Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Winantivir Remove Help! Here Are My Hijack Logs


  • This topic is locked This topic is locked
16 replies to this topic

#1 teo_stiletto_hun

teo_stiletto_hun

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 13 April 2007 - 07:30 AM

Somebody please tell me what to delete to remove WinAntiVir!!!
Thanks,
Teo

HERE ARE MY HIJACKTHIS LOGS:

SmitFraudFix v2.167

Scan done at 13:47:23,95, 2007.04.13.
Run from C:\Documents and Settings\Teo\Asztal\SmitfraudFix
OS: Microsoft Windows XP [verzi˘sz m: 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{6588A202-465B-4619-AFC6-A1165A60B82C}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{EFC92F18-8E56-4666-864D-EA5E0CC4E26D}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{6588A202-465B-4619-AFC6-A1165A60B82C}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{EFC92F18-8E56-4666-864D-EA5E0CC4E26D}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{6588A202-465B-4619-AFC6-A1165A60B82C}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{EFC92F18-8E56-4666-864D-EA5E0CC4E26D}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End






Logfile of HijackThis v1.99.1
Scan saved at 14:06:48, on 2007.04.13.
Platform: Windows XP Szervizcsomag 2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Gigabyte\Gigabyte 802.11b Wireless LAN\WlanMonitor.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\o2flash.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.worldlingo.com/wl/msoffice11?se...amp;lcidUI=1038
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hivatkozások
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\rmvanwel.dll",setvm
O4 - HKLM\..\Run: [SDTray] C:\Program Files\Spyware Doctor\SDTrayApp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Configuration & Monitor Utility.lnk = ?
O8 - Extra context menu item: E&xportálás Microsoft Excel formátumba - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Kutatás - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://neptun1.ppke.hu/msrdp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:09 PM

Posted 13 April 2007 - 07:50 AM

Welcome to the BleepingComputer HijackThis forum teo_stiletto_hun :thumbsup:

Please go to:
C:\Program Files\Hijackthis\HijackThis.exe
Right click on Hijackthis.exe and select 'Rename', rename it to abc.bat
Double click on abc.bat(which is still Hijackthis.exe),post that log into your next reply please.
Posted Image
Posted Image

#3 teo_stiletto_hun

teo_stiletto_hun
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 13 April 2007 - 07:57 AM

Hello Richie!
Thanks for Your quick reply! Here are the log generated by abc.bat.
Is there a chance to remove somehow the virus? :thumbsup:




Logfile of HijackThis v1.99.1
Scan saved at 14:52:15, on 2007.04.13.
Platform: Windows XP Szervizcsomag 2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Gigabyte\Gigabyte 802.11b Wireless LAN\WlanMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\o2flash.exe
C:\Documents and Settings\Teo\Asztal\VundoFix.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Hijackthis\abc.bat

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.worldlingo.com/wl/msoffice11?se...amp;lcidUI=1038
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hivatkozások
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\pmlboovu.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {7F5FFCB8-4838-43CD-80EA-A7EC9C744281} - C:\WINDOWS\system32\khfeecd.dll
O2 - BHO: (no name) - {8BE7FEE5-9DBF-4BEC-8750-0D52C66D7247} - C:\WINDOWS\system32\vtutu.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\rmvanwel.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Configuration & Monitor Utility.lnk = ?
O8 - Extra context menu item: E&xportálás Microsoft Excel formátumba - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Kutatás - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://neptun1.ppke.hu/msrdp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: khfeecd - C:\WINDOWS\SYSTEM32\khfeecd.dll
O20 - Winlogon Notify: vtutu - C:\WINDOWS\system32\vtutu.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:09 PM

Posted 13 April 2007 - 08:03 AM

Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
When VundoFix re-opens,click the "Scan for Vundo" button.
Once it's done scanning,click the "Remove Vundo" button.
You will receive a prompt asking if you want to remove the files, click "YES".
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed,it will prompt that it will reboot your computer,click "OK".
Please post the contents of C:\vundofix.txt into your next reply,along with a new Hijackthis log.

Note:
It is possible that VundoFix encountered a file it could not remove.
In this case,VundoFix will run on reboot,simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
Posted Image
Posted Image

#5 teo_stiletto_hun

teo_stiletto_hun
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 13 April 2007 - 08:16 AM

Thanks! (I still have an error message on reboot, it wants to run an rmvanwel.dll but it doesn't find it)

VUNDOFIX LOG:


VundoFix V6.3.19

Checking Java version...

Sun Java not detected
Scan started at 14:44:31 2007.04.13.

Listing files found while scanning....

C:\WINDOWS\system32\pmlboovu.dll
C:\WINDOWS\system32\ututv.bak1
C:\WINDOWS\system32\ututv.bak2
C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\ututv.tmp
C:\WINDOWS\system32\vtutu.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\pmlboovu.dll
C:\WINDOWS\system32\pmlboovu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.bak1
C:\WINDOWS\system32\ututv.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.bak2
C:\WINDOWS\system32\ututv.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\ututv.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.tmp
C:\WINDOWS\system32\ututv.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\system32\vtutu.dll Has been deleted!

Performing Repairs to the registry.
Done!

-------------------------------------------------------------------
ABC.BAT (HIJACKTHIS) LOG:


Logfile of HijackThis v1.99.1
Scan saved at 15:11:42, on 2007.04.13.
Platform: Windows XP Szervizcsomag 2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Gigabyte\Gigabyte 802.11b Wireless LAN\WlanMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\o2flash.exe
C:\WINDOWS\system32\wuauclt.exe
C:\totalcmd\TOTALCMD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\abc.bat

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.worldlingo.com/wl/msoffice11?se...amp;lcidUI=1038
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hivatkozások
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\pmlboovu.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {7F5FFCB8-4838-43CD-80EA-A7EC9C744281} - C:\WINDOWS\system32\khfeecd.dll
O2 - BHO: (no name) - {8BE7FEE5-9DBF-4BEC-8750-0D52C66D7247} - C:\WINDOWS\system32\vtutu.dll (file missing)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\rmvanwel.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Configuration & Monitor Utility.lnk = ?
O8 - Extra context menu item: E&xportálás Microsoft Excel formátumba - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Kutatás - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://neptun1.ppke.hu/msrdp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: khfeecd - C:\WINDOWS\SYSTEM32\khfeecd.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:09 PM

Posted 13 April 2007 - 08:20 AM

Download Avenger from the link below:
http://swandog46.geekstogo.com/avenger.zip
Unzip/extract it to your desktop.

Start up Avenger.
Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens,copy and paste ALL the following bold blue text in the Quote box below:


Files to delete:
C:\WINDOWS\SYSTEM32\khfeecd.dll

Then click on 'Done'.
Click the Traffic Light icon to start the program.
Then press OK at the prompts to reboot your PC.

Post the Avenger output.txt, which you can find at C:\Avenger\.txt into your next reply please.
Posted Image
Posted Image

#7 teo_stiletto_hun

teo_stiletto_hun
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 13 April 2007 - 08:35 AM

Thanks! Nothing changed yet. I use Firefox but IE pops up and on reboot the error message still shows.




Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\reyjetqg

*******************

Script file located at: \??\C:\Documents and Settings\pyeeiieg.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\SYSTEM32\khfeecd.dll deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

#8 teo_stiletto_hun

teo_stiletto_hun
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 13 April 2007 - 08:39 AM

IE pops up with the following link: http://89.188.16.10/trafc-2/rfe.php?cmp=vm...amp;affid=67308

#9 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:09 PM

Posted 13 April 2007 - 08:44 AM

Please make sure all hidden files are showing:

* Click 'Start'.
* Open 'My Computer'.
* Select the 'Tools' menu and click 'Folder Options'.
* Select the 'View' tab.
* Under the 'Hidden files and folders' heading select 'Show hidden files and folders'.
* Uncheck the 'Hide file extensions for known types' option.
* Uncheck the 'Hide protected operating system files (recommended)' option.
* Click Yes to confirm.
* Click OK.

*******************************

Download/install AVG Anti-Spyware 7.5.

Please follow these instructions very carefully.

Launch/start up AVG Anti-Spyware.
On the main page click the 'Update' tab,and then 'Start Update'.
Note:
If you have any problems running the update process prior to running the scan,download/install the 'Full Database' from here:
http://download.ewido.net/avgas-signatures-full-current.exe

Once the updates have been installed,do the following:
Select the 'Scanner' icon at the top of the screen, then select the 'Settings' tab.
Once in the 'Settings' screen,under 'How to act?',then under 'Set default action for detected malware to:', click on 'Recommended actions',then click on 'Quarantine'.
Under 'Reports' select 'Automatically generate report after every scan' and unselect 'Only if threats were found'.
Exit AVG Anti-Spyware,don't run the scan just yet.

You might want to print/copy the following as you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Have Hijack This fix the following [If still present], by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:

O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\pmlboovu.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {7F5FFCB8-4838-43CD-80EA-A7EC9C744281} - C:\WINDOWS\system32\khfeecd.dll
O2 - BHO: (no name) - {8BE7FEE5-9DBF-4BEC-8750-0D52C66D7247} - C:\WINDOWS\system32\vtutu.dll (file missing)
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\rmvanwel.dll",setvm
O20 - Winlogon Notify: khfeecd - C:\WINDOWS\SYSTEM32\khfeecd.dll


Find and delete if present:
C:\WINDOWS\system32\rmvanwel.dll

Still in Safe Mode launch AVG Anti-Spyware.
Click the 'Scanner' icon at the top.
To start the scan click on 'Complete System Scan'.
Please be patient,it takes a while for the scan to finish.

Once the scan is complete,do the following.
If AVG Anti-Spyware detected any infected objects:,click on 'Apply All Actions'.

Next click on 'Save Report'.
Copy and paste that report into your next reply.
The report can be found under the 'Reports' tab at the top.
Close AVG Anti-Spyware when you've done.
Reboot normally.

Post the AVG Anti Spyware report and a new Hijackthis log into your next reply.
Let me know how your pc is running now please.
Posted Image
Posted Image

#10 teo_stiletto_hun

teo_stiletto_hun
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 13 April 2007 - 10:30 AM

Hello!
THANKS, THANKS, THANKS FOR ALL! It seems to be OK my computer. No error message after reboot. Hopefully no more IE popups. Are we done?

Here are the reports:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 17:19:45 2007.04.13.

+ Scan result:



C:\System Volume Information\_restore{00D7CFD8-310C-44F6-8369-3324EA25B8D0}\RP72\A0011211.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\avenger\backup.zip/avenger/khfeecd.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Teo\Application Data\Mozilla\Firefox\Profiles\h6ytqua0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Documents and Settings\Teo\Application Data\Mozilla\Firefox\Profiles\h6ytqua0.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.43:C:\Documents and Settings\Teo\Application Data\Mozilla\Firefox\Profiles\h6ytqua0.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.
C:\Documents and Settings\Teo\Cookies\teo@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.35:C:\Documents and Settings\Teo\Application Data\Mozilla\Firefox\Profiles\h6ytqua0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.78:C:\Documents and Settings\Teo\Application Data\Mozilla\Firefox\Profiles\h6ytqua0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.44:C:\Documents and Settings\Teo\Application Data\Mozilla\Firefox\Profiles\h6ytqua0.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.45:C:\Documents and Settings\Teo\Application Data\Mozilla\Firefox\Profiles\h6ytqua0.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.52:C:\Documents and Settings\Teo\Application Data\Mozilla\Firefox\Profiles\h6ytqua0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Teo\Cookies\teo@search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
:mozilla.30:C:\Documents and Settings\Teo\Application Data\Mozilla\Firefox\Profiles\h6ytqua0.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Teo\Cookies\teo@skype[1].txt -> TrackingCookie.Skype : Cleaned.
:mozilla.54:C:\Documents and Settings\Teo\Application Data\Mozilla\Firefox\Profiles\h6ytqua0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.


::Report end

------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 17:23:01, on 2007.04.13.
Platform: Windows XP Szervizcsomag 2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Gigabyte\Gigabyte 802.11b Wireless LAN\WlanMonitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\o2flash.exe
C:\WINDOWS\system32\wuauclt.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Hijackthis\abc.bat

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.worldlingo.com/wl/msoffice11?se...amp;lcidUI=1038
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hivatkozások
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13931C5C-484C-4B02-A2ED-004F59D572A2} - C:\WINDOWS\system32\sstqr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Configuration & Monitor Utility.lnk = ?
O8 - Extra context menu item: E&xportálás Microsoft Excel formátumba - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Kutatás - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://neptun1.ppke.hu/msrdp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: sstqr - C:\WINDOWS\system32\sstqr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe

#11 teo_stiletto_hun

teo_stiletto_hun
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 13 April 2007 - 10:31 AM

I haven't found it:

"Find and delete if present:
C:\WINDOWS\system32\rmvanwel.dll"

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:09 PM

Posted 13 April 2007 - 11:14 AM

Double-click VundoFix.exe again to run it.
When VundoFix re-opens,click the "Scan for Vundo" button.
Once it's done scanning,click the "Remove Vundo" button.
You will receive a prompt asking if you want to remove the files, click "YES".
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed,it will prompt that it will reboot your computer,click "OK".
Please post the contents of C:\vundofix.txt into your next reply.

Note:
It is possible that VundoFix encountered a file it could not remove.
In this case,VundoFix will run on reboot,simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

*****************************

Please download Combofix and save to the desktop:
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the contents of C:\vundofix.txt,the C:\ComboFix.txt,and a new Hijackthis log into your next reply.
Note:
Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.

Posted Image
Posted Image

#13 teo_stiletto_hun

teo_stiletto_hun
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 15 April 2007 - 06:06 AM

HELLO, HERE ARE THE LOGS, I HAVE A NEW ERROR MESSAGE AT WINDOWS START-UP + STILL HAVE POPUP INTERNET EXPLORER WINDOWS



VundoFix V6.3.19

Checking Java version...

Sun Java not detected
Scan started at 14:44:31 2007.04.13.

Listing files found while scanning....

C:\WINDOWS\system32\pmlboovu.dll
C:\WINDOWS\system32\ututv.bak1
C:\WINDOWS\system32\ututv.bak2
C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\ututv.tmp
C:\WINDOWS\system32\vtutu.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\pmlboovu.dll
C:\WINDOWS\system32\pmlboovu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.bak1
C:\WINDOWS\system32\ututv.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.bak2
C:\WINDOWS\system32\ututv.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\ututv.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.tmp
C:\WINDOWS\system32\ututv.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\system32\vtutu.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.19

Checking Java version...

Sun Java not detected
Scan started at 11:21:51 2007.04.15.

Listing files found while scanning....

C:\WINDOWS\system32\hkcbrvmy.dll
C:\WINDOWS\system32\rqtss.bak1
C:\WINDOWS\system32\rqtss.bak2
C:\WINDOWS\system32\rqtss.ini
C:\WINDOWS\system32\sstqr.dll
C:\WINDOWS\system32\ymvrbckh.ini

Beginning removal...

Attempting to delete C:\WINDOWS\system32\hkcbrvmy.dll
C:\WINDOWS\system32\hkcbrvmy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rqtss.bak1
C:\WINDOWS\system32\rqtss.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\rqtss.bak2
C:\WINDOWS\system32\rqtss.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\rqtss.ini
C:\WINDOWS\system32\rqtss.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\sstqr.dll
C:\WINDOWS\system32\sstqr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ymvrbckh.ini
C:\WINDOWS\system32\ymvrbckh.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.19

Checking Java version...

Sun Java not detected
Scan started at 11:45:14 2007.04.15.

Listing files found while scanning....


VundoFix V6.3.19

Checking Java version...

Sun Java not detected
Scan started at 11:59:35 2007.04.15.

Listing files found while scanning....

No infected files were found.


Beginning removal...



----------------------------------------------------------------------------------------------------------------------

COMBOFIX

"Teo" - 07-04-15 12:36:26 Szervizcsomag 2
ComboFix 07-04-14.V - Running from: C:\Documents and Settings\Teo\Asztal\


((((((((((((((((((((((((((((((( Files Created from 2007-03-15 to 2007-04-15 ))))))))))))))))))))))))))))))))))


2007-04-13 16:06 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-13 15:30 <DIR> d-------- C:\avenger
2007-04-13 14:44 <DIR> d-------- C:\VundoFix Backups
2007-04-13 13:47 2,500 --a------ C:\WINDOWS\system32\tmp.reg
2007-04-13 13:36 524,288 --ah----- C:\DOCUME~1\RENDSZ~1\NTUSER.DAT
2007-04-13 13:36 <DIR> d--h----- C:\DOCUME~1\RENDSZ~1\Sablonok
2007-04-13 13:36 <DIR> d-------- C:\DOCUME~1\RENDSZ~1\Dokumentumok
2007-04-13 13:36 <DIR> d-------- C:\DOCUME~1\RENDSZ~1\Asztal
2007-04-12 17:22 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-04-12 17:03 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-04-09 00:46 108,144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-04-08 19:16 646,392 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-04-07 23:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-04-07 14:14 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Media Player Classic
2007-04-07 11:32 <DIR> d-------- C:\Program Files\DVD Shrink
2007-04-07 11:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-04-07 11:13 33,340 --------- C:\WINDOWS\system32\dbmsqlgc.dll
2007-04-07 11:13 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-04-07 11:13 24,576 --------- C:\WINDOWS\system32\dbmsgnet.dll
2007-04-07 11:13 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2007-04-07 11:04 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Sony Setup
2007-04-07 10:59 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Sony
2007-04-07 10:59 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Publish Providers
2007-04-07 10:52 <DIR> d-------- C:\Program Files\Vstplugins
2007-04-07 10:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony
2007-04-07 10:49 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\WinRAR
2007-04-07 00:25 <DIR> d-------- C:\Program Files\Sony Setup
2007-04-06 21:12 <DIR> d-------- C:\Program Files\mediaplayerclassic
2007-04-06 21:12 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\uTorrent
2007-04-05 13:45 <DIR> d-------- C:\OKIDATA
2007-04-03 10:53 21,656 --a------ C:\WINDOWS\system32\dopdfmn5.dll
2007-04-03 10:53 17,048 --a------ C:\WINDOWS\system32\dopdfmi5.dll
2007-04-03 10:52 <DIR> d-------- C:\Program Files\Softland
2007-04-02 23:47 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
2007-04-01 20:09 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-04-01 20:09 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
2007-04-01 19:11 <DIR> d-------- C:\Program Files\Funcom
2007-03-31 23:25 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-03-29 22:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
2007-03-29 13:40 <DIR> d-------- C:\Program Files\Creative Edge Studios, Inc
2007-03-29 13:38 <DIR> d---s---- C:\DOCUME~1\Teo\UserData
2007-03-29 13:33 <DIR> d-------- C:\Program Files\Prime95
2007-03-28 22:57 <DIR> d-------- C:\Program Files\KONAMI
2007-03-28 22:13 <DIR> d-------- C:\Program Files\Gotham Games
2007-03-28 21:38 <DIR> d-------- C:\Program Files\AdventurePinballDemo
2007-03-28 10:08 <DIR> d-------- C:\Program Files\Skype
2007-03-28 10:08 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-03-28 10:08 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Skype
2007-03-28 10:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
2007-03-25 17:46 <DIR> d-------- C:\Program Files\UNIWILL
2007-03-25 13:47 <DIR> d-------- C:\Program Files\Intel
2007-03-25 13:30 <DIR> d-------- C:\Program Files\Intel Corporation
2007-03-25 04:44 <DIR> d-------- C:\Program Files\Vstep
2007-03-25 04:19 86,016 --a------ C:\WINDOWS\system32\OpenAL32.dll
2007-03-25 04:19 262,144 --a------ C:\WINDOWS\system32\wrap_oal.dll
2007-03-25 04:18 5,632 --a------ C:\WINDOWS\system32\drivers\Entech64.sys
2007-03-25 04:18 3,972 --a------ C:\WINDOWS\system32\drivers\PciBus.sys
2007-03-25 04:18 21,664 --a------ C:\WINDOWS\system32\drivers\Entech.sys
2007-03-25 04:18 <DIR> d-------- C:\WINDOWS\system32\Futuremark
2007-03-25 04:16 <DIR> d-------- C:\Program Files\Futuremark
2007-03-25 03:37 <DIR> d-------- C:\Program Files\Lavasoft
2007-03-25 03:37 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Lavasoft
2007-03-25 03:36 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-03-25 03:17 180,224 --a------ C:\WINDOWS\system32\igfxres.dll
2007-03-25 03:15 57,344 --a------ C:\WINDOWS\system32\igxprd32.dll
2007-03-25 03:15 5,700,096 --a------ C:\WINDOWS\system32\drivers\igxpmp32.sys
2007-03-25 03:15 393,216 --a------ C:\WINDOWS\system32\igxpun.exe
2007-03-25 03:15 319,456 --a------ C:\WINDOWS\system32\difxapi.dll
2007-03-25 03:15 204,800 --a------ C:\WINDOWS\system32\igfxCoIn_v4785.dll
2007-03-25 03:15 2,555,904 --a------ C:\WINDOWS\system32\igxpdx32.dll
2007-03-25 03:15 149,504 --a------ C:\WINDOWS\system32\igxpgd32.dll
2007-03-25 03:15 1,612,576 --a------ C:\WINDOWS\system32\igxpdv32.dll
2007-03-25 03:14 <DIR> d-------- C:\Intel
2007-03-23 22:20 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2007-03-23 17:40 <DIR> d-------- C:\Program Files\pspvideo9
2007-03-23 17:40 <DIR> d-------- C:\Program Files\AviSynth 2.5
2007-03-23 17:39 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2007-03-23 11:57 <DIR> d-------- C:\Program Files\MSN Messenger
2007-03-23 11:28 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2007-03-23 11:27 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-03-23 11:27 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-03-23 09:26 <DIR> d-------- C:\Program Files\Kalypso
2007-03-23 04:46 <DIR> d-------- C:\Program Files\Sony
2007-03-23 04:31 <DIR> d-------- C:\Program Files\QuickTime
2007-03-23 04:31 <DIR> d-------- C:\Program Files\Apple Software Update
2007-03-23 04:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-03-23 04:24 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-03-23 04:24 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-03-23 04:24 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-03-23 04:24 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-03-23 04:24 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2007-03-23 04:24 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
2007-03-23 04:24 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-03-23 04:24 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2007-03-23 04:24 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-03-23 04:24 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2007-03-23 04:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-03-23 03:37 <DIR> d-------- C:\Program Files\Gaim
2007-03-23 03:37 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-03-23 03:21 2,433,024 --------- C:\WINDOWS\UNNMP.exe
2007-03-23 03:18 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-03-23 03:15 24,064 --------- C:\WINDOWS\system32\msxml3a.dll
2007-03-23 03:14 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-03-23 03:14 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-03-23 03:14 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-03-23 03:14 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2007-03-23 03:14 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-03-23 03:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-03-23 03:13 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-03-23 03:13 <DIR> d-------- C:\Program Files\Ahead
2007-03-23 02:27 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-03-23 02:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
2007-03-23 01:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2007-03-23 01:31 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-03-23 01:30 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-03-23 01:30 <DIR> d-------- C:\Program Files\Microsoft Works
2007-03-23 01:04 <DIR> d-------- C:\Program Files\AC3Filter
2007-03-23 00:55 <DIR> d-------- C:\Program Files\CyberLink
2007-03-23 00:52 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-03-23 00:35 90,368 --a------ C:\WINDOWS\system32\drivers\GNWLMM11.sys
2007-03-23 00:35 87,168 --a------ C:\WINDOWS\system32\drivers\GBM11USB.sys
2007-03-23 00:35 61,440 --a------ C:\WINDOWS\system32\W32N50.dll
2007-03-23 00:35 16,068 --a------ C:\WINDOWS\system32\PCANDIS5.SYS
2007-03-23 00:35 <DIR> d-------- C:\Program Files\Gigabyte
2007-03-23 00:24 <DIR> d-------- C:\Program Files\Winamp
2007-03-23 00:09 36,624 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-03-23 00:09 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-03-23 00:09 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-03-23 00:09 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-03-23 00:09 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-03-23 00:09 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-03-23 00:09 <DIR> d-------- C:\Program Files\Google
2007-03-23 00:09 <DIR> d-------- C:\Program Files\DivX
2007-03-22 22:56 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-03-22 22:50 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-03-22 22:50 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-03-22 20:24 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-03-22 20:15 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-03-22 20:15 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-03-22 20:13 63,592 --a------ C:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\Contacts
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\RadLight Company
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Jasc Software Inc
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Help
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\gtk-2.0
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Google
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Flickr
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\DivX
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\BSplayer Pro
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\BSplayer
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Apple Computer
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Adobe
2007-03-22 20:10 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\.gaim
2007-03-22 19:36 <DIR> d-------- C:\temp
2007-03-22 19:30 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Talkback
2007-03-22 19:16 4,314 --a------ C:\WINDOWS\mozver.dat
2007-03-22 19:16 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2007-03-22 19:16 <DIR> d-------- C:\DOCUME~1\Teo\APPLIC~1\Thunderbird
2007-03-22 19:10 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-03-22 19:10 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-03-22 19:08 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-03-22 19:07 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys
2007-03-22 19:07 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2007-03-22 19:07 57,728 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-03-22 19:07 14,080 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys
2007-03-22 19:07 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys
2007-03-22 19:06 76,288 --a------ C:\WINDOWS\system32\usbui.dll
2007-03-22 19:05 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2007-03-22 19:05 9,008 --a------ C:\WINDOWS\system\VER.DLL
2007-03-22 19:05 85,532 --a------ C:\WINDOWS\system32\dgsetup.dll
2007-03-22 19:05 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL
2007-03-22 19:05 8,704 --a------ C:\WINDOWS\system32\batt.dll
2007-03-22 19:05 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2007-03-22 19:05 75,776 --a------ C:\WINDOWS\system32\storprop.dll
2007-03-22 19:05 70,048 --a------ C:\WINDOWS\system\AVICAP.DLL
2007-03-22 19:05 7,168 --a------ C:\WINDOWS\system32\kbdcz.dll
2007-03-22 19:05 69,632 --a------ C:\WINDOWS\system32\TIFmtA.dll
2007-03-22 19:05 69,632 --a------ C:\WINDOWS\NOTEPAD.EXE
2007-03-22 19:05 69,184 --a------ C:\WINDOWS\system\MMSYSTEM.DLL
2007-03-22 19:05 61,440 --a------ C:\WINDOWS\system32\TrackID.DLL
2007-03-22 19:05 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2007-03-22 19:05 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll
2007-03-22 19:05 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll
2007-03-22 19:05 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll
2007-03-22 19:05 6,656 --a------ C:\WINDOWS\system32\kbdpl.dll
2007-03-22 19:05 6,656 --a------ C:\WINDOWS\system32\kbdcz2.dll
2007-03-22 19:05 6,656 --a------ C:\WINDOWS\system32\kbdcz1.dll
2007-03-22 19:05 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll
2007-03-22 19:05 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL
2007-03-22 19:05 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2007-03-22 19:05 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2007-03-22 19:05 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2007-03-22 19:05 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2007-03-22 19:05 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2007-03-22 19:05 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2007-03-22 19:05 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2007-03-22 19:05 53,248 --a------ C:\WINDOWS\system32\RIC619PI.DLL
2007-03-22 19:05 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2007-03-22 19:05 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2007-03-22 19:05 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2007-03-22 19:05 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2007-03-22 19:05 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2007-03-22 19:05 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2007-03-22 19:05 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2007-03-22 19:05 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2007-03-22 19:05 5,632 --a------ C:\WINDOWS\system32\kbdro.dll
2007-03-22 19:05 5,632 --a------ C:\WINDOWS\system32\kbdpl1.dll
2007-03-22 19:05 5,120 --a------ C:\WINDOWS\system\SHELL.DLL
2007-03-22 19:05 49,664 --a------ C:\WINDOWS\system32\RIC619X.EXE
2007-03-22 19:05 49,152 --a------ C:\WINDOWS\system32\TIBase64.dll
2007-03-22 19:05 33,392 --a------ C:\WINDOWS\system\COMMDLG.DLL
2007-03-22 19:05 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-03-22 19:05 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL
2007-03-22 19:05 19,200 --a------ C:\WINDOWS\system\TAPI.DLL
2007-03-22 19:05 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2007-03-22 19:05 15,360 --a------ C:\WINDOWS\TASKMAN.EXE
2007-03-22 19:05 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-03-22 19:05 126,912 --a------ C:\WINDOWS\system\MSVIDEO.DLL
2007-03-22 19:05 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2007-03-22 19:05 109,504 --a------ C:\WINDOWS\system\AVIFILE.DLL
2007-03-22 19:05 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2007-03-22 19:05 0 --a------ C:\WINDOWS\nsreg.dat
2007-03-22 19:05 <DIR> dr------- C:\Program Files
2007-03-22 19:05 <DIR> dr------- C:\DOCUME~1\ALLUSE~1\Dokumentumok
2007-03-22 19:05 <DIR> d--hs---- C:\WINDOWS\Installer
2007-03-22 19:05 <DIR> d--h----- C:\DOCUME~1\DEFAUL~1\Sablonok
2007-03-22 19:05 <DIR> d--h----- C:\DOCUME~1\ALLUSE~1\Sablonok
2007-03-22 19:05 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2007-03-22 19:05 <DIR> d-------- C:\WINDOWS\system32\CatRoot
2007-03-22 19:05 <DIR> d-------- C:\Program Files\Common Files\SpeechEngines
2007-03-22 19:05 <DIR> d-------- C:\Program Files\Common Files\ODBC
2007-03-22 19:05 <DIR> d-------- C:\Download
2007-03-22 19:05 <DIR> d-------- C:\DOCUME~1\DEFAUL~1\Dokumentumok
2007-03-22 19:05 <DIR> d-------- C:\DOCUME~1\DEFAUL~1\Asztal
2007-03-22 19:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Asztal
2007-03-22 19:04 545 --a------ C:\WINDOWS\UC.PIF
2007-03-22 19:04 545 --a------ C:\WINDOWS\RAR.PIF
2007-03-22 19:04 545 --a------ C:\WINDOWS\PKZIP.PIF
2007-03-22 19:04 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2007-03-22 19:04 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2007-03-22 19:04 545 --a------ C:\WINDOWS\LHA.PIF
2007-03-22 19:04 545 --a------ C:\WINDOWS\ARJ.PIF
2007-03-22 19:04 <DIR> d-------- C:\totalcmd
2007-03-22 19:04 <DIR> d-------- C:\Documents and Settings
2007-03-22 19:02 <DIR> d--hs---- C:\System Volume Information
2007-03-22 18:57 <DIR> dr-hsc--- C:\WINDOWS\system32\dllcache
2007-03-22 18:57 <DIR> dr--s---- C:\WINDOWS\Fonts
2007-03-22 18:57 <DIR> dr------- C:\WINDOWS\Web
2007-03-22 18:57 <DIR> d--h----- C:\WINDOWS\inf
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\WinSxS
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\twain_32
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\wins
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\wbem
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\usmt
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\spool
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\ShellExt
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\Setup
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\ras
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\oobe
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\npp
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\mui
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\inetsrv
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\IME
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\icsxml
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\ias
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\export
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\drivers\etc
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\drivers\disdn
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\drivers
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\dhcp
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\config
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\3com_dmi
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\3076
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\2052
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\1054
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\1042
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\1041
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\1038
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\1037
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\1033
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\1031
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\1028
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32\1025
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system32
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\system
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\security
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\Resources
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\repair
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\Provisioning
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\PeerNet
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\pchealth
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\mui
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\msapps
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\msagent
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\Media
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\java
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\ime
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\Help
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\ehome
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\Driver Cache
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\Debug
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\Cursors
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\Connection Wizard
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\Config
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\AppPatch
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS\addins
2007-03-22 18:57 <DIR> d-------- C:\WINDOWS
2007-03-22 18:56 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-03-22 18:51 483,328 -ra------ C:\WINDOWS\system32\w39NCPA.dll
2007-03-22 18:51 2,600,960 -ra------ C:\WINDOWS\system32\w39MLRes.dll
2007-03-22 18:51 1,428,096 -ra------ C:\WINDOWS\system32\drivers\w39n51.sys
2007-03-22 18:50 90,201 --a------ C:\WINDOWS\system32\SynTPAPI.dll
2007-03-22 18:50 82,012 --a------ C:\WINDOWS\system32\SynCOM.dll
2007-03-22 18:50 81,920 --a------ C:\WINDOWS\system32\SynTPCo2.dll
2007-03-22 18:50 69,721 --a------ C:\WINDOWS\system32\SynTPFcs.dll
2007-03-22 18:50 191,168 --a------ C:\WINDOWS\system32\drivers\SynTP.sys
2007-03-22 18:50 114,688 --a------ C:\WINDOWS\system32\SynCtrl.dll
2007-03-22 18:50 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-03-22 18:50 <DIR> d-------- C:\WINDOWS\system32\ReinstallBackups
2007-03-22 18:50 <DIR> d-------- C:\Program Files\Synaptics
2007-03-22 18:48 <DIR> d-------- C:\WINDOWS\system32\Lang
2007-03-22 18:48 <DIR> d-------- C:\Program Files\Marvell
2007-03-22 18:47 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-03-22 18:47 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-03-22 18:47 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-03-22 18:47 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-03-22 18:47 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-03-22 18:47 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-03-22 18:47 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-03-22 18:47 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-03-22 18:47 49,152 -r------- C:\WINDOWS\system32\ChCfg.exe
2007-03-22 18:47 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-03-22 18:47 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-03-22 18:47 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-03-22 18:47 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-03-22 18:47 143,360 -r------- C:\WINDOWS\system32\RtlCPAPI.dll
2007-03-22 18:47 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-03-22 18:47 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2007-03-22 18:46 9,709,568 -r------- C:\WINDOWS\RTLCPL.exe
2007-03-22 18:46 86,016 -r------- C:\WINDOWS\SoundMan.exe
2007-03-22 18:46 4,368,896 -r------- C:\WINDOWS\system32\drivers\RtkHDAud.Sys
2007-03-22 18:46 364,544 -r------- C:\WINDOWS\RtlUpd.exe
2007-03-22 18:46 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-03-22 18:46 2,879,488 -r------- C:\WINDOWS\SkyTel.exe
2007-03-22 18:46 2,158,592 -r------- C:\WINDOWS\MicCal.exe
2007-03-22 18:46 16,050,176 -r------- C:\WINDOWS\RTHDCPL.exe
2007-03-22 18:45 69,632 -r------- C:\WINDOWS\Alcmtr.exe
2007-03-22 18:45 487,424 -r------- C:\WINDOWS\RtlExUpd.dll
2007-03-22 18:45 2,808,832 -r------- C:\WINDOWS\alcwzrd.exe
2007-03-22 18:45 <DIR> d-------- C:\Program Files\Realtek
2007-03-22 18:41 956,026 -ra------ C:\WINDOWS\system32\ialmdd5.dll
2007-03-22 18:41 61,440 -ra------ C:\WINDOWS\system32\iAlmCoIn_v4543.dll
2007-03-22 18:41 528,384 --a------ C:\WINDOWS\system32\igfxcfg.exe
2007-03-22 18:41 49,152 -ra------ C:\WINDOWS\system32\ialmrem.dll
2007-03-22 18:41 47,616 --a------ C:\WINDOWS\system32\igfxsrvc.dll
2007-03-22 18:41 450,560 --a------ C:\WINDOWS\system32\igldev32.dll
2007-03-22 18:41 45,694 -ra------ C:\WINDOWS\system32\ialmrnt5.dll
2007-03-22 18:41 3,293,184 --a------ C:\WINDOWS\system32\igfxress.dll
2007-03-22 18:41 245,760 --a------ C:\WINDOWS\system32\igfxsrvc.exe
2007-03-22 18:41 24,576 --a------ C:\WINDOWS\system32\igfxexps.dll
2007-03-22 18:41 238,650 -ra------ C:\WINDOWS\system32\ialmdev5.dll
2007-03-22 18:41 204,800 --a------ C:\WINDOWS\system32\igfxdev.dll
2007-03-22 18:41 200,704 --a------ C:\WINDOWS\system32\igfxpph.dll
2007-03-22 18:41 2,334,720 --a------ C:\WINDOWS\system32\iglicd32.dll
2007-03-22 18:41 163,840 --a------ C:\WINDOWS\system32\igfxzoom.exe
2007-03-22 18:41 159,744 --a------ C:\WINDOWS\system32\igfxext.exe
2007-03-22 18:41 155,648 --a------ C:\WINDOWS\system32\hkcmd.exe
2007-03-22 18:41 135,168 --a------ C:\WINDOWS\system32\igfxdo.dll
2007-03-22 18:41 131,072 --a------ C:\WINDOWS\system32\igfxtray.exe
2007-03-22 18:41 131,072 --a------ C:\WINDOWS\system32\igfxpers.exe
2007-03-22 18:41 121,467 -ra------ C:\WINDOWS\system32\ialmdnt5.dll
2007-03-22 18:41 102,400 --a------ C:\WINDOWS\system32\hccutils.dll
2007-03-22 18:41 1,166,972 -ra------ C:\WINDOWS\system32\drivers\ialmnt5.sys
2007-03-22 18:34 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-03-22 18:34 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-03-22 18:31 <DIR> d--hs---- C:\RECYCLER
2007-03-22 18:29 3,932,160 --ah----- C:\DOCUME~1\Teo\NTUSER.DAT
2007-03-22 18:29 <DIR> dr------- C:\DOCUME~1\Teo\Dokumentumok
2007-03-22 18:29 <DIR> d--h----- C:\DOCUME~1\Teo\Sablonok
2007-03-22 18:29 <DIR> d-------- C:\DOCUME~1\Teo\Asztal
2007-03-22 18:28 786,432 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT
2007-03-22 18:28 786,432 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT
2007-03-22 18:28 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-03-22 18:28 <DIR> d-------- C:\WINDOWS\Prefetch
2007-03-22 18:25 229,376 --ah----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT
2007-03-22 18:25 0 -rahs---- C:\MSDOS.SYS
2007-03-22 18:25 0 -rahs---- C:\IO.SYS
2007-03-22 18:25 0 --a------ C:\CONFIG.SYS
2007-03-22 18:25 0 --a------ C:\AUTOEXEC.BAT
2007-03-22 18:25 <DIR> d-------- C:\WINDOWS\system32\xircom
2007-03-22 18:25 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-03-22 18:24 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2007-03-22 18:24 <DIR> dr------- C:\WINDOWS\Offline Web Pages
2007-03-22 18:24 <DIR> d--hs---- C:\DOCUME~1\ALLUSE~1\DRM
2007-03-22 18:24 <DIR> d---s---- C:\WINDOWS\Downloaded Program Files
2007-03-22 18:23 65,536 --a------ C:\WINDOWS\system32\acctres.dll
2007-03-22 18:23 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2007-03-22 18:23 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2007-03-22 18:23 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2007-03-22 18:23 <DIR> d--h----- C:\Program Files\WindowsUpdate
2007-03-22 18:23 <DIR> d---s---- C:\WINDOWS\Tasks
2007-03-22 18:23 <DIR> d-------- C:\WINDOWS\system32\DirectX
2007-03-22 18:23 <DIR> d-------- C:\Program Files\Online Services
2007-03-22 18:23 <DIR> d-------- C:\Program Files\Common Files\MSSoap
2007-03-22 18:22 86,016 --a------ C:\WINDOWS\system32\isign32.dll
2007-03-22 18:22 81,920 --a------ C:\WINDOWS\system32\ils.dll
2007-03-22 18:22 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2007-03-22 18:22 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2007-03-22 18:22 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys
2007-03-22 18:22 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2007-03-22 18:22 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2007-03-22 18:22 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-03-22 18:22 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2007-03-22 18:22 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2007-03-22 18:22 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2007-03-22 18:22 49,152 --a------ C:\WINDOWS\system32\inetres.dll
2007-03-22 18:22 465,688 --a------ C:\WINDOWS\system32\wuapi.dll
2007-03-22 18:22 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2007-03-22 18:22 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2007-03-22 18:22 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2007-03-22 18:22 41,240 --a------ C:\WINDOWS\system32\wups.dll
2007-03-22 18:22 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2007-03-22 18:22 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2007-03-22 18:22 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2007-03-22 18:22 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2007-03-22 18:22 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2007-03-22 18:22 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2007-03-22 18:22 278,528 --a------ C:\WINDOWS\system32\inetcfg.dll
2007-03-22 18:22 278,016 --a------ C:\WINDOWS\system32\mstask.dll
2007-03-22 18:22 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2007-03-22 18:22 241,152 --a------ C:\WINDOWS\system32\srrstr.dll
2007-03-22 18:22 23,040 --a------ C:\WINDOWS\system32\fltmc.exe
2007-03-22 18:22 21,948 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-03-22 18:22 195,352 --a------ C:\WINDOWS\system32\wuaueng1.dll
2007-03-22 18:22 192,000 --a------ C:\WINDOWS\system32\schedsvc.dll
2007-03-22 18:22 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-03-22 18:22 174,872 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-03-22 18:22 173,536 --a------ C:\WINDOWS\system32\wuweb.dll
2007-03-22 18:22 171,008 --a------ C:\WINDOWS\system32\srsvc.dll
2007-03-22 18:22 16,896 --a------ C:\WINDOWS\system32\fltlib.dll
2007-03-22 18:22 128,896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2007-03-22 18:22 127,768 --a------ C:\WINDOWS\system32\wucltui.dll
2007-03-22 18:22 125,208 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-03-22 18:22 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2007-03-22 18:22 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2007-03-22 18:22 1,343,768 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-03-22 18:22 <DIR> d-------- C:\WINDOWS\system32\Restore
2007-03-22 18:22 <DIR> d-------- C:\WINDOWS\system32\Macromed
2007-03-22 18:22 <DIR> d-------- C:\WINDOWS\srchasst
2007-03-22 18:22 <DIR> d-------- C:\Program Files\Movie Maker
2007-03-22 18:21 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2007-03-22 18:21 80,896 --a------ C:\WINDOWS\system32\charmap.exe
2007-03-22 18:21 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2007-03-22 18:21 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2007-03-22 18:21 56,832 --a------ C:\WINDOWS\system32\sol.exe
2007-03-22 18:21 55,808 --a------ C:\WINDOWS\system32\freecell.exe
2007-03-22 18:21 54,272 --a------ C:\WINDOWS\system32\stclient.dll
2007-03-22 18:21 5,632 --a------ C:\WINDOWS\system32\write.exe
2007-03-22 18:21 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2007-03-22 18:21 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2007-03-22 18:21 4,096 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2007-03-22 18:21 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2007-03-22 18:21 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2007-03-22 18:21 33,792 --a------ C:\WINDOWS\system32\regini.exe
2007-03-22 18:21 25,600 --a------ C:\WINDOWS\system32\comaddin.dll
2007-03-22 18:21 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll
2007-03-22 18:21 230,400 --a------ C:\WINDOWS\system32\avtapi.dll
2007-03-22 18:21 23,040 --a------ C:\WINDOWS\system32\msg.exe
2007-03-22 18:21 22,528 --a------ C:\WINDOWS\system32\qwinsta.exe
2007-03-22 18:21 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll
2007-03-22 18:21 17,408 --a------ C:\WINDOWS\system32\tsshutdn.exe
2007-03-22 18:21 17,408 --a------ C:\WINDOWS\system32\qappsrv.exe
2007-03-22 18:21 16,896 --a------ C:\WINDOWS\system32\rwinsta.exe
2007-03-22 18:21 16,384 --a------ C:\WINDOWS\system32\tskill.exe
2007-03-22 18:21 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2007-03-22 18:21 15,872 --a------ C:\WINDOWS\system32\tscon.exe
2007-03-22 18:21 15,872 --a------ C:\WINDOWS\system32\logoff.exe
2007-03-22 18:21 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2007-03-22 18:21 15,360 --a------ C:\WINDOWS\system32\tsdiscon.exe
2007-03-22 18:21 15,360 --a------ C:\WINDOWS\system32\shadow.exe
2007-03-22 18:21 147,456 --a------ C:\WINDOWS\system32\comsnap.dll
2007-03-22 18:21 139,264 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-03-22 18:21 127,488 --a------ C:\WINDOWS\system32\mshearts.exe
2007-03-22 18:21 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2007-03-22 18:21 114,688 --a------ C:\WINDOWS\system32\calc.exe
2007-03-22 18:21 10,240 --a------ C:\WINDOWS\system32\reset.exe
2007-03-22 18:21 1,161 --a------ C:\WINDOWS\system32\usrlogon.cmd
2007-03-22 18:21 <DIR> d-------- C:\WINDOWS\Registration
2007-03-22 18:21 <DIR> d-------- C:\Program Files\MSN Gaming Zone
2007-03-22 18:21 <DIR> d-------- C:\Program Files\Messenger
2007-03-22 18:20 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll
2007-03-22 18:20 94,208 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2007-03-22 18:20 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll
2007-03-22 18:20 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2007-03-22 18:20 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2007-03-22 18:20 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2007-03-22 18:20 655,360 --a------ C:\WINDOWS\system32\mstscax.dll
2007-03-22 18:20 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll
2007-03-22 18:20 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe
2007-03-22 18:20 61,440 --a------ C:\WINDOWS\system32\remotepg.dll
2007-03-22 18:20 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2007-03-22 18:20 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2007-03-22 18:20 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2007-03-22 18:20 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2007-03-22 18:20 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2007-03-22 18:20 540,160 --a------ C:\WINDOWS\system32\comuid.dll
2007-03-22 18:20 539,136 --a------ C:\WINDOWS\system32\spider.exe
2007-03-22 18:20 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2007-03-22 18:20 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe
2007-03-22 18:20 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll
2007-03-22 18:20 408,576 --a------ C:\WINDOWS\system32\mstsc.exe
2007-03-22 18:20 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2007-03-22 18:20 39,424 --a------ C:\WINDOWS\system32\cfgbkend.dll
2007-03-22 18:20 350,208 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-03-22 18:20 345,088 --a------ C:\WINDOWS\system32\mspaint.exe
2007-03-22 18:20 296,960 --a------ C:\WINDOWS\system32\termsrv.dll
2007-03-22 18:20 225,792 --a------ C:\WINDOWS\system32\catsrv.dll
2007-03-22 18:20 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys
2007-03-22 18:20 20,480 --a------ C:\WINDOWS\system32\qprocess.exe
2007-03-22 18:20 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2007-03-22 18:20 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2007-03-22 18:20 187,904 --a------ C:\WINDOWS\system32\accwiz.exe
2007-03-22 18:20 186,880 --a------ C:\WINDOWS\system32\cmprops.dll
2007-03-22 18:20 17,408 --a------ C:\WINDOWS\system32\mmfutil.dll
2007-03-22 18:20 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2007-03-22 18:20 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2007-03-22 18:20 142,336 --a------ C:\WINDOWS\system32\sessmgr.exe
2007-03-22 18:20 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2007-03-22 18:20 132,096 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-03-22 18:20 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2007-03-22 18:20 124,416 --a------ C:\WINDOWS\system32\mplay32.exe
2007-03-22 18:20 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys
2007-03-22 18:20 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2007-03-22 18:20 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2007-03-22 18:20 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2007-03-22 18:20 103,936 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-03-22 18:20 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
2007-03-22 18:20 <DIR> d-------- C:\WINDOWS\system32\MsDtc
2007-03-22 18:20 <DIR> d-------- C:\WINDOWS\system32\Com
2007-03-22 18:20 <DIR> d-------- C:\Program Files\Windows NT


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-09 03:18 97696 --a------ C:\WINDOWS\system32\perfc00e.dat
2007-04-09 03:18 424080 --a------ C:\WINDOWS\system32\perfh00e.dat
2007-03-17 15:45 293376 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-08 17:39 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:39 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:39 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:38 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-02-12 13:56 62 --ahs---- C:\DOCUME~1\Teo\APPLIC~1\desktop.ini
2007-02-05 22:20 185856 --a------ C:\WINDOWS\system32\upnphost.dll
2007-02-01 06:56 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-02-01 06:56 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-02-01 06:56 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-02-01 06:56 639066 --a------ C:\WINDOWS\system32\divx.dll
2007-01-31 23:27 524288 --a------ C:\WINDOWS\system32\divxsm.exe
2007-01-31 01:15 118784 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2007-01-30 07:03 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-01-30 07:03 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-01-30 07:03 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-01-30 06:56 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-01-30 06:56 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2007-01-30 06:56 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-01-30 06:56 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2007-01-30 06:56 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-01-30 06:56 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-01-30 06:56 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-01-30 06:56 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-01-19 13:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
{6531545E-9B6A-48D3-9C2E-699673436864} C:\WINDOWS\system32\sstqr.dll [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"RTHDCPL"="RTHDCPL.EXE"
"SkyTel"="SkyTel.EXE"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"nod32kui"="\"C:\\Program Files\\Eset\\nod32kui.exe\" /WAITSERVICE"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"Persistence"="C:\\WINDOWS\\system32\\igfxpers.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"PrintDrive"="rundll32.exe \"C:\\WINDOWS\\system32\\hkcbrvmy.dll\",setvm"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7F5FFCB8-4838-43CD-80EA-A7EC9C744281}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-15 12:37:43
C:\ComboFix-quarantined-files.txt ... 07-04-15 12:37


HIJACKTHIS

Logfile of HijackThis v1.99.1
Scan saved at 12:57:05, on 2007.04.15.
Platform: Windows XP Szervizcsomag 2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Gigabyte\Gigabyte 802.11b Wireless LAN\WlanMonitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\o2flash.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\abc.bat

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.worldlingo.com/wl/msoffice11?se...amp;lcidUI=1038
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hivatkozások
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6531545E-9B6A-48D3-9C2E-699673436864} - C:\WINDOWS\system32\sstqr.dll (file missing)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\hkcbrvmy.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Configuration & Monitor Utility.lnk = ?
O8 - Extra context menu item: E&xportálás Microsoft Excel formátumba - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Kutatás - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://neptun1.ppke.hu/msrdp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe

#14 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:09 PM

Posted 15 April 2007 - 06:27 AM

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - {6531545E-9B6A-48D3-9C2E-699673436864} - C:\WINDOWS\system32\sstqr.dll (file missing)
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\hkcbrvmy.dll",setvm

Exit Hijackthis.

Restart your pc,let me know how its running now please.
Posted Image
Posted Image

#15 teo_stiletto_hun

teo_stiletto_hun
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 15 April 2007 - 07:19 AM

Hello!
It seems to be OK. No error message at windows startup. No Internet Explorer popups YET, but it comes not so often...

THANKS! What to do now? Am I still infected?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users