Unsolved

This post is more than 5 years old

47 Posts

2882

June 29th, 2006 22:00

HJT Log, help me please

I have received the recent AOL Instant Messenger virus and it has put numerous instances of spyware, adware, malware, etc. on my computer which has slowed my system performance down significantly. Here is the HJT log from my scan:

Logfile of HijackThis v1.99.1
Scan saved at 6:45:18 PM, on 6/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SSA\smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\ActivCard\acautoreg.exe
C:\Program Files\Common Files\ActivCard\accoca.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Hewlett-Packard\PC COE\IDA.EXE
C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
C:\Program Files\Vivitar\V3301\CamCheck\CamCheck.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\mptft.exe
C:\WINDOWS\system32\ssn6tuu.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\cfg32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ssec.exe
C:\WINDOWS\system32\nr1rnqm8.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\PROGRA~1\Sygate\SSA\syg_hp.exe
C:\WINDOWS\rcss.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\cfg32a.exe
C:\WINDOWS\system32\tfthot.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=20065&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=20065&k=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://store.plaync.com/home.php
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\vfbxn.exe
F2 - REG:system.ini: UserInit=userinit.exe,hbibxdm.exe
O2 - BHO: Yvakt Class - {AE0ECC2F-0C33-494C-8B22-B57A7763027F} - C:\WINDOWS\system32\x3cqp0.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink TotalAccess\Toolbar\Toolbar.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [IDA] C:\Program Files\Hewlett-Packard\PC COE\IDA.EXE
O4 - HKLM\..\Run: [QuickPassword] C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule
O4 - HKLM\..\Run: [CamCheck] C:\Program Files\Vivitar\V3301\CamCheck\CamCheck.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SSA\smc.exe -startgui
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ftexc] C:\WINDOWS\system32\mptft.exe
O4 - HKLM\..\Run: [Hhl7RfpJ] "C:\WINDOWS\system32\ssn6tuu.exe"
O4 - HKLM\..\Run: [nff8742a] RUNDLL32.EXE w005908f.dll,n 0018742900000003005908f
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmb_2.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab_adult/WebsiteAccess/ie/bridge-c9.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117836133063
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = AMERICAS.cpqcorp.net,AMERICAS.hpqcorp.net,hpqcorp.net,cpqcorp.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = AMERICAS.cpqcorp.net,AMERICAS.hpqcorp.net,hpqcorp.net,cpqcorp.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = AMERICAS.cpqcorp.net,AMERICAS.hpqcorp.net,hpqcorp.net,cpqcorp.net
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O18 - Filter: text/html - {DA28E0DB-229C-4003-827E-96AE15AD90FB} - C:\WINDOWS\system32\x3cqp0.dll
O20 - AppInit_DLLs: repairs303169590.dll,ASAPHook
O20 - Winlogon Notify: H323TSP - C:\WINDOWS\system32\clsetACL.dll
O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\system32\s6rslg9716.dll (file missing)
O20 - Winlogon Notify: Nls - C:\WINDOWS\system32\ofesvr32.dll
O20 - Winlogon Notify: Unimodem - C:\WINDOWS\system32\ofesvr32.dll
O20 - Winlogon Notify: URL - C:\WINDOWS\system32\ofesvr32.dll
O23 - Service: ActivCard Gold Autoregister (acautoreg) - ActivCard S.A. - C:\Program Files\Common Files\ActivCard\acautoreg.exe
O23 - Service: ActivCard Gold service (Accoca) - ActivCard - C:\Program Files\Common Files\ActivCard\accoca.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: HP Sygate Icon Control (HPSygControl) - Hewlett-Packard Company - C:\PROGRA~1\Sygate\SSA\syg_hp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lan Discover Agent (magaService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SSA\maga\maga.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
O23 - Service: Remote Procedure Call Service (RPCS) - Unknown owner - C:\WINDOWS\rcss.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sygate Security Agent (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SSA\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

June 30th, 2006 04:00

Open HijackThis, click Config, click Misc Tools
Click " Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.

47 Posts

June 30th, 2006 13:00

ActivCard Gold
ActivCard Initialization Utility
Ad-Aware SE Personal
Adobe Photoshop 7.0.1
Adobe Reader 6.0.1
AOL Instant Messenger
Athlon 64 Processor Driver
ATI - Software Uninstall Utility
BioWare Premium Module: Neverwinter Nights(TM) Kingmaker
BitComet 0.70
Camtasia Studio 3
Command & Conquer Generals
Command and ConquerTM Generals Zero Hour
Conexant AC-Link Audio
DivX
EarthLink Software
EarthLink Toolbar
Forethought
Google Gmail Notifier
Guild Wars
HijackThis 1.99.1
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB912475)
HP Accessories Product Tour
HP BIOS Configuration for ProtectTools 1.00 D4
HP Credential Manager for ProtectTools
HP Help and Support
HP Integrated Module with Bluetooth wireless technology
HP One Click
HP ProtectTools Security Manager 2.00 A4
HP Wireless Assistant 1.01 A3
HP_User_Guides_0003
HyperCam 2
InterVideo DVD Check
InterVideo WinDVD
iTunes
J2SE Runtime Environment 5.0 Update 2
Java 2 Runtime Environment, SE v1.4.2_10
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Flash Player
Macromedia Flash Player 8
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.0 Hotfix (KB886906)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Office 2003 Web Components
Microsoft Office Professional Edition 2003
Microsoft Office Visio Professional 2003
Might and Magic® VII
Morrowind
Mozilla Firefox (1.5)
Neverwinter Nights
NVIDIA Photoshop Plug-ins
Quick Launch Buttons 5.10 B5
Quicklinks
QuickTime
Related Page
Rio Internet Update
Rio Internet Update
Rio Music Manager
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
SoftV.90 Data Fax Modem with SmartCP
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Sony Vegas Movie Studio 6.0b
Spybot - Search & Destroy 1.4
Surf SideKick
Sygate Security Agent 4.1
Symantec AntiVirus
Synaptics Pointing Device Driver
TES Construction Set
The Sims 2
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB900930)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB912945)
Viewpoint Media Player
ViviCam 3301 Digital Camera
Wheel of Time
Windows Installer 3.1 (KB893803)
Windows Media Connect
Windows Media Format Runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB884575
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885464
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892559
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Hotfix - KB894083
WinRAR archiver
WinZip

June 30th, 2006 13:00

Please remove these entries from Add/Remove Programs in the Control Panel(if present):

Forethought
Java 2 Runtime Environment, SE v1.4.2_10
Quicklinks
Surf SideKick

The following are optional; however, any time your are running any type of P2P application, you are FAR more prone to infection by malware. Your current infections are likely due to P2P use.

BitComet 0.70

Please note any other programs that you dont recognize in that list in your next response


1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


In your next post, please include
  • combofix log
  • new hijackthis log

  • *use separate posts to ensure the logs don't get cut off!

47 Posts

July 1st, 2006 15:00

Logfile of HijackThis v1.99.1
Scan saved at 11:47:53 AM, on 7/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SSA\smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HPQ\IAM\bin\asghost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\ActivCard\acautoreg.exe
C:\Program Files\Common Files\ActivCard\accoca.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\PROGRA~1\Sygate\SSA\syg_hp.exe
C:\WINDOWS\rcss.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Hewlett-Packard\PC COE\IDA.EXE
C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
C:\Program Files\Vivitar\V3301\CamCheck\CamCheck.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\cfg32.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\cfg32a.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=20065&k=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://store.plaync.com/home.php
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink TotalAccess\Toolbar\Toolbar.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [IDA] C:\Program Files\Hewlett-Packard\PC COE\IDA.EXE
O4 - HKLM\..\Run: [QuickPassword] C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule
O4 - HKLM\..\Run: [CamCheck] C:\Program Files\Vivitar\V3301\CamCheck\CamCheck.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SSA\smc.exe -startgui
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ftexc] C:\WINDOWS\system32\mptft.exe
O4 - HKLM\..\Run: [nff8742a] RUNDLL32.EXE w005908f.dll,n 0018742900000003005908f
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab_adult/WebsiteAccess/ie/bridge-c9.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117836133063
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = AMERICAS.cpqcorp.net,AMERICAS.hpqcorp.net,hpqcorp.net,cpqcorp.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = AMERICAS.cpqcorp.net,AMERICAS.hpqcorp.net,hpqcorp.net,cpqcorp.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = AMERICAS.cpqcorp.net,AMERICAS.hpqcorp.net,hpqcorp.net,cpqcorp.net
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - AppInit_DLLs: ASAPHook
O23 - Service: ActivCard Gold Autoregister (acautoreg) - ActivCard S.A. - C:\Program Files\Common Files\ActivCard\acautoreg.exe
O23 - Service: ActivCard Gold service (Accoca) - ActivCard - C:\Program Files\Common Files\ActivCard\accoca.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: HP Sygate Icon Control (HPSygControl) - Hewlett-Packard Company - C:\PROGRA~1\Sygate\SSA\syg_hp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lan Discover Agent (magaService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SSA\maga\maga.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
O23 - Service: Remote Procedure Call Service (RPCS) - Unknown owner - C:\WINDOWS\rcss.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sygate Security Agent (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SSA\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

47 Posts

July 1st, 2006 15:00

Sorry for taking so much time to get back to you I was busy yesterday and the times I could manage to get on the computer it was slowed down to the point where I could get little to no work done so it took a couple of tries but I got the products un-installed heres the ComboFix log its going to be in 2 pieces, sorry.

47 Posts

July 1st, 2006 15:00

((((((((((((((((((((((((((((((((((((((((( Files Created - Last 30days ))))))))))))))))))))))))))))))))))))))))))))))


2006-07-01 09:08 45,056 C:\WINDOWS\cfg32s.dll
2006-07-01 09:08 397,312 C:\WINDOWS\cfg32p.dll
2006-07-01 09:08 102,400 C:\WINDOWS\cfg32r.dll
2006-07-01 08:40 9,956 C:\Trelew.exe
2006-07-01 08:38 3,209 C:\cmdhost.exe
2006-06-30 21:09 31,232 C:\WINDOWS\pv.exe
2006-06-30 21:09 14,336 C:\WINDOWS\settings.exe
2006-06-30 20:04 14,336 C:\install62.exe
2006-06-30 19:26 14,336 C:\install64.exe
2006-06-30 18:36 14,336 C:\install16.exe
2006-06-30 17:44 678 C:\install32.exe
2006-06-30 10:20 290,816 C:\installerwnus.exe
2006-06-30 10:02 587,776 C:\626_101.exe
2006-06-29 21:28 24,576 C:\WINDOWS\system32ssec.exe
2006-06-29 20:45 32,768 C:\WINDOWS\njeggaom.exe
2006-06-29 20:44 110,592 C:\WINDOWS\cfg32o.dll
2006-06-29 20:43 20,480 C:\stub_sca3.exe
2006-06-29 20:43 1,392,640 C:\WINDOWS\cfg32a.exe
2006-06-29 20:23 677 C:\runstd0.exe
2006-06-29 20:22 677 C:\runstd.exe
2006-06-29 18:21 12,288 C:\runme.exe
2006-06-29 10:23 24,296 C:\WINDOWS\icont.exe
2006-06-29 10:03 380,928 C:\WINDOWS\system32\WinNB58.dll
2006-06-29 10:03 32,768 C:\WINDOWS\system32\WinDmy.dll
2006-06-29 09:59 296,299 C:\drweb64.exe
2006-06-29 09:59 12,800 C:\WINDOWS\comsonie.exe
2006-06-29 09:54 114,174 C:\WINDOWS\hostsmgr.exe
2006-06-28 20:38 61,440 C:\WINDOWS\system32\aaa00000.dll
2006-06-28 20:38 1,057 C:\WINDOWS\system32\aaa00000.sys
2006-06-28 20:37 840,000 C:\WINDOWS\yxcxrlg.exe
2006-06-28 20:37 29,696 C:\WINDOWS\system32\w055fdbb.dll
2006-06-28 20:37 2,560 C:\ac3_0003.exe
2006-06-28 20:35 362,496 C:\526_620.exe
2006-06-28 20:33 48,190 C:\VSL02.exe
2006-06-28 20:02 197,096 C:\NNSCAA638.EXE
2006-06-28 20:00 30,208 C:\SS1001.exe
2006-06-28 19:59 45,056 C:\wd7gi8n.exe
2006-06-28 19:59 14,848 C:\stub_113_4_0_4_0.exe
2006-06-28 19:56 461,941 C:\visfx500.exe
2006-06-28 19:56 45,059 C:\ZIGID003.exe
2006-06-28 19:54 403,799 C:\WINDOWS\cmdmgr.exe
2006-06-28 19:54 172 C:\WINDOWS\comexec.bat
2006-06-28 09:39 32,768 C:\WINDOWS\nvplvdzv.exe
2006-06-28 08:46 61,440 C:\WINDOWS\system32\nff8742a.dll
2006-06-28 08:46 1,063 C:\WINDOWS\system32\nff8742a.sys
2006-06-28 08:37 303,104 C:\WINDOWS\system32\WinNB57.dll
2006-06-28 08:33 29,696 C:\WINDOWS\system32\w005908f.dll
2006-06-27 23:29 340 C:\WINDOWS\erqae.dll
2006-06-27 23:28 8,464 C:\WINDOWS\system32\sporder.dll
2006-06-27 23:28 45,056 C:\WINDOWS\system32tfthot.exe
2006-06-27 23:28 28,672 C:\WINDOWS\system32ftuninst.exe
2006-06-27 23:28 28,672 C:\WINDOWS\system32\gbe90qs.exe
2006-06-27 23:28 28,672 C:\WINDOWS\system32\ftuninst.exe
2006-06-27 23:26 58,880 C:\WINDOWS\rcss.exe
2006-06-19 15:39 139,264 C:\WINDOWS\876056.exe
2006-06-02 13:39 402,736 C:\WINDOWS\system32\WgaLogon.dll
2006-06-02 13:39 286,000 C:\WINDOWS\system32\WgaTray.exe
2006-05-30 18:19 2,088,960 C:\WINDOWS\cfg32.exe
2006-05-30 18:09 24,576 C:\WINDOWS\Uninstall.exe


((((((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"PTHOSTTR"="C:\\Program Files\\HPQ\\HP ProtectTools Security Manager\\PTHOSTTR.EXE /Start"
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"hpWirelessAssistant"="C:\\Program Files\\hpq\\HP Wireless Assistant\\HP Wireless Assistant.exe"
"eabconfg.cpl"="C:\\Program Files\\HPQ\\Quick Launch Buttons\\EabServr.exe /Start"
"Cpqset"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe"
"WatchDog"="C:\\Program Files\\InterVideo\\DVD Check\\DVDCheck.exe"
"IDA"="C:\\Program Files\\Hewlett-Packard\\PC COE\\IDA.EXE"
"QuickPassword"="C:\\Program Files\\ActivCard\\ActivCard Gold\\agquickp.exe"
"CognizanceTS"="rundll32.exe C:\\PROGRA~1\\HPQ\\IAM\\Bin\\AsTsVcc.dll,RegisterModule"
"CamCheck"="C:\\Program Files\\Vivitar\\V3301\\CamCheck\\CamCheck.exe"
"BearShare"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\\Program Files\\Google\\Gmail Notifier\\gnotify.exe"
"SmcService"="C:\\PROGRA~1\\Sygate\\SSA\\smc.exe -startgui"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"ftexc"="C:\\WINDOWS\\system32\\mptft.exe"
"nff8742a"="RUNDLL32.EXE w005908f.dll,n 0018742900000003005908f"
"ACTX1"="C:\\WINDOWS\\v1201.exe"
"Configuration Manager"="C:\\WINDOWS\\cfg32.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_02\\bin\\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
"flags"=dword:00000008

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex\000]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"SpySweeper"=""
"WhatPulse"="C:\\PROGRA~1\\WHATPU~1\\WHATPU~1.EXE"
"E6TaskPanel"="\"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe\" -winstart"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="http://www.wotmania.com/images/shakefist.gif"
"SubscribedURL"="http://www.wotmania.com/images/shakefist.gif"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,00,00,00,00,00,00,00,00,00,05,00,00,de,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:02,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,05,00,00,e2,03,\
00,00,02,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,05,00,00,e2,03,\
00,00,01,00,00,00

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,2e,01,00,00,23,00,00,00,a4,00,00,00,9a,00,00,00,ea,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,2e,01,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"koww"="C:\\PROGRA~1\\COMMON~1\\koww\\kowwm.exe"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"koww"="C:\\PROGRA~1\\COMMON~1\\koww\\kowwm.exe"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\IDA{07A2D605-F561-11D1-BEE5-AC785AC8CD4E}000.job
C:\WINDOWS\tasks\IDA{5B940D5F-0A3F-11D2-95B5-080009DC8202}000.job
C:\WINDOWS\tasks\IDA{5B940D5F-0A3F-11D2-95B5-080009DC8202}001.job
C:\WINDOWS\tasks\IDA{884F3959-E5F7-11D1-9B15-080009F878E4}000.job
C:\WINDOWS\tasks\IDA{E1B2A4DD-AE06-4B97-9B55-8E8F1348E7FB}000.job

Completion time: Sat 07/01/2006 11:34:03.90
ComboFix ver 06.07.02 - This logfile is located at C:\ComboFix.txt

ComboFix.2006-07-01.113346.txt

47 Posts

July 1st, 2006 15:00

Start Time= Sat 07/01/2006 11:33:46.48
Running from: C:\Documents and Settings\evanrh\My Documents\Downloads

QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log )))))))))))))))))))))))))))))))))))))))))))))))))))))


HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wzcnotif


* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\clsid\{C98A1BBC-EFBF-45FC-BCFD-B820370013F8}]
@=""

[HKEY_CLASSES_ROOT\clsid\{C98A1BBC-EFBF-45FC-BCFD-B820370013F8}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{C98A1BBC-EFBF-45FC-BCFD-B820370013F8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{C98A1BBC-EFBF-45FC-BCFD-B820370013F8}\InprocServer32]
@="C:\\WINDOWS\\system32\\mtcoree.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


FILES REMOVED:

C:\WINDOWS\SYSTEM32\lvps0977e.dll
C:\WINDOWS\SYSTEM32\mtcoree.dll
C:\WINDOWS\SYSTEM32\t48u0el9ehq.dll


Granting sedebugprivilege to Administrators ... successful


(((((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))

11:28:47.07

Not all files found by this method are bad. There may be legitimate files found
This log should be examined by a trained analyst


* * * PRE-RUN - Filepaths extracted from the Registry * * * * * * * * * * * * * * * * * * * * * *


C:\WINDOWS\system32\hbibxdm.exe


* * * PRE-RUN - Filepaths from Locate * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


2006-04-18 17:30:14 536,576 "C:\WINDOWS\system32\DivXsm.exe"
2006-04-18 17:30:28 90,112 "C:\WINDOWS\system32\dpl100.dll"
2006-04-18 17:30:28 344,064 "C:\WINDOWS\system32\dpus11.dll"
2006-04-18 17:30:28 200,704 "C:\WINDOWS\system32\dtu100.dll"
2006-05-10 00:25:22 55,808 "C:\WINDOWS\system32\extmgr.dll"
2006-05-10 00:25:22 96,256 "C:\WINDOWS\system32\inseng.dll"
2006-05-19 10:06:04 3,055,104 "C:\WINDOWS\system32\mshtml.dll"
2006-05-10 00:25:22 532,480 "C:\WINDOWS\system32\mstime.dll"
2006-05-10 00:25:22 615,424 "C:\WINDOWS\system32\urlmon.dll"
2006-06-29 10:03:16 32,768 "C:\WINDOWS\system32\WinDmy.dll"
2006-06-27 23:28:22 28,672 "C:\WINDOWS\system32\gbe90qs.exe"
2006-07-01 08:59:14 23,552 "C:\WINDOWS\system32\hbibxdm.exe"
2006-06-02 13:39:46 286,000 "C:\WINDOWS\system32\WgaTray.exe"
2006-05-10 00:25:20 151,040 "C:\WINDOWS\system32\cdfview.dll"
2006-05-10 00:25:22 357,888 "C:\WINDOWS\system32\dxtmsft.dll"
2006-05-10 00:25:22 205,312 "C:\WINDOWS\system32\dxtrans.dll"
2006-05-10 00:25:22 251,904 "C:\WINDOWS\system32\iepeers.dll"
2006-06-01 13:47:08 163,840 "C:\WINDOWS\system32\jgdw400.dll"
2006-06-01 13:47:08 27,648 "C:\WINDOWS\system32\jgpl400.dll"
2006-05-18 00:24:26 450,560 "C:\WINDOWS\system32\jscript.dll"
2006-05-10 00:25:22 15,872 "C:\WINDOWS\system32\jsproxy.dll"
2006-04-18 17:31:14 1,044,480 "C:\WINDOWS\system32\libdivx.dll"
2006-07-01 09:08:16 234,272 "C:\WINDOWS\system32\mtcoree.dll"
2006-05-10 00:25:22 39,424 "C:\WINDOWS\system32\pngfilt.dll"
2006-05-14 03:44:08 181,248 "C:\WINDOWS\system32\rasmans.dll"
2006-05-29 10:32:10 1,496,576 "C:\WINDOWS\system32\shdocvw.dll"
2006-05-10 00:25:22 474,112 "C:\WINDOWS\system32\shlwapi.dll"
2006-06-27 23:28:48 8,464 "C:\WINDOWS\system32\sporder.dll"
2006-04-18 17:31:14 200,704 "C:\WINDOWS\system32\ssldivx.dll"
2006-05-10 00:25:22 663,552 "C:\WINDOWS\system32\wininet.dll"
2006-06-28 08:37:08 303,104 "C:\WINDOWS\system32\WinNB57.dll"
2006-06-29 10:03:14 380,928 "C:\WINDOWS\system32\WinNB58.dll"
2006-05-10 00:25:20 1,054,208 "C:\WINDOWS\system32\danim.dll"
2006-04-18 17:30:28 294,912 "C:\WINDOWS\system32\dpu10.dll"
2006-04-18 17:30:28 294,912 "C:\WINDOWS\system32\dpu11.dll"
2006-04-18 17:30:28 57,344 "C:\WINDOWS\system32\dpv11.dll"
2006-07-01 08:58:58 340 "C:\WINDOWS\erqae.dll"
2006-06-07 19:32:30 4,719 "C:\WINDOWS\mozver.dat"
2006-06-30 10:21:04 53 "C:\WINDOWS\vneqbc.dat"


* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *


07/01/2006 08:59 AM 23,552 hbibxdm.exe.vir
06/30/2006 10:21 AM 53 vneqbc.dat.vir


DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO


* * * POST-RUN - Filepaths from Locate * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


2006-06-27 23:28:22 28,672 "C:\WINDOWS\system32\gbe90qs.exe"
2006-06-02 13:39:46 286,000 "C:\WINDOWS\system32\WgaTray.exe"
2006-04-18 17:30:14 536,576 "C:\WINDOWS\system32\DivXsm.exe"
2006-05-10 00:25:20 151,040 "C:\WINDOWS\system32\cdfview.dll"
2006-05-10 00:25:22 357,888 "C:\WINDOWS\system32\dxtmsft.dll"
2006-05-10 00:25:22 205,312 "C:\WINDOWS\system32\dxtrans.dll"
2006-05-10 00:25:22 251,904 "C:\WINDOWS\system32\iepeers.dll"
2006-06-01 13:47:08 163,840 "C:\WINDOWS\system32\jgdw400.dll"
2006-06-01 13:47:08 27,648 "C:\WINDOWS\system32\jgpl400.dll"
2006-05-18 00:24:26 450,560 "C:\WINDOWS\system32\jscript.dll"
2006-05-10 00:25:22 15,872 "C:\WINDOWS\system32\jsproxy.dll"
2006-04-18 17:31:14 1,044,480 "C:\WINDOWS\system32\libdivx.dll"
2006-05-10 00:25:22 39,424 "C:\WINDOWS\system32\pngfilt.dll"
2006-05-14 03:44:08 181,248 "C:\WINDOWS\system32\rasmans.dll"
2006-05-29 10:32:10 1,496,576 "C:\WINDOWS\system32\shdocvw.dll"
2006-05-10 00:25:22 474,112 "C:\WINDOWS\system32\shlwapi.dll"
2006-06-27 23:28:48 8,464 "C:\WINDOWS\system32\sporder.dll"
2006-04-18 17:31:14 200,704 "C:\WINDOWS\system32\ssldivx.dll"
2006-05-10 00:25:22 663,552 "C:\WINDOWS\system32\wininet.dll"
2006-06-28 08:37:08 303,104 "C:\WINDOWS\system32\WinNB57.dll"
2006-06-29 10:03:14 380,928 "C:\WINDOWS\system32\WinNB58.dll"
2006-04-18 17:30:28 90,112 "C:\WINDOWS\system32\dpl100.dll"
2006-04-18 17:30:28 344,064 "C:\WINDOWS\system32\dpus11.dll"
2006-04-18 17:30:28 200,704 "C:\WINDOWS\system32\dtu100.dll"
2006-05-10 00:25:22 55,808 "C:\WINDOWS\system32\extmgr.dll"
2006-05-10 00:25:22 96,256 "C:\WINDOWS\system32\inseng.dll"
2006-05-19 10:06:04 3,055,104 "C:\WINDOWS\system32\mshtml.dll"
2006-05-10 00:25:22 532,480 "C:\WINDOWS\system32\mstime.dll"
2006-05-10 00:25:22 615,424 "C:\WINDOWS\system32\urlmon.dll"
2006-06-29 10:03:16 32,768 "C:\WINDOWS\system32\WinDmy.dll"
2006-05-10 00:25:20 1,054,208 "C:\WINDOWS\system32\danim.dll"
2006-04-18 17:30:28 294,912 "C:\WINDOWS\system32\dpu10.dll"
2006-04-18 17:30:28 294,912 "C:\WINDOWS\system32\dpu11.dll"
2006-04-18 17:30:28 57,344 "C:\WINDOWS\system32\dpv11.dll"
2006-07-01 08:58:58 340 "C:\WINDOWS\erqae.dll"
2006-06-07 19:32:30 4,719 "C:\WINDOWS\mozver.dat"


((((((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\drsmartload1.exe
C:\drsmartload45m.exe
C:\drsmartload45n.exe
C:\drsmartload45o.exe
C:\drsmartload45p.exe
C:\drsmartload45q.exe
C:\drsmartload46m.exe
C:\drsmartload46n.exe
C:\drsmartload46o.exe
C:\drsmartload46p.exe
C:\drsmartload849m.exe
C:\drsmartload849n.exe
C:\drsmartload849o.exe
C:\drsmartload849p.exe
C:\dfndrb_3.exe
C:\dfndrc_2.exe
C:\nwnmb_2.exe
C:\nwnmb_3.exe
C:\kybrdb_3.exe
C:\kybrdc_2.exe
C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\XJ2CPHF4\drsmartload45a[1].exe
C:\RECYCLER\S-1-5-21-1215972812-3613370904-3328117264-1005\Dc1074\dfndrc_2[1].exe
C:\RECYCLER\S-1-5-21-1215972812-3613370904-3328117264-1005\Dc1075\Mendoza1[1].exe
C:\WINDOWS\drsmartload2.dat
C:\WINDOWS\newname.dat
C:\WINDOWS\keyboard1.dat
C:\MTE3NDI6ODoxNg.exe
C:\warebundle2.exe
C:\WINDOWS\MTE3NDI6ODoxNg.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-07-01 11:32:14 3209 ( A.... ) "C:\cmdhost.exe"
2006-07-01 09:12:36 1063 ( A.... ) "C:\WINDOWS\system32\nff8742a.sys"
2006-07-01 09:12:36 1063 ( A.... ) "C:\WINDOWS\system32\nff8742a.sys"
2006-07-01 09:08:58 102400 ( A.... ) "C:\WINDOWS\cfg32r.dll"
2006-07-01 09:08:56 45056 ( A.... ) "C:\WINDOWS\cfg32s.dll"
2006-07-01 09:08:54 397312 ( A.... ) "C:\WINDOWS\cfg32p.dll"
2006-07-01 08:58:58 340 ( A.... ) "C:\WINDOWS\erqae.dll"
2006-07-01 08:45:00 9956 ( A.... ) "C:\Trelew.exe"
2006-06-30 20:07:30 14336 ( A.... ) "C:\install64.exe"
2006-06-30 20:04:54 14336 ( A.... ) "C:\install62.exe"
2006-06-30 19:10:36 14336 ( A.... ) "C:\install16.exe"
2006-06-30 18:17:16 678 ( A.... ) "C:\install32.exe"
2006-06-30 10:20:58 290816 ( A.... ) "C:\installerwnus.exe"
2006-06-30 10:06:02 587776 ( A.... ) "C:\626_101.exe"
2006-06-30 01:30:58 14336 ( A.... ) "C:\WINDOWS\settings.exe"
2006-06-29 21:28:08 24576 ( A.... ) "C:\WINDOWS\system32ssec.exe"
2006-06-29 20:45:16 32768 ( A.... ) "C:\WINDOWS\njeggaom.exe"
2006-06-29 20:44:42 110592 ( A.... ) "C:\WINDOWS\cfg32o.dll"
2006-06-29 20:44:18 ( .D... ) "C:\Program Files\PartyPoker"
2006-06-29 20:43:58 1392640 ( A.... ) "C:\WINDOWS\cfg32a.exe"
2006-06-29 20:43:24 20480 ( A.... ) "C:\stub_sca3.exe"
2006-06-29 20:23:38 677 ( A.... ) "C:\runstd0.exe"
2006-06-29 20:22:44 677 ( A.... ) "C:\runstd.exe"
2006-06-29 18:21:34 12288 ( A.... ) "C:\runme.exe"
2006-06-29 10:23:20 24296 ( A.... ) "C:\WINDOWS\icont.exe"
2006-06-29 10:03:16 32768 ( A.... ) "C:\WINDOWS\system32\WinDmy.dll"
2006-06-29 10:03:14 380928 ( A.... ) "C:\WINDOWS\system32\WinNB58.dll"
2006-06-29 09:59:48 296299 ( A.... ) "C:\drweb64.exe"
2006-06-28 20:38:08 61440 ( A.... ) "C:\WINDOWS\system32\aaa00000.dll"
2006-06-28 20:38:08 1057 ( A.... ) "C:\WINDOWS\system32\aaa00000.sys"
2006-06-28 20:38:08 1057 ( A.... ) "C:\WINDOWS\system32\aaa00000.sys"
2006-06-28 20:37:38 29696 ( A.... ) "C:\WINDOWS\system32\w055fdbb.dll"
2006-06-28 20:37:28 2560 ( A.... ) "C:\ac3_0003.exe"
2006-06-28 20:37:24 362496 ( A.... ) "C:\526_620.exe"
2006-06-28 20:33:16 48190 ( A.... ) "C:\VSL02.exe"
2006-06-28 20:02:50 197096 ( A.... ) "C:\NNSCAA638.EXE"
2006-06-28 20:01:50 30208 ( A.... ) "C:\SS1001.exe"
2006-06-28 20:00:04 45056 ( A.... ) "C:\wd7gi8n.exe"
2006-06-28 19:59:58 14848 ( A.... ) "C:\stub_113_4_0_4_0.exe"
2006-06-28 19:59:48 461941 ( A.... ) "C:\visfx500.exe"
2006-06-28 19:56:34 45059 ( A.... ) "C:\ZIGID003.exe"
2006-06-28 09:39:24 32768 ( A.... ) "C:\WINDOWS\nvplvdzv.exe"
2006-06-28 08:46:52 61440 ( A.... ) "C:\WINDOWS\system32\nff8742a.dll"
2006-06-28 08:37:08 303104 ( A.... ) "C:\WINDOWS\system32\WinNB57.dll"
2006-06-28 08:33:32 29696 ( A.... ) "C:\WINDOWS\system32\w005908f.dll"
2006-06-27 23:28:48 8464 ( A.... ) "C:\WINDOWS\system32\sporder.dll"
2006-06-27 23:28:22 45056 ( A.... ) "C:\WINDOWS\system32tfthot.exe"
2006-06-27 23:28:22 28672 ( A.... ) "C:\WINDOWS\system32ftuninst.exe"
2006-06-27 23:28:22 28672 ( A.... ) "C:\WINDOWS\system32\gbe90qs.exe"
2006-06-27 23:28:20 28672 ( A.... ) "C:\WINDOWS\system32\ftuninst.exe"
2006-06-27 18:06:50 ( .D... ) "C:\Program Files\WinRAR"
2006-06-27 16:30:52 172 ( A.... ) "C:\WINDOWS\comexec.bat"
2006-06-27 16:22:54 12800 ( A.... ) "C:\WINDOWS\comsonie.exe"
2006-06-27 16:04:42 ( .D... ) "C:\Program Files\Spybot - Search & Destroy"
2006-06-27 15:05:44 ( .D... ) "C:\Program Files\BitComet"
2006-06-24 12:24:58 ( .D... ) "C:\Documents and Settings\evanrh\Application Data\yoclient"
2006-06-23 22:05:42 ( .D... ) "C:\Documents and Settings\evanrh\Application Data\Publish Providers"
2006-06-23 22:05:20 ( .D... ) "C:\Documents and Settings\evanrh\Application Data\Sony"
2006-06-23 22:02:18 ( .D... ) "C:\Program Files\Vstplugins"
2006-06-23 22:01:18 ( .D... ) "C:\Program Files\Sony"
2006-06-21 18:56:42 ( .D... ) "C:\Program Files\iPod"
2006-06-20 17:32:50 58880 ( ..SHR ) "C:\WINDOWS\rcss.exe"
2006-06-19 15:39:16 139264 ( A.... ) "C:\WINDOWS\876056.exe"
2006-06-16 00:01:54 ( .D... ) "C:\Program Files\NVIDIA Corporation"
2006-06-14 22:01:56 403799 ( A.... ) "C:\WINDOWS\cmdmgr.exe"
2006-06-14 21:03:46 114174 ( A.... ) "C:\WINDOWS\hostsmgr.exe"
2006-06-08 20:19:50 5967776 ( A.... ) "C:\WINDOWS\system32\MRT.exe"
2006-06-08 07:22:28 ( .D... ) "C:\Program Files\Common Files\AOL"
2006-06-02 13:39:54 579888 ( A.... ) "C:\WINDOWS\system32\LegitCheckControl.dll"
2006-06-02 13:39:46 402736 ( ..... ) "C:\WINDOWS\system32\WgaLogon.dll"
2006-06-02 13:39:46 286000 ( ..... ) "C:\WINDOWS\system32\WgaTray.exe"
2006-06-01 13:47:08 163840 ( A.... ) "C:\WINDOWS\system32\jgdw400.dll"
2006-06-01 13:47:08 27648 ( A.... ) "C:\WINDOWS\system32\jgpl400.dll"
2006-05-30 18:19:18 2088960 ( A.... ) "C:\WINDOWS\cfg32.exe"
2006-05-30 18:09:20 24576 ( A.... ) "C:\WINDOWS\Uninstall.exe"
2006-05-29 10:32:10 1496576 ( A.... ) "C:\WINDOWS\system32\shdocvw.dll"
2006-05-19 10:06:04 3055104 ( A.... ) "C:\WINDOWS\system32\mshtml.dll"
2006-05-18 00:24:26 450560 ( A.... ) "C:\WINDOWS\system32\jscript.dll"
2006-05-14 03:44:08 181248 ( A.... ) "C:\WINDOWS\system32\rasmans.dll"
2006-05-11 03:37:26 90112 ( A.... ) "C:\WINDOWS\system32\xpsp3res.dll"
2006-05-10 00:25:22 663552 ( A.... ) "C:\WINDOWS\system32\wininet.dll"
2006-05-10 00:25:22 615424 ( A.... ) "C:\WINDOWS\system32\urlmon.dll"
2006-05-10 00:25:22 532480 ( A.... ) "C:\WINDOWS\system32\mstime.dll"
2006-05-10 00:25:22 474112 ( A.... ) "C:\WINDOWS\system32\shlwapi.dll"
2006-05-10 00:25:22 448512 ( A.... ) "C:\WINDOWS\system32\mshtmled.dll"
2006-05-10 00:25:22 357888 ( A.... ) "C:\WINDOWS\system32\dxtmsft.dll"
2006-05-10 00:25:22 251904 ( A.... ) "C:\WINDOWS\system32\iepeers.dll"
2006-05-10 00:25:22 205312 ( A.... ) "C:\WINDOWS\system32\dxtrans.dll"
2006-05-10 00:25:22 146432 ( A.... ) "C:\WINDOWS\system32\msrating.dll"
2006-05-10 00:25:22 96256 ( A.... ) "C:\WINDOWS\system32\inseng.dll"
2006-05-10 00:25:22 55808 ( A.... ) "C:\WINDOWS\system32\extmgr.dll"
2006-05-10 00:25:22 39424 ( A.... ) "C:\WINDOWS\system32\pngfilt.dll"
2006-05-10 00:25:22 15872 ( A.... ) "C:\WINDOWS\system32\jsproxy.dll"
2006-05-10 00:25:20 1054208 ( A.... ) "C:\WINDOWS\system32\danim.dll"
2006-05-10 00:25:20 1022976 ( A.... ) "C:\WINDOWS\system32\browseui.dll"
2006-05-10 00:25:20 151040 ( A.... ) "C:\WINDOWS\system32\cdfview.dll"
2006-04-29 06:07:48 5533696 ( A.... ) "C:\WINDOWS\system32\wmp.dll"
2006-04-19 15:09:20 778240 ( A.... ) "C:\WINDOWS\system32\divx_xx0c.dll"
2006-04-19 15:09:20 778240 ( A.... ) "C:\WINDOWS\system32\divx_xx07.dll"
2006-04-19 15:09:20 761856 ( A.... ) "C:\WINDOWS\system32\divx_xx11.dll"
2006-04-19 15:09:20 619156 ( A.... ) "C:\WINDOWS\system32\DivX.dll"
2006-04-18 17:31:14 1044480 ( A.... ) "C:\WINDOWS\system32\libdivx.dll"
2006-04-18 17:31:14 200704 ( A.... ) "C:\WINDOWS\system32\ssldivx.dll"
2006-04-18 17:30:58 3596288 ( A.... ) "C:\WINDOWS\system32\qt-dx331.dll"
2006-04-18 17:30:30 53248 ( A.... ) "C:\WINDOWS\system32\dpuGUI10.dll"
2006-04-18 17:30:28 593920 ( A.... ) "C:\WINDOWS\system32\dpuGUI11.dll"
2006-04-18 17:30:28 344064 ( A.... ) "C:\WINDOWS\system32\dpus11.dll"
2006-04-18 17:30:28 294912 ( A.... ) "C:\WINDOWS\system32\dpu11.dll"
2006-04-18 17:30:28 294912 ( A.... ) "C:\WINDOWS\system32\dpu10.dll"
2006-04-18 17:30:28 200704 ( A.... ) "C:\WINDOWS\system32\dtu100.dll"
2006-04-18 17:30:28 90112 ( A.... ) "C:\WINDOWS\system32\dpl100.dll"
2006-04-18 17:30:28 57344 ( A.... ) "C:\WINDOWS\system32\dpv11.dll"
2006-04-18 17:30:14 536576 ( A.... ) "C:\WINDOWS\system32\DivXsm.exe"
2006-04-10 13:37:12 118784 ( A.... ) "C:\WINDOWS\system32\DivXCodecUpdateChecker.exe"

47 Posts

July 1st, 2006 15:00

Sorry for taking so much time to get back to you I was busy yesterday and the times I could manage to get on the computer it was slowed down to the point where I could get little to no work done so it took a couple of tries but I got the products un-installed. The ComboFix log will be in the next post, I'll post the HJT log in the next post after that along with any previously un-identified software I've found on my machine.

July 1st, 2006 16:00

1. Please download, install, and update Ewido anti-spyware

  1. Load Ewido and then click the Update tab at the top. Under Manual Update click Start update.
  2. After the update finishes (the status bar at the bottom will display "Update successful")
  3. Close Ewido. Do not run it yet.

  4. 2. Please download Brute Force Uninstaller to your desktop.
    • Right click the BFU folder on your desktop, and choose Extract All
    • Click "Next"
    • In the box to choose where to extract the files to, click "Browse"
    • Click on the + sign next to "My Computer"
    • Click on "Local Disk (C:) or whatever your primary drive is
    • Click "Make New Folder"
    • Type in BFU
    • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
    3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcan worm remover. Save it in the same folder you made earlier (c:\BFU).

    Do not do anything with these yet!

    3. Please reboot your computer into Safe Mode. To boot into Safe Mode, please restart your computer. Tap F8 before Windows loads. Select Safe Mode on the screen that appears.

    4. Once in Safe Mode, please go to Start > My Computer and navigate to the C:\BFU folder.
    • Start the Brute Force Uninstaller by doubleclicking BFU.exe
    • Next to the scriptline to execute field click the folder icon and select alcanshorty.bfu
    • Press Execute and let it do its job. (You ought to see a progress bar if you did this correctly.)
    • Wait for the complete script execution box to pop up and press OK.
    • Press exit to terminate the BFU program.

    5. Ewido Scan
    • Then run Ewido and click on the Scanner tab at the top and then click on Complete System Scan. This scan can take quite a while to run, so be prepared.
    • Ewido will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. Ewido will display "All actions have been applied" on the right hand side.
    • Click on "Save Report", then "Save Report As". This will create a text file. Make sure you know where to find this file again (like on the Desktop).
    • Restart back into Normal Mode.

    Please go HERE to run Panda's ActiveScan
    • Once you are on the Panda site click the Scan your PC button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

    in your next post, please include
    • new hijackthis log
    • ewido log
    • panda log

47 Posts

July 2nd, 2006 15:00

I would have posted back sooner, but the PandaScan isn't working, when it finishes downloading and updating and I'm supposed to go and select My Computer I go and click My Computer and it doesn't do anything, but it says errors on page down at the bottom.

July 2nd, 2006 16:00

substitude kaspersky for panda:


Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT

  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    • Extended (if available otherwise Standard)
    • Scan Options:
    • Scan ArchivesScan Mail Bases
    • Click OK
    • Now under select a target to scan:
      • Select My Computer
    • This will program will start and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete it will display if your system has been infected.
      • Now click on the Save as Text button:
    • Save the file to your desktop.
    • Copy and paste that information in your next post.

    47 Posts

    July 2nd, 2006 23:00

    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0105322.exe NSIS: infected - 1 skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0105322.exe UPX: infected - 1 skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0105322.exe PE_Patch.UPX: infected - 1 skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0105327.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0106328.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0107322.exe/hostsmgr.exe/BAT Infected: Trojan.BAT.KillAV.cr skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0107322.exe/hostsmgr.exe Infected: Trojan.BAT.KillAV.cr skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0107322.exe/settings.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0107322.exe Instyler: infected - 3 skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0107327.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0108326.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0109341.exe Infected: Trojan-Dropper.Win32.Agent.hl skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0109407.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0109494.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0109495.dll Infected: Trojan-Downloader.Win32.Agent.agw skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0109496.exe Infected: Trojan-Downloader.Win32.Qoologic.c skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0109510.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0109511.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0109512.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0109513.dll Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110540.exe Infected: Trojan-Downloader.Win32.VB.agk skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110541.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110542.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110543.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110544.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110545.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110546.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110547.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110548.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110549.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110550.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110551.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110552.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110553.exe Infected: Trojan-Downloader.Win32.VB.afv skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110554.exe Infected: Trojan-Downloader.Win32.VB.afv skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110555.exe Infected: Trojan-Clicker.Win32.VB.fc skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110556.exe Infected: Trojan-Downloader.Win32.Adload.cm skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110557.exe Infected: Backdoor.Win32.VB.ary skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110558.exe Infected: Trojan-Downloader.Win32.VB.agi skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110559.exe Infected: Trojan-Downloader.Win32.VB.afv skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110561.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110563.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110575.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110614.pif Infected: Backdoor.Win32.SdBot.aad skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110618.exe Infected: Trojan-Downloader.Win32.VB.agk skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110619.pif Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110620.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110621.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110625.exe Infected: Trojan-Downloader.Win32.Agent.ala skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110626.exe Infected: Trojan-Dropper.Win32.Agent.hl skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110628.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110629.exe Infected: Trojan-Downloader.Win32.VB.afv skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110630.exe Infected: Trojan-Downloader.Win32.VB.agi skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110654.exe Infected: Trojan-Dropper.Win32.Small.qn skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110656.exe Infected: Trojan-Clicker.Win32.VB.is skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110719.exe Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110720.exe/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110720.exe/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110720.exe NSIS: infected - 2 skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0110722.exe Infected: Trojan-Dropper.Win32.Small.qn skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0111584.exe Infected: Trojan-Dropper.Win32.Mudrop.bq skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0111585.exe Infected: Trojan-Dropper.Win32.Agent.mu skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0111586.exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0111587.exe Infected: Trojan-Downloader.Win32.Agent.ala skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0111588.exe Infected: Trojan.Win32.Runner.h skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0112608.exe Infected: Backdoor.Win32.SdBot.aad skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0112609.exe Infected: Trojan-Downloader.Win32.Small.ajc skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0113598.exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0119645.dll Infected: Trojan-Downloader.Win32.Small.ctp skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0119647.dll Infected: Trojan-Downloader.Win32.Agent.agw skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP289\A0119648.exe Infected: Trojan-Downloader.Win32.Qoologic.c skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP290\change.log Object is locked skipped
    C:\VSL02.exe/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped
    C:\VSL02.exe/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped
    C:\VSL02.exe NSIS: infected - 2 skipped
    C:\VSL02new.exe/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped
    C:\VSL02new.exe/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped
    C:\VSL02new.exe NSIS: infected - 2 skipped
    C:\wd7gi8nnew.exe Infected: Trojan-Downloader.Win32.Agent.ala skipped
    C:\WINDOWS\0313.INS/BAT Infected: Trojan.BAT.KillAV.cr skipped
    C:\WINDOWS\0313.INS QuickBatch: infected - 1 skipped
    C:\WINDOWS\0313.INS PECompact: infected - 1 skipped
    C:\WINDOWS\0313.INS PecBundle: infected - 1 skipped
    C:\WINDOWS\0313.INS PE_Patch.PECompact: infected - 1 skipped
    C:\WINDOWS\86102025.INS/data0001 Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\WINDOWS\86102025.INS NSIS: infected - 1 skipped
    C:\WINDOWS\86102025.INS UPX: infected - 1 skipped
    C:\WINDOWS\86102025.INS PE_Patch.UPX: infected - 1 skipped
    C:\WINDOWS\cmdmgr.exe/hostsmgr.exe/BAT Infected: Trojan.BAT.KillAV.cr skipped
    C:\WINDOWS\cmdmgr.exe/hostsmgr.exe Infected: Trojan.BAT.KillAV.cr skipped
    C:\WINDOWS\cmdmgr.exe/mc-110-12-0000488.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\WINDOWS\cmdmgr.exe/mc-110-12-0000488.exe Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\WINDOWS\cmdmgr.exe Instyler: infected - 4 skipped
    C:\WINDOWS\comsonie.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\WINDOWS\CSC\00000001 Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\hostsmgr.exe/BAT Infected: Trojan.BAT.KillAV.cr skipped
    C:\WINDOWS\hostsmgr.exe QuickBatch: infected - 1 skipped
    C:\WINDOWS\hostsmgr.exe PECompact: infected - 1 skipped
    C:\WINDOWS\hostsmgr.exe PecBundle: infected - 1 skipped
    C:\WINDOWS\hostsmgr.exe PE_Patch.PECompact: infected - 1 skipped
    C:\WINDOWS\MTE3NDI6ODoxNg.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\settings.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\appcom.dll Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\Credenti.evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\dmonwv.dll Infected: Trojan-Downloader.Win32.Agent.agw skipped
    C:\WINDOWS\system32\eeent.dll Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\jt4s07h7e.dll Object is locked skipped
    C:\WINDOWS\system32\k608lgdu1608.dll Object is locked skipped
    C:\WINDOWS\system32\o866lijs18o6.dll Object is locked skipped
    C:\WINDOWS\system32\removefunc.ram/hostsmgr.exe/BAT Infected: Trojan.BAT.KillAV.cr skipped
    C:\WINDOWS\system32\removefunc.ram/hostsmgr.exe Infected: Trojan.BAT.KillAV.cr skipped
    C:\WINDOWS\system32\removefunc.ram/settings.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\WINDOWS\system32\removefunc.ram Instyler: infected - 3 skipped
    C:\WINDOWS\system32\waps.dll Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\system32\wgpns.dll Object is locked skipped
    C:\WINDOWS\Temp\Cookies\index.dat Object is locked skipped
    C:\WINDOWS\Temp\f333921.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\WINDOWS\Temp\F7BB.tmp/mptft.exe Infected: Trojan.Win32.StartPage.ajj skipped
    C:\WINDOWS\Temp\F7BB.tmp CAB: infected - 1 skipped
    C:\WINDOWS\Temp\History\History.IE5\index.dat Object is locked skipped
    C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\WINDOWS\unwn.exe Infected: Trojan-Downloader.Win32.Qoologic.c skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped
    Scan process completed.

    47 Posts

    July 2nd, 2006 23:00

    C:\picture012.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
    C:\Program Files\ComPlus Applications\pohohy.html Infected: Trojan-Clicker.Win32.Small.jf skipped
    C:\Program Files\ewido anti-spyware 4.0\ewido.dmp Object is locked skipped
    C:\Program Files\Movie Maker\mezotemy.dll Infected: Trojan-Downloader.Win32.Small.ctp skipped
    C:\Program Files\Movie Maker\mezotemy.dll.exe Infected: Trojan-Downloader.Win32.Small.ajc skipped
    C:\Program Files\Sygate\SSA\debug.log Object is locked skipped
    C:\Program Files\Sygate\SSA\rawlog.log Object is locked skipped
    C:\Program Files\Sygate\SSA\seclog.log Object is locked skipped
    C:\Program Files\Sygate\SSA\syslog.log Object is locked skipped
    C:\Program Files\Sygate\SSA\tralog.log Object is locked skipped
    C:\Program Files\symantec antivirus\SAVRT\0319NAV~.TMP Object is locked skipped
    C:\Program Files\symantec antivirus\SAVRT\0553NAV~.TMP Object is locked skipped
    C:\Program Files\symantec antivirus\SAVRT\0688NAV~.TMP Object is locked skipped
    C:\Program Files\symantec antivirus\SAVRT\0731NAV~.TMP Object is locked skipped
    C:\runme.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\SS1001new.exe Infected: Trojan-Dropper.Win32.Small.qn skipped
    C:\stub_113_4_0_4_0new.exe Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\tracking.log Object is locked skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0088513.exe Infected: Trojan-Downloader.Win32.Small.ajc skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089102.exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089120.dll Infected: Trojan-Downloader.Win32.Agent.agw skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089121.exe Infected: Trojan-Downloader.Win32.Qoologic.c skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089128.exe Infected: Trojan-Clicker.Win32.VB.fc skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089143.exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089161.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089164.dll Infected: Trojan-Downloader.Win32.Agent.agw skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089165.exe Infected: Trojan-Downloader.Win32.Qoologic.c skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089194.exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089207.exe Infected: Trojan-Downloader.Win32.VB.agk skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089215.exe Infected: Trojan-Downloader.Win32.Small.ajc skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089216.dll Infected: Trojan-Downloader.Win32.Agent.agw skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP285\A0089217.exe Infected: Trojan-Downloader.Win32.Qoologic.c skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP286\A0090195.exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0091296.exe Infected: Trojan-Clicker.Win32.VB.is skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0091297.exe Infected: Trojan.Win32.Runner.h skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0091298.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0091299.exe Infected: Trojan.Win32.Runner.h skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0092271.exe Infected: Trojan-Clicker.Win32.VB.is skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0092273.exe Infected: Trojan.Win32.Runner.h skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093282.exe/data.rar/cmdmgr.exe/hostsmgr.exe/BAT Infected: Trojan.BAT.KillAV.cr skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093282.exe/data.rar/cmdmgr.exe/hostsmgr.exe Infected: Trojan.BAT.KillAV.cr skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093282.exe/data.rar/cmdmgr.exe/mc-110-12-0000488.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093282.exe/data.rar/cmdmgr.exe/mc-110-12-0000488.exe Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093282.exe/data.rar/cmdmgr.exe Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093282.exe/data.rar/comsonie.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093282.exe/data.rar Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093282.exe RarSFX: infected - 7 skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093283.exe/hostsmgr.exe/BAT Infected: Trojan.BAT.KillAV.cr skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093283.exe/hostsmgr.exe Infected: Trojan.BAT.KillAV.cr skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093283.exe/mc-110-12-0000488.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093283.exe/mc-110-12-0000488.exe Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093283.exe Instyler: infected - 4 skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093285.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0093287.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0094278.exe/hostsmgr.exe/BAT Infected: Trojan.BAT.KillAV.cr skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0094278.exe/hostsmgr.exe Infected: Trojan.BAT.KillAV.cr skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0094278.exe/mc-110-12-0000488.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0094278.exe/mc-110-12-0000488.exe Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0094278.exe Instyler: infected - 4 skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0095318.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0095319.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0095320.dll Infected: Trojan-Downloader.Win32.Agent.agw skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0095321.exe Infected: Trojan-Downloader.Win32.Qoologic.c skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0096289.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0096290.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0096291.dll Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP287\A0096292.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0096309.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0097289.exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0097299.dll Infected: Trojan-Downloader.Win32.Agent.agw skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0097300.exe Infected: Trojan-Downloader.Win32.Qoologic.c skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0099327.exe Infected: Trojan-Downloader.Win32.VB.agk skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0101326.exe Infected: Trojan-Downloader.Win32.VB.agk skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0102317.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0102319.exe Infected: Trojan-Downloader.Win32.VB.agk skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0102327.exe Infected: Trojan.Win32.Runner.h skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0103318.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0104317.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0104327.exe Infected: Trojan-Downloader.Win32.VB.agk skipped
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP288\A0105322.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.u skipped

    47 Posts

    July 2nd, 2006 23:00

    The log is to big for one post so it will be multiple replies long:

    KASPERSKY ONLINE SCANNER REPORT
    Sunday, July 02, 2006 5:44:30 PM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.83.0
    Kaspersky Anti-Virus database last update: 2/07/2006
    Kaspersky Anti-Virus database records: 192029
    Scan Settings
    Scan using the following antivirus database standard
    Scan Archives true
    Scan Mail Bases true
    Scan Target My Computer
    C:\
    D:\
    Scan Statistics
    Total number of scanned objects 74893
    Number of viruses found 36
    Number of infected objects 258 / 0
    Number of suspicious objects 2
    Duration of the scan process 01:18:01

    Infected Object Name Virus Name Last Action
    C:\626_101.exe Infected: Trojan-Dropper.Win32.Agent.mu skipped
    C:\626_101new.exe Infected: Trojan-Dropper.Win32.Agent.mu skipped
    C:\dfndrb_3.exe Infected: Trojan-Downloader.Win32.VB.afv skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f565b2acc5d8563245b09cfd59159dd_1713e2ff-b1f4-4407-b651-562c9e0bbf44 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89ed64102ea1e1c8f23aa392655bafd2_1713e2ff-b1f4-4407-b651-562c9e0bbf44 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bbb78300220bcb9b83c3dbaf43e6cd3b_1713e2ff-b1f4-4407-b651-562c9e0bbf44 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/MTE3NDI6ODoxNg.exe Suspicious: Password-protected-EXE skipped
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: suspicious - 1 skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03680004.VBN Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03680005.VBN/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03680005.VBN/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03680005.VBN NSIS: infected - 2 skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03680005.VBN CryptZ: infected - 2 skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03680008.VBN Infected: Trojan-Downloader.Win32.Qoologic.at skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0368000F.VBN Infected: Trojan-Dropper.Win32.Agent.hl skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08480001.VBN Infected: Trojan-Dropper.Win32.Agent.hl skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08480002.VBN Infected: Trojan-Clicker.Win32.VB.ij skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08480003.VBN Infected: Trojan-Dropper.Win32.Agent.hl skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08480004.VBN Infected: Trojan-Downloader.Win32.VB.nw skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09540000\4DF6B14B.VBN Infected: Trojan-Dropper.Win32.Agent.hl skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09540001\4DF6B4FC.VBN Infected: Trojan.Win32.StartPage.ajj skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A1C0000.VBN Infected: Trojan.Win32.StartPage.ajj skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A1C0002.VBN Infected: Trojan-Clicker.Win32.VB.ij skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A1C0003.VBN Infected: Trojan-Downloader.Win32.VB.nw skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A1C0004.VBN Infected: Trojan-Dropper.Win32.Agent.hl skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A1C0005.VBN Infected: Trojan-Dropper.Win32.Agent.hl skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AF80000\4EFD7226.VBN Infected: Trojan-Downloader.Win32.PurityScan.bg skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AF80006\4EFD7A12.VBN Infected: Trojan-Spy.Win32.SCKeyLog.o skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AF80007\4EFD7A37.VBN Infected: Trojan-Spy.Win32.SCKeyLog.o skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AF80008\4EFD7A46.VBN Infected: Trojan-Spy.Win32.SCKeyLog.o skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AF80009\4EFD7A55.VBN Infected: Trojan-Spy.Win32.SCKeyLog.o skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AF8000A\4EFD7A62.VBN Infected: Trojan-Spy.Win32.SCKeyLog.o skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AF8000B\4EFD7A70.VBN Infected: Trojan-Spy.Win32.GhostKeyLogger.b skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AF8000C\4EFD7B36.VBN Infected: Trojan.Win32.Small.cy skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B980000\4FFD241A.VBN Infected: Trojan-Downloader.Win32.Agent.acd skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BE80000\4FEA864A.VBN Infected: Trojan-Downloader.Win32.VB.afv skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CD00000\4CF2933A.VBN Infected: Trojan-Downloader.Win32.VB.afv skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00000.VBN Infected: Trojan-Downloader.Win32.VB.agk skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DCC0000\4DEE8001.VBN Infected: Trojan-Dropper.Win32.Agent.hl skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EDC0001.VBN Infected: Trojan-Clicker.Win32.VB.fc skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EDC0002.VBN Infected: Trojan-Dropper.Win32.Small.qn skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EDC0003.VBN Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EDC0004.VBN Infected: Trojan-Downloader.Win32.Small.ctp skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EDC0005.VBN Infected: Trojan-Downloader.Win32.Small.buy skipped
    C:\Documents and Settings\evanrh\Application Data\Aim\wxjffnnm\manpersonguy\cert8.db Object is locked skipped
    C:\Documents and Settings\evanrh\Application Data\Aim\wxjffnnm\manpersonguy\key3.db Object is locked skipped
    C:\Documents and Settings\evanrh\Application Data\Mozilla\Firefox\Profiles\y3u329wz.default\cert8.db Object is locked skipped
    C:\Documents and Settings\evanrh\Application Data\Mozilla\Firefox\Profiles\y3u329wz.default\formhistory.dat Object is locked skipped
    C:\Documents and Settings\evanrh\Application Data\Mozilla\Firefox\Profiles\y3u329wz.default\history.dat Object is locked skipped
    C:\Documents and Settings\evanrh\Application Data\Mozilla\Firefox\Profiles\y3u329wz.default\key3.db Object is locked skipped
    C:\Documents and Settings\evanrh\Application Data\Mozilla\Firefox\Profiles\y3u329wz.default\parent.lock Object is locked skipped
    C:\Documents and Settings\evanrh\Application Data\Sun\Java\Deployment\log\plugin150_02.trace Object is locked skipped
    C:\Documents and Settings\evanrh\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Application Data\Mozilla\Firefox\Profiles\y3u329wz.default\Cache\_CACHE_001_ Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Application Data\Mozilla\Firefox\Profiles\y3u329wz.default\Cache\_CACHE_002_ Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Application Data\Mozilla\Firefox\Profiles\y3u329wz.default\Cache\_CACHE_003_ Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Application Data\Mozilla\Firefox\Profiles\y3u329wz.default\Cache\_CACHE_MAP_ Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\A6AD.tmp/mptft.exe Infected: Trojan.Win32.StartPage.ajj skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\A6AD.tmp CAB: infected - 1 skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\f476890.exe Infected: Trojan-Downloader.Win32.Qoologic.bj skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\History\History.IE5\MSHist012006070220060703\index.dat Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\hsperfdata_evanrh\4952 Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\7JSUN18Z\drsmartload45a[1].exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\7JSUN18Z\gkyukar[1].cab/mptft.exe Infected: Trojan.Win32.StartPage.ajj skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\7JSUN18Z\gkyukar[1].cab CAB: infected - 1 skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\7JSUN18Z\wd7gi8n[1].exe Infected: Trojan-Downloader.Win32.Agent.ala skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\F3BTHVZJ\drsmartload46a[1].exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\F3BTHVZJ\installerwnus[1].exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\F3BTHVZJ\MTE3NDI6ODoxNg[1].exe Infected: Trojan-Downloader.Win32.Small.buy skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\UXVX2MHD\626_101[1].exe Infected: Trojan-Dropper.Win32.Agent.mu skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\UXVX2MHD\drsmartload849a[1].exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\UXVX2MHD\drsmartload[1].exe Infected: Trojan-Downloader.Win32.VB.agk skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\UXVX2MHD\SS1001[1].exe Infected: Trojan-Dropper.Win32.Small.qn skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\UXVX2MHD\stub_113_4_0_4_0[1].exe Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\UXVX2MHD\VSL02[1].exe/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\UXVX2MHD\VSL02[1].exe/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped
    C:\Documents and Settings\evanrh\Local Settings\Temp\Temporary Internet Files\Content.IE5\UXVX2MHD\VSL02[1].exe NSIS: infected - 2 skipped
    C:\Documents and Settings\evanrh\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\evanrh\My Documents\My Music\iTunes\iTunes Library.itl Object is locked skipped
    C:\Documents and Settings\evanrh\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\evanrh\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\evanrh\UserData\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\drsmartload1.exe Infected: Trojan-Downloader.Win32.VB.agk skipped
    C:\drsmartload45r.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\drsmartload45s.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\drsmartload46r.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\drsmartload46s.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\drsmartload849r.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\drsmartload849s.exe Infected: Trojan-Downloader.Win32.Adload.ck skipped
    C:\drweb64.exe/data.rar/cmdmgr.exe/hostsmgr.exe/BAT Infected: Trojan.BAT.KillAV.cr skipped
    C:\drweb64.exe/data.rar/cmdmgr.exe/hostsmgr.exe Infected: Trojan.BAT.KillAV.cr skipped
    C:\drweb64.exe/data.rar/cmdmgr.exe/mc-110-12-0000488.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\drweb64.exe/data.rar/cmdmgr.exe/mc-110-12-0000488.exe Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\drweb64.exe/data.rar/cmdmgr.exe Infected: Trojan-Downloader.NSIS.Agent.u skipped
    C:\drweb64.exe/data.rar/comsonie.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\drweb64.exe/data.rar Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\drweb64.exe RarSFX: infected - 7 skipped
    C:\install16.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\install62.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\install64.exe Infected: Trojan-Downloader.Win32.VB.afo skipped
    C:\installerwnusnew.exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped
    C:\kybrdb_3.exe Infected: Backdoor.Win32.VB.ary skipped
    C:\MTE3NDI6ODoxNg.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
    C:\MTE3NDI6ODoxNgnew.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
    C:\nwnmb_3.exe Infected: Trojan-Downloader.Win32.Adload.cm skipped

    July 3rd, 2006 00:00

    looks like the ewido log got cut off as well. could you post the rest of it in separate posts?

    also include a new hijackthis log in a separate post.

    thanks!
    No Events found!

    Top