunesHelper.exe"
QuickTime Task "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
NvCplDaemon RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
nwiz nwiz.exe /install
NvMediaCenter RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
AIM C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
MSMSGS "C:\Program Files\Messenger\MSMSGS.EXE" /background

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = Explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon
= C:\WINDOWS\System32\NavLogon.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


Scan Complete
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 10/16/2005 9:00:00 AM

#4 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:05:49 PM

Posted 23 October 2005 - 08:32 AM

Hi dansun1222. Sorry for the delay. I don't see anything out of the ordinary in the HijackThis log. There are a couple of suspicious files showing in the WinPind log and we will hve those checked out.

But first, it appears that there are multiple anti-virus applications running on this computer. It is not recommended to have this because it can cause file access issues and if there is an infection the multiple programs can block each other from dealing with the infected file. I highly recommend that you choose which application you want to keep and uninstall the other one(s) to prevent these problems.

Next, go to the Jotti's malware scan page and use the buttons at the top of the page to browse to this file(s) on your hard drive to submit for a scan:C:\WINDOWS\80xFire.exe
C:\WINDOWS\windrvrs32.exe

Several scanning engines will be used to check the file for any threats. Please post the results of the scans back here.
Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#5 dansun1222

dansun1222
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:04:49 PM

Posted 24 October 2005 - 12:03 AM

Thanks OT,

The file called windrvrs32.exe was no longer on my computer, however the files called 80xfire.exe was very infected. Here was what came up with the website you recomended:

File: 80xFire.exe
Status: INFECTED/MALWARE
MD5 c7376b0af31fa1aba3f95e2b85e8723c
Packers detected: PE_PATCH, NSPACK
Scanner results
AntiVir Found nothing
ArcaVir Found Win32
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found Backdoor.SDBot.7508E9BB
ClamAV Found nothing
Dr.Web Found Win32.HLLW.MyBot.based
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found Backdoor.Win32.SdBot.aad
NOD32 Found a variant of IRC/SdBot
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found Embedded.Rootkit.Win32.Agent.p (probable variant)

I deleted it and it has not come back. I also ran panda active scan which detected a spybot.ftp (i forget the exact name), however it deleted that also. I thought i was good at this point, but the same one came back.

Again, it is a file that appears in "windows/system32" called "setup_******.exe" where the stars are random numbers. Norton detects it as "w32.spybot.worm" and generally does nothing during the first 3 detections and then manages to quarantine it on the forth. At this point I cannot acces hisotry in the internet browser and cannot direct the browser to a new site. (I can send myself an IM with a url and if I click that it brings me to where I want to go). I really hope you can help me because I am beginning to look into just getting a new computer (I need one soon anyway, but i don't want it to be becasue of a virus).

I have no problem with reformating the computer, however That hsa not worked with this virus when I tried it in the past. My method of reformating was to insert the Windows XP CD and then delete the existing partition and reformat in (full not quick) and then reinstall XP. I have a second harddrive that contains my movies and music. Is there anyway a virus could be surviving the reformat? It doesn't make sense that something could be coming off my D: drive, but i thought that reformating C: deletees everything. So I don't see how a virus could still be there when it started back up with the new OS.

Thanks,

Dan

Oh, new HJT this (doesn't say anything though).

Scan saved at 9:46:59 PM, on 10/23/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\PROGRA~1\AIM95\aim.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
D:\Spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1128608455867
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1128608908913
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users