This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hijack this log

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:57:38, on 14.2.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\BitDefender\BitDefender 2009\bdwizreg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [lphcng1j0ev5t] C:\WINDOWS\system32\lphcng1j0ev5t.exe
O4 - HKLM\..\Run: [in3] C:\Documents and Settings\Korisnik\Local Settings\Temp\.tt17.tmp.exe /CR=8CBA18F4F154B8E1B01AA0560819391B0311B3CA8C6C873248771327F813F04BBC19CFB881B18
30C87161805ABB29B7CD0C0A5E2A7FADE7701EA78A05D75154913EDE111980F3369E4213DBB3B2311
847E48DD66A54A
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [46865178000711279275786472985669] C:\Program Files\Antivirus 2009\av2009.exe
O4 - HKCU\..\Run: [systeminit.exe] C:\DOCUME~1\Korisnik\LOCALS~1\Temp\systeminit.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [SystemDriverLoad] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [SystemDriver] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [FDriver] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ADriver] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [CDriver] c:\z_Drivers\svchost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DDriver] c:\z_Drivers\svchost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [alpha] c:\z_Drivers\svchost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [beta] c:\z_Drivers\svchost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [gamma] c:\z_Drivers\svchost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
O24 - Desktop Component 0: (no name) - http://zena.hr/images/clanci/603.jpg

–
End of file - 6250 bytes
Hi pishulinac, welcome to the forum.

Please be advised, as I'm still in training, all my replies will have to be approved by a teacher or expert before I can post them. This may cause some delays, but I will do my best to keep them as short as possible.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
I will post back soon with additional instructions.


Thanks
Hi pishulinac,

You have 2 antivirus programs installed. This will not give you more protection. Conflicts could arise and give you less. Please uninstall either BitDefender or AVG8.

We need some file information
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file paths, one at a time into the "Suspicious files to scan" box on the top of the page:
  • wait for the results before submitting the second file
  • Please clearly identify the results for each file.

    C:\WINDOWS\system32\CTFMON.EXE
    C:\WINDOWS\system32\lphcng1j0ev5t.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Please download DDS and save it to your desktop. Do not run it yet, you will use it at the end.

You may want to print out or copy and paste the rest of these instruction into a notepad and save it to your desktop for easy reference. When you run this next tool you will be in safe mode with no access to this thread.

Next Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log
Next
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Please post back with both DDS logs, the VirSCAN.org FREE results and the SDFix report.

No need for a HJT (hijackthis) log this time.

Thanks
dear oldman960 :) i came across some problems ,first i uninstaled bitdefender as u asked,than i checked : C:\WINDOWS\system32\CTFMON.EXE in VirSCAN.org ,log is in attachment. in case of C:\WINDOWS\system32\lphcng1j0ev5t.exe after i select upload popup window is up saying ERROR: Can't find upload file! next , i cannot start windows in safe mode .after i select safe mode in options menu i get blue screen saying that i need to do dskchk on /f drive and virusscan. i attached new HJthis log if it is of any help. i rly dunno how to get rid of that blue screen and start windows in safe mode ….plx help thx for ur patience. 📎hijackthis_17.02..txt 📎scan_log___CTFMON.EXE.txt
Hi pishulinac,

You have ERUNT installed, please use it to backup your registry.

Download this file and save it to your desktop (in Internet Explorer it's right click, Save Target As)
Make sure the Save In box is set to desktop
📎user.zip
Locate user.zip on your desktop
  • right click the file and select Extract Here
  • A file named SafeBoot-for-Windows-XP-SP2.reg will now be on your desktop
  • right click it and select merge
Try booting into safe mode.

If safe mode now works, run SDFix with the instructions given earlier.

Please post back with the SDFix log and a new HJT log.

If you are still unable to enter into safe mode, please let me know. We have other tools. :)

Please only attach logs when asked to.

Thanks
hi again ,
i had a popup when i started sdfix in safe mode saying this:
c:\PROGRA~1\symantec\S32EVNT1.DLL . an installable Virtual Device Driver failed Dll initialization.Choose "close " to termiate application
and i pressed ignore and this is result bellow

SDfix log:


SDFix: Version 1.240
Run by [removed] on sri 18.02.2009 at 16:38

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\Documents and Settings\[removed]\Desktop\SDFix

Checking Services :

Name :
sysrest.sys
TDSSserv.sys

Path :
\??\C:\WINDOWS\system32\sysrest.sys
\systemroot\system32\drivers\TDSSkace.sys

sysrest.sys - Deleted
TDSSserv.sys - Deleted



Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\drivers\TDSSkace.sys - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-18 16:51:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

C:\Documents and Settings\Korisnik\Application Data\Mozilla\Firefox\Profiles\d5g2vxmn.default\places.sqlite-journal

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\u3\\Binaries\\UT3.exe"="C:\\u3\\Binaries\\UT3.exe:*:Disabled:UT3"
"C:\\Program Files\\World of Warcraft\\WoW-2.4.0.8089-to-2.4.1.8125-enGB-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.4.0.8089-to-2.4.1.8125-enGB-downloader.exe:*:Disabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.3.2.7741-to-2.3.3.7799-enGB-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.3.2.7741-to-2.3.3.7799-enGB-downloader.exe:*:Disabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Disabled:Blizzard Downloader"
"C:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\GGclient.exe"="C:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\GGclient.exe:*:Disabled:GG E-Sports Platform Client"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Disabled:Skype"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\wc3\\Warcraft III\\Warcraft III.exe"="C:\\wc3\\Warcraft III\\Warcraft III.exe:*:Disabled:Warcraft III"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Disabled:SoulSeek"
"F:\\AutoPlay\\Software\\IPUtility.exe"="F:\\AutoPlay\\Software\\IPUtility.exe:*:Enabled:IPUtility"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Documents and Settings\\Korisnik\\Local Settings\\Temp\\.ttF.tmp"="C:\\Documents and Settings\\Korisnik\\Local Settings\\Temp\\.ttF.tmp:*:Enabled:enable"
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Remaining Files :


File Backups: - C:\DOCUME~1\Korisnik\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes :

Wed 13 Oct 2004 1,694,208 ..SH. — "C:\Program Files\Messenger\msmsgs.exe"
Mon 26 Jan 2009 1,740,632 A.SHR — "C:\Program Files\Spybot - Search & Destroy2\SDUpdate.exe"
Mon 26 Jan 2009 5,365,592 A.SHR — "C:\Program Files\Spybot - Search & Destroy2\SpybotSD.exe"
Mon 26 Jan 2009 2,144,088 A.SHR — "C:\Program Files\Spybot - Search & Destroy2\TeaTimer.exe"
Wed 22 Oct 2008 962,896 A.SHR — "C:\Program Files\Spybot - Search & Destroy2\Tools.dll"
Wed 12 Jul 2006 56 ..SHR — "C:\WINDOWS\system32\CB8D06B2DB.sys"
Sat 16 Feb 2008 1,682 A.SH. — "C:\WINDOWS\system32\KGyGaAvL.sys"
Mon 28 Jan 2008 1,404,240 A.SHR — "C:\RECYCLER\S-1-5-21-1715567821-1326574676-682003330-1003\Dc21\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR — "C:\RECYCLER\S-1-5-21-1715567821-1326574676-682003330-1003\Dc21\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR — "C:\RECYCLER\S-1-5-21-1715567821-1326574676-682003330-1003\Dc21\TeaTimer.exe"
Tue 12 Jun 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

Finished!

HJthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:08:35, on 18.2.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [in3] C:\Documents and Settings\Korisnik\Local Settings\Temp\.tt17.tmp.exe /CR=8CBA18F4F154B8E1B01AA0560819391B0311B3CA8C6C873248771327F813F04BBC19CFB881B18
30C87161805ABB29B7CD0C0A5E2A7FADE7701EA78A05D75154913EDE111980F3369E4213DBB3B231
1
847E48DD66A54A
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [systeminit.exe] C:\DOCUME~1\Korisnik\LOCALS~1\Temp\systeminit.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O24 - Desktop Component 0: (no name) - http://zena.hr/images/clanci/603.jpg

–
End of file - 4453 bytes
Hi pishulinac,

i had a popup when i started sdfix in safe mode saying this:
c:\PROGRA~1\symantec\S32EVNT1.DLL . an installable Virtual Device Driver failed Dll initialization.Choose "close " to termiate application
and i pressed ignore

We'll take are of that once we get your antivirus programs sorted out. Right now the important thing is getting the junk off of your computer.

Open HJT, do a system scan only and checkmark the following if present

O4 - HKLM\..\Run: [in3] C:\Documents and Settings\Korisnik\Local Settings\Temp\.tt17.tmp.exe /CR=8CBA18F4F154B8E1B01AA0560819391B0311B3CA8C6C873248771327F813F04BBC19CFB881B18
30C87161805ABB29B7CD0C0A5E2A7FADE7701EA78A05D75154913EDE111980F3369E4213DBB3B231
1
847E48DD66A54A
O4 - HKCU\..\Run: [systeminit.exe] C:\DOCUME~1\Korisnik\LOCALS~1\Temp\systeminit.exe


Close all other browser/windows and click fixed checked. Answer Yes if prompted. Close HJT.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE
    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "in3"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "systeminit.exe"=-
    
    :Files
    C:\Documents and Settings\Korisnik\Local Settings\Temp\.tt17.tmp.exe 
    C:\DOCUME~1\Korisnik\LOCALS~1\Temp\systeminit.exe
    C:\\Documents and Settings\\Korisnik\\Local Settings\\Temp\\.ttF.tmp
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Next, Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.

Please post back with the OTMOVEIT3 log, the DR. Web report and a new HJT log.

Thanks
hello,
here are logs u asked:
1. OTMOVEIT: I had program stoped responding few times and than i would reboot and start it again and every time it went step further in scanig ,so after a few restarts here is log i hope its usefull.

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\in3 not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\systeminit.exe not found.
========== FILES ==========
File/Folder C:\Documents and Settings\Korisnik\Local Settings\Temp\.tt17.tmp.exe not found.
File/Folder C:\DOCUME~1\Korisnik\LOCALS~1\Temp\systeminit.exe not found.
File/Folder C:\\Documents and Settings\\Korisnik\\Local Settings\\Temp\\.ttF.tmp not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Korisnik\LOCALS~1\Temp\etilqs_J7asTKhoNvcPyiHcGlDu scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Korisnik\Local Settings\Application Data\Mozilla\Firefox\Profiles\d5g2vxmn.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Korisnik\Local Settings\Application Data\Mozilla\Firefox\Profiles\d5g2vxmn.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Korisnik\Local Settings\Application Data\Mozilla\Firefox\Profiles\d5g2vxmn.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Korisnik\Local Settings\Application Data\Mozilla\Firefox\Profiles\d5g2vxmn.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Korisnik\Local Settings\Application Data\Mozilla\Firefox\Profiles\d5g2vxmn.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Korisnik\Local Settings\Application Data\Mozilla\Firefox\Profiles\d5g2vxmn.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02182009_222258

2.DR.WEB: with this one i didnt rly had issue i just started scan fell asleep and saved log and in the morning i couldnt remember i finished scan so i started another one ,so igive u both:D

FIRST LOG:

SDFix.exe\SDFix\apps\Process.exe C:\Documents and Settings\Korisnik\Desktop\SDFix.exe Tool.Prockill
SDFix.exe C:\Documents and Settings\Korisnik\Desktop Archive contains infected objects Moved.
setupeng.exe/data001\data015 C:\Documents and Settings\Korisnik\Desktop\setupeng.exe/data001 Trojan.KillFiles.892
data001 C:\Documents and Settings\Korisnik\Desktop Container contains infected objects
setupeng.exe C:\Documents and Settings\Korisnik\Desktop Container contains infected objects Moved.
Process.exe C:\Documents and Settings\Korisnik\Desktop\SDFix\apps Tool.Prockill
A0471412.dll C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP359 Trojan.KillFiles.892 Deleted.
A0476252.msi/stream034\livesrv.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP364\A0476252.msi/stream034 Probably DLOADER.Trojan
stream034 C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP364 Archive contains infected objects
A0476252.msi C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP364 Archive contains infected objects Moved.
A0478615.rbf C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP367 Probably DLOADER.Trojan
A0478820.rbf/stream034\livesrv.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP367\A0478820.rbf/stream034 Probably DLOADER.Trojan
stream034 C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP367 Archive contains infected objects
A0478820.rbf C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP367 Archive contains infected objects Moved.
A0479507.exe\SDFix\apps\Process.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369\A0479507.exe Tool.Prockill
A0479507.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369 Archive contains infected objects Moved.
A0479572.exe\SDFix\apps\Process.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369\A0479572.exe Tool.Prockill
A0479572.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369 Archive contains infected objects Moved.
A0479620.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369 Tool.Prockill
A0486427.exe\SDFix\apps\Process.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369\A0486427.exe Tool.Prockill
A0486427.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369 Archive contains infected objects Moved.
A0486428.exe/data001\data015 C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369\A0486428.exe/data001 Trojan.KillFiles.892
data001 C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369 Container contains infected objects
A0486428.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369 Container contains infected objects Moved.

SECOND(LAST) LOG:

A0486430.exe C:\System Volume Information\_restore{1C4277E6-809D-46E0-BC09-391D04F9D55B}\RP369 Tool.Prockill

and the only scan i cant mess up last :)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17:27, on 19.2.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Korisnik\Desktop\drweb-cureit.exe
C:\DOCUME~1\Korisnik\LOCALS~1\Temp\RarSFX0\_start.exe
C:\DOCUME~1\Korisnik\LOCALS~1\Temp\RarSFX0\setup.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O24 - Desktop Component 0: (no name) - http://zena.hr/images/clanci/603.jpg

–
End of file - 4128 bytes
Hi

i just started scan fell asleep

Some scans can be as exciting as watching paint dry. -_-

You have remnants of previous antivirus programs. We'll clean that up then continue cleaning your computer.

Download the Norton Removal Tool from HERE and save it to your desktop.

Close all other browser and windows.

Next double click Norton_Removal_Tool.exe to run the tool.

Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.

Download and save the BitDefender Uninstall Tool to your desktop.

Double click on BitDefender_Uninstall_Tool.exe to run the tool. It may take a minute or two for the tool to start.
  • Click Uninstall;
  • Wait for the tool to display the completion message and then restart your computer

Next , Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log and a new HJT log.

Please tell us how your computer is now.

Thanks
hello again a bitsy problem occured while combofix was starting . i got a popup saying that virus ranger3.6 is still running,i tried to find removal tool for it but best i could find is a request for removal tool via e-mail ,or instructions for its removal. instructions are…. lets say no use at all couse they dont say anything about stoping virus ranger processes . so i filled request form and still havent got answer. so it would be nice if u can push me in right direction here a bit .do u wanna me to run combo fix just ignoring VR 3.6 or u have some other solution . thank u for help … like 10000 zillion times:D
Hi pishulinac,

VirusRanger is a rouge program that we will remove.

You have Malwarebytes' Anti-Malware on your computer, so we will use it.

Open MBAM
  • Click the update tab
  • Click check for updates
  • Once the program has updated, if any are found click on the Scanner tab and select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Then run combofix. If you still get a warning, please ignore it and continue the combofix scan.

Please include in your next reply the MBAM log, the combofix log, and a new HJT log.

Thanks
hi again,
i did mbam scan as u asked but it came out clean(no threats found) so i thought there is no need to paste log here.
i just ignored virus ranger in combofix scan,tho it says i dont have recovery console instaled, combofix never during its scan suggested or asked to install it ,so here are results:

ComboFix 09-02-19.01 - Korisnik 2009-02-21 11:50:28.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.1535.1066 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
AV: VirusRanger 3.6 *On-access scanning enabled* (Outdated)
FW: Kerio Personal Firewall *disabled*

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-01-21 to 2009-02-21 )))))))))))))))))))))))))))))))
.

2009-02-21 02:23 . 2009-02-21 02:24 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-21 02:23 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-21 02:23 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-19 23:06 . 2009-02-19 23:06 d——– c:\program files\Enigma Software Group
2009-02-19 22:22 . 2009-02-19 22:22 d——– c:\documents and settings\All Users\Application Data\NortonInstaller
2009-02-18 22:41 . 2009-02-18 22:55 d——– c:\documents and settings\Korisnik\DoctorWeb
2009-02-18 21:28 . 2009-02-18 21:28 d——– C:\_OTMoveIt
2009-02-18 16:31 . 2009-02-18 16:31 d——– c:\windows\ERUNT
2009-02-18 00:41 . 2009-02-18 00:41 d——– c:\documents and settings\All Users\Application Data\WinZip
2009-02-14 14:57 . 2009-02-14 14:57 d——– c:\program files\Trend Micro
2009-02-14 14:44 . 2009-02-14 14:44 d——– c:\program files\ERUNT
2009-02-14 13:55 . 2009-02-16 20:05 81,984 –a—— c:\windows\system32\bdod.bin
2009-02-14 13:47 . 2009-02-14 13:47 850 –a—— c:\windows\system32\ProductTweaks.xml
2009-02-14 13:47 . 2009-02-14 13:47 385 –a—— c:\windows\system32\user_gensett.xml
2009-02-14 13:36 . 2009-02-14 13:36 d——– c:\windows\system32\logs
2009-02-14 13:32 . 2009-02-16 20:09 d——– c:\program files\BitDefender
2009-02-11 21:58 . 2009-02-11 21:58 d——– c:\documents and settings\Korisnik\Application Data\Malwarebytes
2009-02-11 21:58 . 2009-02-11 21:58 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-11 20:36 . 2009-02-11 17:58 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-11 17:59 . 2009-02-11 17:58 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-02-11 17:56 . 2009-02-11 17:56 d——– c:\program files\Lavasoft
2009-02-11 17:56 . 2009-02-11 17:59 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-11 17:56 . 2009-02-11 17:56 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-10 20:03 . 2009-02-19 03:05 54,156 –ah—– c:\windows\QTFont.qfn
2009-02-10 20:03 . 2009-02-10 20:03 1,409 –a—— c:\windows\QTFont.for
2009-02-10 19:43 . 2009-02-10 19:43 d——– c:\program files\Bonjour
2009-02-10 19:40 . 2009-02-10 19:40 d——– c:\program files\Common Files\Kodak
2009-02-10 19:39 . 2009-02-10 19:39 d——– C:\KPCMS
2009-02-02 13:55 . 2009-02-02 13:56 d——– c:\program files\Soldier of Fortune II - Double Helix

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-20 17:08 ——— d—–w c:\program files\World of Warcraft
2009-02-11 19:46 ——— d—–w c:\program files\Spybot - Search & Destroy2
2009-02-10 18:43 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-06 09:09 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-06 09:08 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-06 09:08 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-06 15:03 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-05 14:47 ——— d—–w c:\program files\Alwil Software
2009-01-05 14:37 5,300,384 -c–a-w c:\windows\system32\drivers\fwdrv.err
2009-01-05 14:23 ——— d—–w c:\documents and settings\Korisnik\Application Data\AVGTOOLBAR
2009-01-05 10:29 ——— d—–w c:\program files\Corel
2006-01-23 15:56 0 -c–a-w c:\documents and settings\Korisnik\ignorelist.dat
1999-07-07 10:02 99,840 -c–a-w c:\program files\Common Files\IRAABOUT.DLL
1998-12-08 23:53 70,144 -c–a-w c:\program files\Common Files\IRAMDMTR.DLL
1998-12-08 23:53 48,640 -c–a-w c:\program files\Common Files\IRALPTTR.DLL
1998-12-08 23:53 31,744 -c–a-w c:\program files\Common Files\IRAWEBTR.DLL
1998-12-08 23:53 186,368 -c–a-w c:\program files\Common Files\IRAREG.DLL
1998-12-08 23:53 17,920 -c–a-w c:\program files\Common Files\IRASRIAL.DLL
2006-07-12 12:05 56 –sh–r c:\windows\system32\CB8D06B2DB.sys
2008-02-16 19:14 1,682 –sha-w c:\windows\system32\KGyGaAvL.sys
2007-05-08 20:48 3,723,808 –sha-w c:\windows\system32\drivers\fidbox.dat
2007-05-08 20:48 10,272 –sha-w c:\windows\system32\drivers\fidbox2.dat
.

——- Sigcheck ——-

2005-03-01 16:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2004-08-04 00:05 2056832 947fb1d86d14afcffdb54bf837ec25d0 c:\windows\$NtUninstallKB890859$\ntkrnlpa.exe
2006-12-19 13:55 2057600 1d659bfb788ed2ba45075624b748d249 c:\windows\Driver Cache\i386\ntkrnlpa.exe
2006-12-19 13:55 2057600 1d659bfb788ed2ba45075624b748d249 c:\windows\system32\ntkrnlpa.exe
2006-12-19 13:55 2057600 1d659bfb788ed2ba45075624b748d249 c:\windows\system32\dllcache\ntkrnlpa.exe

2005-03-02 02:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2004-08-03 22:20 2180992 ce218bc7088681faa06633e218596ca7 c:\windows\$NtUninstallKB890859$\ntoskrnl.exe
2006-12-19 15:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f c:\windows\Driver Cache\i386\ntoskrnl.exe
2006-12-19 15:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f c:\windows\system32\ntoskrnl.exe
2006-12-19 15:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f c:\windows\system32\dllcache\ntoskrnl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-06 1601304]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-11 509784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-03 c:\windows\system32\narrator.exe]

c:\documents and settings\Korisnik\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-02 180224]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 16423]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-06 10:08 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera\0lsdelete

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\World of Warcraft\\WoW-2.4.0.8089-to-2.4.1.8125-enGB-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.3.2.7741-to-2.3.3.7799-enGB-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-11 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-05 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-05 107272]
R1 fwdrv;Firewall Driver;c:\windows\system32\drivers\fwdrv.sys [2004-11-02 262144]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-05 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-05 298264]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\drivers\RMSPPPOE.SYS [2002-10-03 31504]
S0 Hdm40;Hdm40; [x]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt –> c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [?]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70e45706-75a7-11db-8d01-000000000000}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com g:
\Shell\Open\command - g:\resycled\boot.com g:

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0113fda-d9c4-11dd-b865-0013d463354b}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com g:
\Shell\Open\command - "res
.
Contents of the 'Scheduled Tasks' folder

2009-02-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-11 17:58]
.
.
——- Supplementary Scan ——-
.
uStart Page =
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Korisnik\Application Data\Mozilla\Firefox\Profiles\d5g2vxmn.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-21 12:02:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(644)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-02-21 12:10:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-21 11:10:17
ComboFix2.txt 2009-02-21 10:35:08

Pre-Run: 10.066.272.256 bytes free
Post-Run: 10,048,831,488 bytes free

196

and HJTlog:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:18, on 21.2.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O24 - Desktop Component 0: (no name) - http://zena.hr/images/clanci/603.jpg

–
End of file - 4088 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI