Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Reboot Without Warning


  • Please log in to reply
9 replies to this topic

#1 Nick_b

Nick_b

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:14 AM

Posted 07 May 2007 - 10:38 PM

Hey guys...this is my first post on this forum, I've been lurking for awhile though (I've found it to be the best place for good knowledge concerning any problems i have).

My deal is...about a week ago, I kept getting a SVCHOST.EXE error, every time my computer would boot up. As soon as the Welcome screen came on, it would give me 60 seconds and then reboot. Well, I searched around, and found (I believe on here), a tip that typing in RUN shutdown -a would prevent the comp for shutting down for enough time to do some work on it.

Well, that worked, but I still wanted to clean it up so I would not lose all of my files and programs. And so I ran lavasoft adaware, and then avg antispyware (which I've heard was a good program). Now, after cleaning it, I get random reboots without warning, instantly. Also, if I ever try to run AVG Antispyware it instantly reboots. Any ideas? Any help on this will be greatly greatly appreciated!

Here is my Hijackthis log...

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:23:37 PM, on 5/7/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Netscape\Netscape Browser\netscape.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://err.dat/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {12C08D46-34D3-7057-A14B-1BE34CE6FBEA} - C:\WINDOWS\System32\xisbkkr.dll (file missing)
O2 - BHO: (no name) - {16666766-9AA1-43B1-B90F-D3E09C064847} - C:\WINDOWS\System32\awvts.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O2 - BHO: (no name) - {CA2CFBDE-0F94-491B-9286-00C60C553954} - C:\WINDOWS\System32\rqrstqq.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Policies\Explorer\Run: [{0CFB2073-0823-1033-0611-040804030001}] "C:\Program Files\Common Files\{0CFB2073-0823-1033-0611-040804030001}\Update.exe" mc-110-12-0000140
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{0CFB2073-0823-1033-0611-040804030001}] "C:\Program Files\Common Files\{0CFB2073-0823-1033-0611-040804030001}\Update.exe" mc-110-12-0000140 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{0CFB2073-0823-1033-0611-040804030001}] "C:\Program Files\Common Files\{0CFB2073-0823-1033-0611-040804030001}\Update.exe" mc-110-12-0000140 (User 'Default user')
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\AMV Convert Tool 3.70\AMVConverter\grab.html
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {08882277-D04C-4A9D-845A-A28FE8CD0773} (xpreload.xpreloader) - ms-its:mhtml:file://c:\\nores.mht!http://adxgate.net/zscript/pre.chm::/xpreload.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mrbulletproof.spaces.live.com//Phot...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178567616625
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178567593765
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\System32\svchosts.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Online Services\vilojogofs.html

--
End of file - 8639 bytes




Moved from the XP Forum. ~acklan~

Edited by acklan, 08 May 2007 - 12:34 AM.


BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:14 AM

Posted 08 May 2007 - 03:31 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Nick_b :thumbsup:

First please delete the following:
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\HiJackThis_v2.exe

Now download and install Hijackthis.
This is a self-extracting version which will automatically install HJT to C:\Program Files\Hijackthis by default.
A desktop shortcut can be created during install under 'Select Additional Tasks'.

***************************

Download SDFix and save it to your desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.zip

Please then reboot your computer into Safe Mode by doing the following :

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.

* In Safe Mode, right click the SDFix.zip folder and choose Extract All,
* Open the extracted folder and double click RunThis.bat to start the script.
* Type Y to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.

**************************

Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
When VundoFix re-opens,click the "Scan for Vundo" button.
Once it's done scanning,click the "Remove Vundo" button.
You will receive a prompt asking if you want to remove the files, click "YES".
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed,it will prompt that it will reboot your computer,click "OK".
Pase post the contents of C:\vundofix.txt into your next reply.

Note:
It is possible that VundoFix encountered a file it could not remove.
In this case,VundoFix will run on reboot,simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

**************************

Please download Combofix and save to your desktop:
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.


Also post a new Hijackthis log please.

Edited by RichieUK, 08 May 2007 - 03:32 AM.

Posted Image
Posted Image

#3 Nick_b

Nick_b
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:14 AM

Posted 08 May 2007 - 03:23 PM

Richie, you are the man. Thanks a lot for all the help.

Here are the logs:
--------------------------------------------------------------------------------

SDFIX.exe

SDFix: Version 1.83

Run by Owner - Tue 05/08/2007 - 11:37:28.67

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\Owner\Desktop\SDFix\SDFix

Safe Mode:
Checking Services:

Name:
Client IP-IPX
core
EXAMPLE
NDnet1
Runtime
wincom32

ImagePath:
"C:\WINDOWS\System32\svchosts.exe" -e mc-110-12-0000140
system32\drivers\core.sys
\??\C:\WINDOWS\System32\main.sys
\??\C:\WINDOWS\System32\ksys.sys
\??\C:\WINDOWS\System32\drivers\runtime.sys
\??\C:\WINDOWS\system32\wincom32.sys

Client IP-IPX - Deleted
core - Deleted
EXAMPLE - Deleted
NDnet1 - Deleted
wincom32 - Deleted


Trojan Subkey Found:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\origami

Filepath:

.dll will be moved on reboot to SDFix\Backups
Notify Key Permissions will be repaired after Reboot...


Trojan Subkey Found:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\origami

Filepath:

.dll will be moved on reboot to SDFix\Backups
Notify Key Permissions will be repaired after Reboot...



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...

Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\system32\.dll - Deleted
C:\WINDOWS\system32\.dll - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\ALIVE_~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\ALIVE_~2.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\ALIVE_~3.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\ALIVE_~4.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\AL64FC~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\AL68FC~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\4HI7KLE3\RUNNED~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\ALIVE_~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\RUNNED~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\ALIVE_~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\ALIVE_~2.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\ALIVE_~3.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\ALIVE_~4.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\RUNNED~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_1~2.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_1~3.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_1~4.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_1~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_2~2.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_2~3.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_2~4.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_2~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_3~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_4~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_5~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_6~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_7~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_8~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\30FWNRVW\TASK_9~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_1~2.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_1~3.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_1~4.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_1~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_2~2.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_2~3.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_2~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_3~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_4~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_5~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_6~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_7~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_8~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\CGQ0J53V\TASK_9~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\TASK_1~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\TASK_2~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\TASK_3~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\TASK_4~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\TASK_5~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\TASK_6~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\TASK_7~1.HTM - Deleted
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\WDQRSPQF\TASK_8~1.HTM - Deleted
C:\WINDOWS\system32\pdp.exe.exe - Deleted
C:\WINDOWS\system32\sony.exe.exe - Deleted
C:\Documents and Settings\Owner\Application Data\Install.dat - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\setup.exe - Deleted
C:\svchost.exe - Deleted
C:\WINDOWS\ServicePackFiles\services.exe - Deleted
C:\WINDOWS\system32\7_exception.nls - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\ksys.sys - Deleted
C:\WINDOWS\system32\ldinfo.ldr - Deleted
C:\WINDOWS\system32\msnav32.ax - Deleted
C:\WINDOWS\system32\svcp.csv - Deleted
C:\WINDOWS\system32\wincom32.ini - Deleted
C:\WINDOWS\system32\wincom32.sys - Deleted
C:\WINDOWS\system32\winsub.xml - Deleted
C:\WINDOWS\Uninst2.htm - Deleted
C:\WINDOWS\Unist1.htm - Deleted



Removing Temp Files

ADS Check:

Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.

Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.



Final Check:

Remaining Services:
------------------




Remaining Files:
---------------

Backups Folder: - C:\DOCUME~1\Owner\Desktop\SDFix\SDFix\backups\backups.zip

Checking For Files with Hidden Attributes:

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\his_princess_22@hotmail.com\Sharing Folders\alestola@hotmail.com\Thumbs.db
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\his_princess_22@hotmail.com\Sharing Folders\dieufille@hotmail.com\Thumbs.db
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\mrbulletproof@hotmail.com\Sharing Folders\africachic2@yahoo.com\Thumbs.db
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\mrbulletproof@hotmail.com\Sharing Folders\dieufille@hotmail.com\Thumbs.db
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\mrbulletproof@hotmail.com\SharingMetadata\hzweifel@hotmail.com\DFSR\ConflictDelete\Thumbs-{BBCF0AC9-C90F-4D50-A6E8-0660E6AE19CE}-v72.db
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\mrbulletproof@hotmail.com\SharingMetadata\hzweifel@hotmail.com\DFSR\ConflictDelete\Thumbs-{BBCF0AC9-C90F-4D50-A6E8-0660E6AE19CE}-v74.db
C:\Documents and Settings\Owner\NetHood\www.alertanalytical.com\Desktop.ini
C:\Program Files\Autodesk\Autodesk DWF Viewer\_Setupx.dll
C:\Documents and Settings\Owner\My Documents\revisedtraining\fdw70.exe
C:\Program Files\Autodesk\Autodesk DWF Viewer\Setup.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1396OinUninstaller.exe
C:\Program Files\?dobe\userinit.exe
C:\WINDOWS\system32\?ystem32\msconfig.exe
C:\Documents and Settings\Owner\Local Settings\Temp\vmgr33c5.tmp\Thumbs.db
C:\Documents and Settings\Owner\Local Settings\Temp\{31571D81-A87F-4a8e-8AE6-591DA5DBB6FC}\temE4.tmp
C:\Documents and Settings\Owner\Local Settings\Temp\{31571D81-A87F-4a8e-8AE6-591DA5DBB6FC}\temE5.tmp
C:\Documents and Settings\Owner\Local Settings\Temp\{31571D81-A87F-4a8e-8AE6-591DA5DBB6FC}\temE6.tmp
C:\WINDOWS\system32\stvwa.tmp

Finished

---------------------------------------------------------------------------------------

Vundofix.exe


VundoFix V6.3.21

Checking Java version...

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Scan started at 12:15:44 PM 5/8/2007

Listing files found while scanning....


VundoFix V6.3.21

Checking Java version...

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Scan started at 1:05:12 PM 5/8/2007

Listing files found while scanning....

C:\WINDOWS\System32\awvts.dll
C:\WINDOWS\system32\dcxvlrnu.dll
C:\WINDOWS\system32\ddurmfml.dll
C:\WINDOWS\system32\jyiidsuh.dll
C:\WINDOWS\System32\stvwa.bak1
C:\WINDOWS\System32\stvwa.bak2
C:\WINDOWS\System32\stvwa.ini
C:\WINDOWS\System32\stvwa.ini2
C:\WINDOWS\System32\stvwa.tmp

Beginning removal...

Attempting to delete C:\WINDOWS\system32\dcxvlrnu.dll
C:\WINDOWS\system32\dcxvlrnu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddurmfml.dll
C:\WINDOWS\system32\ddurmfml.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jyiidsuh.dll
C:\WINDOWS\system32\jyiidsuh.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\stvwa.bak1
C:\WINDOWS\System32\stvwa.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\System32\stvwa.bak2
C:\WINDOWS\System32\stvwa.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\System32\stvwa.ini
C:\WINDOWS\System32\stvwa.ini Has been deleted!

Attempting to delete C:\WINDOWS\System32\stvwa.ini2
C:\WINDOWS\System32\stvwa.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\System32\stvwa.tmp
C:\WINDOWS\System32\stvwa.tmp Has been deleted!

Performing Repairs to the registry.
Done!
--------------------------------------------------------------------------------

Combofix.exe


"Owner" - 2007-05-08 13:44:47 Service Pack 1
ComboFix 07-05.08.3.V - Running from: "C:\Documents and Settings\Owner\Desktop\"

/wow section - STAGE #3

(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\ddcccde.dll
C:\WINDOWS\system32\djeisfoo.dll
C:\WINDOWS\system32\efccyvs.dll
C:\WINDOWS\system32\hggfcyv.dll
C:\WINDOWS\system32\jsarewve.dll
C:\WINDOWS\system32\kgdaegtq.dll
C:\WINDOWS\system32\opnmljg.dll
C:\WINDOWS\system32\tugqojao.dll
C:\WINDOWS\system32\tuvuspq.dll
C:\WINDOWS\system32\ulwwfxoe.dll
C:\WINDOWS\system32\oofsiejd.ini
C:\WINDOWS\system32\evwerasj.ini
C:\WINDOWS\system32\qtgeadgk.ini
C:\WINDOWS\system32\oajoqgut.ini
C:\WINDOWS\system32\eoxfwwlu.ini


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\ipwindows\ipwins.dll
C:\Program Files\ipwindows\ipwins.exe
C:\Program Files\outerinfo\Terms.rtf
C:\WINDOWS\system32\bund1\ClientBundle1.exe
C:\WINDOWS\system32\bund1\temp.txt
C:\Program Files\Common Files\{3CFB2~1\UnInstall.exe
C:\DOCUME~1\Owner\Desktop\bravesentry.lnk
C:\WINDOWS\servicepackfiles\xx
C:\WINDOWS\TTC.exe
C:\WINDOWS\system32\sony.exe
C:\Program Files\inetget2
C:\Program Files\ipwindows
C:\Program Files\outerinfo
C:\Program Files\outlook
C:\WINDOWS\system32\bund1
C:\Program Files\Common Files\{0CFB2~1
C:\Program Files\Common Files\{3CFB2~1
C:\WINDOWS\system32\windev-f66-66a0.sys
C:\WINDOWS\system32\windev-peers.ini
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\Owner
C:\qoobox\purity\C\DOCUME~1\Owner\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\Owner\MYDOCU~1
C:\qoobox\purity\C\DOCUME~1\Owner\APPLIC~1\APPATC~1
C:\qoobox\purity\C\DOCUME~1\Owner\MYDOCU~1\SSEMBL~1
C:\qoobox\purity\C\Program Files\DOBE~1
C:\qoobox\purity\C\WINDOWS\DOBE~1
C:\qoobox\purity\C\WINDOWS\SSEMBL~1
C:\qoobox\purity\C\WINDOWS\system32\YSTEM3~1
C:\qoobox\purity\C\WINDOWS\system32\YSTEM3~1\msconfig.exe
C:\qoobox\purity\C\WINDOWS\system32\YSTEM3~1\?ystem32
C:\qoobox\purity\C\WINDOWS\system32\YSTEM3~1\?ystem32\ctxad-552.0000

Infected copy of C:\WINDOWS\system32\winlogon.exe was found & disinfected
Restored copy from - "C:\WINDOWS\system32\dllcache\winlogon.exe"



((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\windev-f66-66a0


((((((((((((((((((((((((((((((( Files Created from 2007-04-08 to 2007-05-08 ))))))))))))))))))))))))))))))))))


2007-05-08 12:15 <DIR> d-------- C:\VundoFix Backups
2007-05-08 11:10 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Netscape
2007-05-08 11:08 1,048,576 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-05-08 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\WINDOWS
2007-05-08 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-05-08 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
2007-05-08 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
2007-05-07 17:07 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Lavasoft
2007-05-07 17:06 <DIR> d-------- C:\Program Files\Lavasoft
2007-05-07 14:31 991,232 --a------ C:\WINDOWS\system32\esent.dll
2007-05-07 13:59 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-05-07 13:59 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-05-07 13:59 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-05-07 13:58 7,680 --------- C:\WINDOWS\system32\bitsprx2.dll
2007-05-07 13:58 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2007-05-07 13:58 331,776 --a------ C:\WINDOWS\system32\winhttp.dll
2007-05-07 13:58 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-05-07 13:58 <DIR> d-------- C:\WINDOWS\system32\bits
2007-05-07 13:55 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2007-05-07 13:54 465,176 --a------ C:\WINDOWS\system32\wuapi.dll
2007-05-07 13:54 41,240 --a------ C:\WINDOWS\system32\wups.dll
2007-05-07 13:54 194,328 --a------ C:\WINDOWS\system32\wuaueng1.dll
2007-05-07 13:54 18,200 --a------ C:\WINDOWS\system32\wups2.dll
2007-05-07 13:54 172,312 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-05-07 13:54 127,256 --a------ C:\WINDOWS\system32\wucltui.dll
2007-05-07 13:53 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-05-07 12:48 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-05-07 12:45 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-05-07 11:26 40,503 --a------ C:\WINDOWS\system32\rem1.dll
2007-05-07 10:59 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-05-07 10:55 <DIR> d-------- C:\DOCUME~1\Owner\.housecall6.6
2007-05-07 10:52 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-05-07 10:39 40,503 --a------ C:\WINDOWS\system32\rem.dll
2007-05-07 10:39 30,641 --a------ C:\WINDOWS\system32\helper.sys
2007-05-07 10:39 1 --a------ C:\WINDOWS\system32\ps.dat
2007-05-07 10:39 1 --a------ C:\WINDOWS\system32\cookie.dat
2007-05-07 10:16 152,576 --a------ C:\WINDOWS\system32\Jds44.sys
2007-05-06 23:03 45,056 --a------ C:\WINDOWS\retadpu2000219.exe
2007-05-06 23:03 45,056 --a------ C:\WINDOWS\retadpu1000106.exe
2007-05-06 23:03 <DIR> d-------- C:\WINDOWS\system32\smpi1
2007-05-06 23:03 <DIR> d-------- C:\WINDOWS\system32\SBO
2007-05-06 23:03 <DIR> d-------- C:\temp\17O7
2007-05-06 23:02 40,183 ---hs---- C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
2007-04-23 12:11 146,944 ---hs---- C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
2007-04-16 20:17 32,768 --a------ C:\DOCUME~1\Owner\setup9x.exe
2007-04-16 20:11 32,178 --ahs---- C:\Program Files\Common Files\Yazzle1396OinUninstaller.exe
2007-04-16 13:00 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-04-16 12:14 <DIR> d-------- C:\Program Files\Microsoft AntiSpyware
2007-04-16 09:48 829,488 --a------ C:\DOCUME~1\Owner\APPLIC~1\Dxcknwrd.dll
2007-04-16 09:46 934 --a------ C:\WINDOWS\system32\winpfz32.sys
2007-04-16 09:46 105,434 --a------ C:\WINDOWS\VTTC.exe
2007-04-16 09:46 <DIR> d-------- C:\temp\tn3
2007-04-16 09:45 8,464 --a------ C:\WINDOWS\system32\sporder.dll
2007-04-16 09:45 <DIR> d-------- C:\WINDOWS\system32\micro1
2007-04-15 18:46 <DIR> d--hs---- C:\DOCUME~1\Owner\Complete
2007-04-09 11:22 <DIR> d-------- C:\Program Files\Fellowes
2007-04-09 11:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fellowes


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-08 19:43:54 4,388 ----a-w C:\WINDOWS\mozver.dat
2007-05-08 09:05:07 -------- d-----w C:\Program Files\Messenger
2007-05-08 03:10:26 -------- d--h--w C:\Program Files\WindowsUpdate
2007-05-07 23:33:54 -------- d-----w C:\Program Files\Online Services
2007-04-16 17:38:39 -------- d-----w C:\Program Files\LimeWire
2007-04-09 22:32:22 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\U3
2007-04-09 17:24:39 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-04-06 19:32:10 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\AdobeUM
2007-03-19 19:13:29 -------- d-----w C:\Program Files\WarZone
2007-03-19 19:13:29 -------- d-----w C:\Program Files\Common Files\Idu
2007-03-19 19:06:58 -------- d-----w C:\Program Files\XMPChat
2007-03-16 06:40:19 -------- d-----w C:\Program Files\iWin.com
2007-03-16 06:33:36 -------- d-----w C:\Program Files\iWin Games
2007-03-14 22:45:06 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\uTorrent
2007-03-12 19:30:35 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Netscape
2007-03-10 07:28:15 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\WinRAR


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{12C08D46-34D3-7057-A14B-1BE34CE6FBEA}"="C:\WINDOWS\System32\xisbkkr.dll" [x]
"{16666766-9AA1-43B1-B90F-D3E09C064847}"="C:\WINDOWS\System32\awvts.dll" [x]
"{BDF3E430-B101-42AD-A544-FADC6B084872}"="c:\Program Files\Norton AntiVirus\NavShExt.dll" [x]
"{CA2CFBDE-0F94-491B-9286-00C60C553954}"="C:\WINDOWS\System32\rqrstqq.dll" [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"VTTimer"="VTTimer.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ C:\Program Files\Online Services\vilojogofs.html

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{9EF34FF2-3396-4527-9D27-04C8C1C67806}"="C:\Program Files\Microsoft AntiSpyware\shellextension.dll"
"{CA2CFBDE-0F94-491B-9286-00C60C553954}"="C:\WINDOWS\System32\rqrstqq.dll" [x]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll"


HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvts
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrstqq

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^compaq connections.lnk
C:\PROGRA~1\COMPAQ~1\1940576\Program\BACKWE~1.EXE -startup

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^hp psc 1000 series.lnk
C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpohmr08.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^hpoddt01.exe.lnk
C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^kodak easyshare software.lnk
C:\PROGRA~1\Kodak\KODAKE~1\bin\EASYSH~1.EXE -hx

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^kodak software updater.lnk
C:\PROGRA~1\Kodak\KODAKS~1\7288971\Program\KODAKS~1.EXE

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^microsoft office.lnk
C:\PROGRA~1\MI1933~1\Office10\OSA.EXE -b -l

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^oki lpr utility.lnk
C:\PROGRA~1\Okidata\OKILPR~1\okilpr.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^quicken scheduled updates.lnk
C:\PROGRA~1\Quicken\bagent.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^wupdmgr.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\wupdmgr.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^owner^start menu^programs^startup^compaq organize.lnk
C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\DISPLA~1.EXE "-application" "core.hp.main/application.xml" "-appname" "eLife"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^owner^start menu^programs^startup^imstart.lnk
C:\PROGRA~1\INTERM~1\IMStart.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^owner^start menu^programs^startup^powerreg scheduler v3.exe
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^owner^start menu^programs^startup^powerreg schedulerv2.exe
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\PowerReg SchedulerV2.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^owner^start menu^programs^startup^ta_start.lnk
C:\WINDOWS\system32\micro1\z6.exe SKY003

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^owner^start menu^programs^startup^think-adz.lnk
C:\WINDOWS\system32\swinlodv.exe SKY003

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!avg anti-spyware
"C:\Program Files\GRISOFT\AVG Anti-Spyware 7.5\avgas.exe" /minimized

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\agrsmmsg
AGRSMMSG.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aim6
"C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\alcxmonitor
ALCXMNTR.EXE

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\altnetpointsmanager
c:\program files\altnet\points manager\points manager.exe -s

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\brave-sentry
C:\Program Files\BraveSentry\BraveSentry.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccapp
"c:\Program Files\Common Files\Symantec Shared\ccApp.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe
C:\WINDOWS\System32\ctfmon.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\deluxecommunications
C:\Program Files\DeluxeCommunications\Dxc.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\envkjpl
"C:\Documents and Settings\Owner\Application Data\A?pPatch\csrss.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\exploreupdsched
C:\WINDOWS\System32\swinlodv.exe SKY003

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasserv
"C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\google desktop search
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hostmanager
C:\Program Files\Common Files\AOL\1141618581\ee\AOLSoftware.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpdj taskbar utility
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv
c:\windows\system\hpsysdrv.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipwins
C:\Program Files\Ipwindows\ipwins.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ituneshelper
"C:\Program Files\iTunes\iTunesHelper.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kbd
C:\HP\KBD\KBD.EXE

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kernelfaultcheck
%systemroot%\system32\dumprep 0 -k

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kuh
C:\WINDOWS\?dobe\netdde.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mediaface integration
C:\Program Files\Fellowes\MediaFACE 4.2\SetHook.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ms04844352177
C:\WINDOWS\ms04844352177.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nav cfgwiz
c:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\new.net startup
rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\notn
"C:\PROGRA~1\DOBE~1\userinit.exe" -vt yazb

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\om_monitor
C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\outlook
C:\Program Files\outlook\outlook.exe /auto

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\p2p networking
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ps2
C:\WINDOWS\system32\ps2.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pvr
C:\Program Files\XemiComputers\Pocket Voice Recorder\PVR.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\quicktime task
"C:\Program Files\QuickTime\qttask.exe" -atboottime

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\realplayer
"C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\recguard
C:\WINDOWS\SMINST\RECGUARD.EXE

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\recordnow!


HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1
C:\WINDOWS\retadpu2000219.exe 61A847B5BBF72810329B385473F001F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\semanticinsight
C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sunjavaupdatesched
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\symantec netdriver monitor
C:\PROGRA~1\SYMNET~1\SNDMon.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\t3mon
"C:\Program Files\FLIR Systems\ThermaCAM Connect 3\T3Mon.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tkbellexe
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updatemanager
"c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vactrls
v7

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\viewmgr
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vttimer
VTTimer.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\windows update loader
C:\Windows\xpupdate.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\windowsservice
rundll32.exe "C:\WINDOWS\System32\pxdyygjl.dll",realset

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winlog
winlog.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yahoo! pager
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVG Anti-Spyware Guard"=dword:00000002

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
Usnsvc usnsvc\0\0

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1098757419.job
C:\WINDOWS\tasks\Symantec NetDetect.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-08 14:01:06
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 2007-05-08 14:05:42 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-08 14:05
-----------------------------------------------------------------------------------------------------------

And the new HijackThis:

Logfile of HijackThis v1.99.1
Scan saved at 2:20:18 PM, on 5/8/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\VTTimer.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Netscape\Netscape Browser\netscape.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://err.dat/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {12C08D46-34D3-7057-A14B-1BE34CE6FBEA} - C:\WINDOWS\System32\xisbkkr.dll (file missing)
O2 - BHO: (no name) - {16666766-9AA1-43B1-B90F-D3E09C064847} - C:\WINDOWS\System32\awvts.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O2 - BHO: (no name) - {CA2CFBDE-0F94-491B-9286-00C60C553954} - C:\WINDOWS\System32\rqrstqq.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\AMV Convert Tool 3.70\AMVConverter\grab.html
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {08882277-D04C-4A9D-845A-A28FE8CD0773} (xpreload.xpreloader) - ms-its:mhtml:file://c:\\nores.mht!http://adxgate.net/zscript/pre.chm::/xpreload.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mrbulletproof.spaces.live.com//Phot...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178567616625
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178567593765
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awvts - C:\WINDOWS\System32\awvts.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: rqrstqq - rqrstqq.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:14 AM

Posted 08 May 2007 - 04:01 PM

Download Avenger from the link below:
http://swandog46.geekstogo.com/avenger.zip
Unzip/extract it to your desktop.

Start up Avenger.
Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens,copy and paste ALL the following bold blue text in the Quote box below:

Files to delete:
C:\WINDOWS\retadpu2000219.exe
C:\WINDOWS\retadpu1000106.exe
C:\WINDOWS\system32\winpfz32.sys
C:\DOCUMENTS AND SETTINGS\Owner\APPLICATION DATA\Dxcknwrd.dll

Folders to delete:
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1396OinUninstaller.exe

Then click on 'Done'.
Click the Traffic Light icon to start the program.
Then press OK at the prompts to reboot your PC.

Post the Avenger output.txt, which you can find at C:\Avenger\.txt into your next reply.
Posted Image
Posted Image

#5 Nick_b

Nick_b
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:14 AM

Posted 08 May 2007 - 04:24 PM

Richie, again..thanks so much for all the help. My computer is running like a dream now. I thought I was hopeless here. You're a lifesaver.

What exactly was causing all these problems I was having?

Here is the Avenger Log:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\jhohegdm

*******************

Script file located at: \??\C:\WINDOWS\pudimgsc.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\retadpu2000219.exe deleted successfully.
File C:\WINDOWS\retadpu1000106.exe deleted successfully.
File C:\WINDOWS\system32\winpfz32.sys deleted successfully.
File C:\DOCUMENTS AND SETTINGS\Owner\APPLICATION DATA\Dxcknwrd.dll deleted successfully.


Error: C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe is not a folder! It may instead be a file.
Deletion of folder C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe failed!

Could not process line:
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
Status: 0xc0000103



Error: C:\Program Files\Common Files\Yazzle1281OinAdmin.exe is not a folder! It may instead be a file.
Deletion of folder C:\Program Files\Common Files\Yazzle1281OinAdmin.exe failed!

Could not process line:
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
Status: 0xc0000103



Error: C:\Program Files\Common Files\Yazzle1396OinUninstaller.exe is not a folder! It may instead be a file.
Deletion of folder C:\Program Files\Common Files\Yazzle1396OinUninstaller.exe failed!

Could not process line:
C:\Program Files\Common Files\Yazzle1396OinUninstaller.exe
Status: 0xc0000103


Completed script processing.

*******************

Finished! Terminate.

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:14 AM

Posted 08 May 2007 - 04:43 PM

Sorry about that,my mistake :thumbsup:
Start up Avenger.
Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens,copy and paste ALL the following bold blue text in the Quote box below:

Files to delete:
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1396OinUninstaller.exe

Then click on 'Done'.
Click the Traffic Light icon to start the program.
Then press OK at the prompts to reboot your PC.

Post the Avenger output.txt, which you can find at C:\Avenger\.txt into your next reply.
Also post a new Hijackthis log please.
Posted Image
Posted Image

#7 Nick_b

Nick_b
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:14 AM

Posted 08 May 2007 - 10:59 PM

Haha, the last thing you should be is sorry..I appreciate the help a lot...

Avenger Log:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\cvjqqckv

*******************

Script file located at: \??\C:\WINDOWS\xlrqbqqe.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe deleted successfully.
File C:\Program Files\Common Files\Yazzle1281OinAdmin.exe deleted successfully.
File C:\Program Files\Common Files\Yazzle1396OinUninstaller.exe deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
-------------------------------------------------------------------------------------------

HijackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 9:53:29 PM, on 5/8/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\VTTimer.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\System32\rsvp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://err.dat/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {12C08D46-34D3-7057-A14B-1BE34CE6FBEA} - C:\WINDOWS\System32\xisbkkr.dll (file missing)
O2 - BHO: (no name) - {16666766-9AA1-43B1-B90F-D3E09C064847} - C:\WINDOWS\System32\awvts.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O2 - BHO: (no name) - {CA2CFBDE-0F94-491B-9286-00C60C553954} - C:\WINDOWS\System32\rqrstqq.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\AMV Convert Tool 3.70\AMVConverter\grab.html
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {08882277-D04C-4A9D-845A-A28FE8CD0773} (xpreload.xpreloader) - ms-its:mhtml:file://c:\\nores.mht!http://adxgate.net/zscript/pre.chm::/xpreload.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mrbulletproof.spaces.live.com//Phot...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178567616625
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178567593765
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awvts - C:\WINDOWS\System32\awvts.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: rqrstqq - rqrstqq.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:14 AM

Posted 09 May 2007 - 03:25 AM

Download/install AVG Anti-Spyware 7.5.

Please follow these instructions very carefully.

Launch/start up AVG Anti-Spyware.
On the main page click the 'Update' tab,and then 'Start Update'.
Note:
If you have any problems running the update process prior to running the scan,download/install the 'Full Database' from here:
http://download.ewido.net/avgas-signatures-full-current.exe

Once the updates have been installed,do the following:
Select the 'Scanner' icon at the top of the screen, then select the 'Settings' tab.
Once in the 'Settings' screen,under 'How to act?',then under 'Set default action for detected malware to:', click on 'Recommended actions',then click on 'Quarantine'.
Under 'Reports' select 'Automatically generate report after every scan' and unselect 'Only if threats were found'.
Exit AVG Anti-Spyware,don't run the scan just yet.

You might want to print/copy the following as you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Have Hijack This fix the following [If still present], by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:

O2 - BHO: (no name) - {12C08D46-34D3-7057-A14B-1BE34CE6FBEA} - C:\WINDOWS\System32\xisbkkr.dll (file missing)
O2 - BHO: (no name) - {16666766-9AA1-43B1-B90F-D3E09C064847} - C:\WINDOWS\System32\awvts.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O2 - BHO: (no name) - {CA2CFBDE-0F94-491B-9286-00C60C553954} - C:\WINDOWS\System32\rqrstqq.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O16 - DPF: {08882277-D04C-4A9D-845A-A28FE8CD0773} (xpreload.xpreloader) - ms-its:mhtml:file://c:\nores.mht!http://adxgate.net/zscript/pre.chm::/xpreload. cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O20 - Winlogon Notify: awvts - C:\WINDOWS\System32\awvts.dll (file missing)
O20 - Winlogon Notify: rqrstqq - rqrstqq.dll (file missing)


Still in Safe Mode launch AVG Anti-Spyware.
Click the 'Scanner' icon at the top.
To start the scan click on 'Complete System Scan'.
Please be patient,it takes a while for the scan to finish.

Once the scan is complete,do the following.
If AVG Anti-Spyware detected any infected objects:,click on 'Apply All Actions'.

Next click on 'Save Report'.
Copy and paste that report into your next reply.
The report can be found under the 'Reports' tab at the top.
Close AVG Anti-Spyware when you've done.
Reboot normally.

Post the AVG Anti Spyware report and a new Hijackthis log into your next reply.
Let me know how your pc is running now please.
Posted Image
Posted Image

#9 Nick_b

Nick_b
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:14 AM

Posted 09 May 2007 - 11:21 PM

Hey Richie..sorry it took so long..that was a long AVG scan, and a long day at work.. :thumbsup:

It runs fast. Real fast. Faster than it has since it was new. The only problem I see is that at times it has problems opening files. It'll get to a point where it won't open up anything new, the currently running programs will work fine, but it refuses to open up a new one. For instance, I had Netscape open, and was replying to you, but was unable to open the AVG Scan Report until I rebooted...but it's miles ahead of where it was..thank you sir...

Here are the new logs:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 9:56:08 PM 5/9/2007

+ Scan result:



C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019300.dll -> Adware.404Search : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019289.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019301.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019294.dll -> Adware.BraveSentry : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019295.dll -> Adware.BraveSentry : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019296.dll -> Adware.BraveSentry : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019297.dll -> Adware.BraveSentry : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019302.DLL -> Adware.IESearch : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{3CFB2~1\UnInstall.exe.vir -> Adware.IWantSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027555.exe -> Adware.IWantSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019299.dll -> Adware.Lucky : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019303.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019304.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019305.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019306.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019307.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019308.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019309.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019316.cpl -> Adware.P2PNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019315.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019317.exe -> Adware.Relevant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019290.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019291.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019292.exe -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019282.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019283.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\TTC.exe.vir -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP1\A0001047.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0002077.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0002089.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0003110.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0004104.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0013153.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027557.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP8\A0013276.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0014260.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0015258.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019314.dll -> Adware.TTC : Cleaned with backup (quarantined).
C:\WINDOWS\VTTC.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcccde.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\efccyvs.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\hggfcyv.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\opnmljg.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\tuvuspq.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027559.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027561.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027562.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027565.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027567.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0017253.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019284.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019285.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019286.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019287.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019288.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019310.dll -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019311.exe -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019312.exe -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019313.exe -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019269.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019277.exe -> Dialer.GBDialer.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019278.exe -> Dialer.GBDialer.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019257.exe -> Downloader.Agent.ac : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019256.exe -> Downloader.Agent.axh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019279.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019255.dll -> Downloader.Agent.bga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019320.dll -> Downloader.Agent.bga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0004087.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0029869.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0029870.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019265.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\WINDOWS\system32\smpi1\lib06.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\avenger\backup-Tue 05.08.2007-21.52.19.81.zip/avenger/retadpu1000106.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\avenger\backup-Tue 05.08.2007-21.52.19.81.zip/avenger/retadpu2000219.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0004088.exe -> Downloader.PurityScan.af : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027577.exe -> Downloader.PurityScan.af : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0004085.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0030884.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\avenger\backup.zip/avenger/Yazzle1281OinAdmin.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019258.exe -> Downloader.PurityScan.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019259.exe -> Downloader.PurityScan.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019272.exe -> Downloader.Small.dxm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019273.exe -> Downloader.Small.dxm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019274.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Desktop\SDFix\SDFix\backups\backups.zip/backups/pdp.exe.exe -> Downloader.Tibs.kv : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Desktop\SDFix\SDFix\backups\backups.zip/backups/sony.exe.exe -> Downloader.Tibs.kv : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\sony.exe.vir -> Downloader.Tibs.kv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP37\A0025413.exe -> Downloader.Tibs.kv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP37\A0025414.exe -> Downloader.Tibs.kv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP37\A0025430.exe -> Downloader.Tibs.kv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP37\A0025433.exe -> Downloader.Tibs.kv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027558.exe -> Downloader.Tibs.kv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019281.exe -> Hijacker.Agent.jc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019275.exe -> Hijacker.Costrat.e : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Desktop\SDFix\SDFix\backups\backups.zip/backups/services.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\ServicePackFiles\xx.vir -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP37\A0025416.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP37\A0025431.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019267.dll -> Hijacker.StartPage : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019268.dll -> Hijacker.StartPage : Cleaned with backup (quarantined).
C:\WINDOWS\system32\rem.dll -> Logger.Banker.cnq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\rem1.dll -> Logger.Banker.cnq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019318.exe -> Not-A-Virus.Hoax.Win32.Renos.fi : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Jds44.sys -> Rootkit.Agent.ea : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019276.sys -> Rootkit.Agent.eq : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Desktop\SDFix\SDFix\backups\backups.zip/backups/ksys.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP1\A0000009.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP1\A0000020.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP1\A0001020.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP1\A0001031.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP1\A0001043.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP1\A0001055.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP1\A0002055.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP1\A0002066.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP37\A0025418.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP37\A0025428.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0003068.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0003080.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0004080.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0004117.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0005117.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0006117.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0007117.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0008116.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0008129.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0009130.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0010129.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0011141.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0013141.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP8\A0013245.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP8\A0014245.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0015245.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0016244.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Owner\Application Data\Netscape\NSB\Profiles\of3xbg5i.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\Owner\Application Data\Netscape\NSB\Profiles\of3xbg5i.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\Owner\Application Data\Netscape\NSB\Profiles\of3xbg5i.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\Documents and Settings\Owner\Application Data\Netscape\NSB\Profiles\of3xbg5i.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.12:C:\Documents and Settings\Owner\Application Data\Netscape\NSB\Profiles\of3xbg5i.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.13:C:\Documents and Settings\Owner\Application Data\Netscape\NSB\Profiles\of3xbg5i.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.14:C:\Documents and Settings\Owner\Application Data\Netscape\NSB\Profiles\of3xbg5i.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.15:C:\Documents and Settings\Owner\Application Data\Netscape\NSB\Profiles\of3xbg5i.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.10:C:\Documents and Settings\Owner\Application Data\Netscape\NSB\Profiles\of3xbg5i.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019262.exe -> Trojan.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019263.exe -> Trojan.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019264.exe -> Trojan.Agent : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Ipwindows\ipwins.dll.vir -> Trojan.Rond : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Ipwindows\ipwins.exe.vir -> Trojan.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027552.dll -> Trojan.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027553.exe -> Trojan.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019266.exe -> Trojan.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019280.exe -> Trojan.Small.mf : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Desktop\SDFix\SDFix\backups\backups.zip/backups/wincom32.sys -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\windev-f66-66a0.sys.vir -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP37\A0025421.sys -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP37\A0025436.sys -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP3\A0004097.sys -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP66\A0027587.sys -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Desktop\Setup153.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019270.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019271.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019260.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8153ACA8-C727-4835-A7D4-A3A2B949B296}\RP9\A0019261.exe -> Worm.VB.dw : Cleaned with backup (quarantined).


::Report end

_________________________________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 10:15:20 PM, on 5/9/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\VTTimer.exe
C:\WINDOWS\System32\ctfmon.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\System32\rsvp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://err.dat/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\AMV Convert Tool 3.70\AMVConverter\grab.html
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mrbulletproof.spaces.live.com//Phot...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178567616625
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178567593765
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:14 AM

Posted 10 May 2007 - 05:39 AM

Download/install Dial-a-Fix from here:
http://www.softpedia.com/get/System/System...ial-a-fix.shtml
Launch the program,place a check in ALL the boxes.
Then click on 'GO' at the bottom.
Restart your pc when Dial-a-Fix has done.

********************

Double click on combofix.exe again and follow the prompts.
When it's finished it will produce a log.
Post the contents of C:\ComboFix.txt into your next reply.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users