This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Need assistance removing Trojan and Rootkit Malware

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have ZoneAlarm Antivirus and it says that it has quarantined the Trojan.Win32.Inject.yrx virus, because it can't treat it. I also appear to have the following in the quarantine:

Rootkit.win32.agent.ex in c:\windows\new_drv.sys
Trojan.win32.inject.yrx in c:\windows\system32\wbem\grpconv.exe

I followed some suggestions that I found online a day or two ago and thought that I had removed the malware, but it appears that I was not successful since the scan turned up the Trojan.Win32.Inject.yrx virus again today, this time in C:\system volume information\_restore…

Here is the log from ZoneAlarm from several days ago.

ZoneAlarm Logging Client v8.0.298.035
Windows XP-5.1.2600-Service Pack 3-SP
type,date,time,source,destination,transport (Security)
type,date,time,virus name,file name,mode,e-mail id (Anti-Virus)
type,date,time,source,destination,action,service (IM Security)
type,date,time,source,destination,program,action (Malicious Code Protection)
type,date,time,action,product,file,event,subevent,class,data,data,… (OSFirewall)
type,date,time,name,type,mode (Anti-Spyware)
AV/update,2009/05/11,08:56:58 -7:00 GMT,,Update Install Completed,Auto
AV/scan,2009/05/11,11:18:06 -7:00 GMT,Multiple Files,Scan Completed,Manual
AV/treatment,2009/05/11,11:49:04 -7:00 GMT,Trojan.Win32.Inject.yrx,C:\System Volume Information\_restore{E1F2B311-CC84-41E9-81DA-CD0CB74D5B28}\RP858\A0139792.exe,File Repair Failed,Auto
,2009/05/11,11:49:04 -7:00 GMT,
AV/update,2009/05/11,11:58:52 -7:00 GMT,,Update Install Completed,Auto
,2009/05/11,12:09:24 -7:00 GMT,
,2009/05/11,12:09:34 -7:00 GMT,
,2009/05/11,12:09:36 -7:00 GMT,
,2009/05/11,12:09:44 -7:00 GMT,
,2009/05/11,14:49:08 -7:00 GMT,
FWOUT,2009/05/11,14:49:38 -7:00 GMT,192.168.1.101:1028,68.87.69.146:53,UDP
OSFW,2009/05/11,14:50:00 -7:00 GMT,UNKNOWN(0),wpv811242077638.exe,C:\WINDOWS\Temp\wpv811242077638.exe,REGISTRY,SETVALUE,SRC,HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN,ttool
PE,2009/05/11,14:50:10 -7:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,0.0.0.0:135,N/A
OSFW,2009/05/11,14:50:20 -7:00 GMT,UNKNOWN(0),wpv811242077638.exe,C:\WINDOWS\Temp\wpv811242077638.exe,PROCESS,SPAWNPROCESS,SRC,C:\WINDOWS\system32\cmd.exe,8000058d
PE,2009/05/11,14:51:00 -7:00 GMT,9129837.exe,C:\WINDOWS\9129837.exe,0.0.0.0:10633,N/A
AV/treatment,2009/05/11,14:51:06 -7:00 GMT,Rootkit.Win32.Agent.ex,C:\WINDOWS\new_drv.sys,File Repair Failed,Auto
,2009/05/11,14:51:10 -7:00 GMT,
FWIN,2009/05/11,14:52:26 -7:00 GMT,192.168.1.3:0,192.168.1.101:0,ICMP (type:3/subtype:2)
PE,2009/05/11,14:55:54 -7:00 GMT,9129837.exe,C:\WINDOWS\9129837.exe,192.168.1.101:0,N/A
PE,2009/05/11,14:55:56 -7:00 GMT,9129837.exe,C:\WINDOWS\9129837.exe,192.168.1.101:0,N/A
ACCESS,2009/05/11,14:56:04 -7:00 GMT,9129837.exe was temporarily blocked from connecting to the Internet (192.168.1.101).,N/A,N/A
ACCESS,2009/05/11,14:56:04 -7:00 GMT,9129837.exe was temporarily blocked from connecting to the Internet (68.87.69.146).,N/A,N/A
ACCESS,2009/05/11,14:56:04 -7:00 GMT,9129837.exe was temporarily blocked from connecting to the Internet (74.125.127.99).,N/A,N/A
ACCESS,2009/05/11,14:56:04 -7:00 GMT,9129837.exe was temporarily blocked from receiving data from the Internet (192.168.1.101).,N/A,N/A
ACCESS,2009/05/11,14:56:04 -7:00 GMT,9129837.exe was temporarily blocked from receiving data from the Internet (74.125.127.99).,N/A,N/A
PE,2009/05/11,14:56:04 -7:00 GMT,9129837.exe,C:\WINDOWS\9129837.exe,127.0.0.1:1052,N/A
ACCESS,2009/05/11,14:56:06 -7:00 GMT,9129837.exe was temporarily blocked from connecting to the local zone (127.0.0.1:Port 1052).,N/A,N/A
ACCESS,2009/05/11,14:56:06 -7:00 GMT,9129837.exe was temporarily blocked from connecting to the Internet (91.207.61.44:HTTP).,N/A,N/A
ACCESS,2009/05/11,14:56:06 -7:00 GMT,9129837.exe was temporarily blocked from connecting to the Internet (208.176.36.92).,N/A,N/A
ACCESS,2009/05/11,14:56:06 -7:00 GMT,9129837.exe was temporarily blocked from receiving data from the Internet (208.176.36.92).,N/A,N/A
OSFW,2009/05/11,14:56:08 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,\SystemRoot\System32\smss.exe
OSFW,2009/05/11,14:56:12 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\csrss.exe
OSFW,2009/05/11,14:56:12 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\winlogon.exe
OSFW,2009/05/11,14:56:12 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\services.exe
OSFW,2009/05/11,14:56:12 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\lsass.exe
OSFW,2009/05/11,14:56:12 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,14:56:12 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,14:56:12 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\System32\svchost.exe
OSFW,2009/05/11,14:56:12 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,14:56:12 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,14:56:12 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\spoolsv.exe
OSFW,2009/05/11,14:56:16 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\Explorer.EXE
OSFW,2009/05/11,14:56:16 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
OSFW,2009/05/11,14:56:16 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\AGRSMMSG.exe
OSFW,2009/05/11,14:56:16 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Apoint2K\Apoint.exe
OSFW,2009/05/11,14:56:18 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\hkcmd.exe
OSFW,2009/05/11,14:56:18 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
OSFW,2009/05/11,14:56:18 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
ACCESS,2009/05/11,14:56:20 -7:00 GMT,9129837.exe was temporarily blocked from connecting to the Internet (91.207.61.44:HTTP).,N/A,N/A
OSFW,2009/05/11,14:56:20 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Apoint2K\Apntex.exe
OSFW,2009/05/11,14:56:20 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\iTunes\iTunesHelper.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Java\jre6\bin\jusched.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\TPPALDR.EXE
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Bonjour\mDNSResponder.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\iPod\Bin\iPodSrv.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Java\jre6\bin\jqs.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,SRC,C:\Program Files\Canon\CAL\CALMAIN.exe
OSFW,2009/05/11,14:56:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\wuauclt.exe
OSFW,2009/05/11,14:56:24 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\iPod\bin\iPodService.exe
OSFW,2009/05/11,14:56:24 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\wbem\wmiprvse.exe
ACCESS,2009/05/11,14:56:24 -7:00 GMT,9129837.exe was temporarily blocked from connecting to the Internet (91.207.61.44:HTTP).,N/A,N/A
AV/update,2009/05/11,15:00:54 -7:00 GMT,,Update Install Completed,Auto
ZLUpdate,2009/05/11,15:03:08 -7:00 GMT,,,Auto
ZLUpdate,2009/05/11,15:03:16 -7:00 GMT,,,Auto
PE,2009/05/11,15:10:58 -7:00 GMT,9129837.exe,C:\WINDOWS\9129837.exe,91.207.61.44:80,N/A
PE,2009/05/11,15:26:00 -7:00 GMT,9129837.exe,C:\WINDOWS\9129837.exe,91.207.61.44:80,N/A
AV/scan,2009/05/11,15:29:54 -7:00 GMT,C:\,Scan Cancelled,Manual
OSFW,2009/05/11,15:35:56 -7:00 GMT,BLOCKED,Windows Explorer,C:\WINDOWS\explorer.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,15:35:56 -7:00 GMT,BLOCKED,Windows Explorer,C:\WINDOWS\explorer.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,15:35:56 -7:00 GMT,BLOCKED,Windows Explorer,C:\WINDOWS\explorer.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,15:35:56 -7:00 GMT,BLOCKED,Windows Explorer,C:\WINDOWS\explorer.exe,FILE,WRITE,SRC,ZLDIR*
,2009/05/11,15:36:16 -7:00 GMT,
OSFW,2009/05/11,15:38:42 -7:00 GMT,BLOCKED,Windows Explorer,C:\WINDOWS\explorer.exe,FILE,WRITE,SRC,ZLDIR*
PE,2009/05/11,15:38:46 -7:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,0.0.0.0:135,N/A
OSFW,2009/05/11,15:38:48 -7:00 GMT,BLOCKED,Windows Explorer,C:\WINDOWS\explorer.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,15:38:48 -7:00 GMT,BLOCKED,Windows Explorer,C:\WINDOWS\explorer.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,15:38:48 -7:00 GMT,BLOCKED,Windows Explorer,C:\WINDOWS\explorer.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,15:38:48 -7:00 GMT,BLOCKED,Windows Explorer,C:\WINDOWS\explorer.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,15:48:24 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,15:48:24 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,15:48:24 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,15:48:24 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,15:48:24 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,15:48:24 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,15:48:24 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,15:48:24 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,15:48:24 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,15:48:24 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,16:12:38 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,16:12:38 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,16:12:38 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,16:12:38 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,16:12:38 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,16:12:38 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,16:12:38 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,16:12:38 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,16:12:38 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,16:12:38 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,ZLDIR*
AV/treatment,2009/05/11,16:20:54 -7:00 GMT,Trojan.Win32.Inject.yrx,C:\WINDOWS\system32\wbem\grpconv.exe,File Repair Failed,Manual
,2009/05/11,16:20:56 -7:00 GMT,
AV/scan,2009/05/11,16:21:20 -7:00 GMT,C:\,Scan Completed,Manual
OSFW,2009/05/11,16:21:26 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,16:21:26 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
ZLUpdate,2009/05/11,16:21:30 -7:00 GMT,,,Auto
ZLUpdate,2009/05/11,16:21:34 -7:00 GMT,,,Auto
OSFW,2009/05/11,16:46:50 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,16:46:50 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,16:46:50 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
OSFW,2009/05/11,16:46:50 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs\avsys*
,2009/05/11,16:47:18 -7:00 GMT,
PE,2009/05/11,16:48:12 -7:00 GMT,9129837.exe,C:\WINDOWS\9129837.exe,0.0.0.0:12774,N/A
OSFW,2009/05/11,16:48:18 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,\SystemRoot\System32\smss.exe
AV/treatment,2009/05/11,16:48:20 -7:00 GMT,Rootkit.Win32.Agent.ex,C:\WINDOWS\new_drv.sys,File Repair Failed,Auto
PE,2009/05/11,16:48:22 -7:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,0.0.0.0:135,N/A
PE,2009/05/11,16:48:22 -7:00 GMT,9129837.exe,C:\WINDOWS\9129837.exe,0.0.0.0:12774,N/A
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\csrss.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\winlogon.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\services.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\lsass.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\System32\svchost.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\spoolsv.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\WgaTray.exe
OSFW,2009/05/11,16:48:22 -7:00 GMT,UNKNOWN(0),9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\Explorer.EXE
,2009/05/11,16:48:28 -7:00 GMT,
PE,2009/05/11,16:49:18 -7:00 GMT,9129837.exe,C:\WINDOWS\9129837.exe,127.0.0.1:1031,N/A
ACCESS,2009/05/11,16:49:22 -7:00 GMT,9129837.exe was blocked from connecting to the local zone (127.0.0.1:Port 1031).,N/A,N/A
ACCESS,2009/05/11,16:49:22 -7:00 GMT,9129837.exe was blocked from connecting to the Internet (91.207.61.44:HTTP).,N/A,N/A
OSFW,2009/05/11,16:49:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\iPod\Bin\iPodSrv.exe
OSFW,2009/05/11,16:49:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Java\jre6\bin\jqs.exe
OSFW,2009/05/11,16:49:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Documents and Settings\Cal McGrath\Desktop\ProcessExplorer\procexp.exe
OSFW,2009/05/11,16:49:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
OSFW,2009/05/11,16:49:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\svchost.exe
OSFW,2009/05/11,16:49:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,SRC,C:\Program Files\Canon\CAL\CALMAIN.exe
OSFW,2009/05/11,16:49:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\wuauclt.exe
OSFW,2009/05/11,16:49:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\wbem\wmiprvse.exe
OSFW,2009/05/11,16:49:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\iPod\bin\iPodService.exe
OSFW,2009/05/11,16:49:22 -7:00 GMT,BLOCKED,9129837.exe,C:\WINDOWS\9129837.exe,PROCESS,OPENPROCESS,DST,C:\WINDOWS\system32\wbem\wmiprvse.exe
ACCESS,2009/05/11,16:49:22 -7:00 GMT,9129837.exe was blocked from connecting to the Internet (91.207.61.44:HTTP).,N/A,N/A
FWIN,2009/05/11,16:54:24 -7:00 GMT,192.168.1.3:0,192.168.1.101:0,ICMP (type:3/subtype:2)
OSFW,2009/05/11,16:58:32 -7:00 GMT,UNKNOWN(0),Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,MESSAGE,Unknown Sub Event(3),DST,C:\WINDOWS\system32\taskmgr.exe
OSFW,2009/05/11,16:58:40 -7:00 GMT,BLOCKED,Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,16:58:40 -7:00 GMT,BLOCKED,Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,16:58:56 -7:00 GMT,BLOCKED,Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,16:58:56 -7:00 GMT,BLOCKED,Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,16:58:56 -7:00 GMT,BLOCKED,Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,16:58:56 -7:00 GMT,BLOCKED,Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
ACCESS,2009/05/11,16:58:58 -7:00 GMT,9129837.exe was blocked from connecting to the Internet (91.207.61.44:HTTP).,N/A,N/A
OSFW,2009/05/11,17:04:30 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,17:04:30 -7:00 GMT,BLOCKED,Sysinternals Process Explorer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\PROCESSEXPLORER\procexp.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
ZLUpdate,2009/05/11,17:04:30 -7:00 GMT,,,Auto
ZLUpdate,2009/05/11,17:04:34 -7:00 GMT,,,Auto
FWIN,2009/05/11,18:21:12 -7:00 GMT,192.168.1.3:0,192.168.1.101:0,ICMP (type:3/subtype:2)
OSFW,2009/05/11,18:22:10 -7:00 GMT,UNKNOWN(0),HijackThis,C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE,FILE,WRITE,SRC,WINDRVDIR\etc\hosts
PE,2009/05/11,18:23:00 -7:00 GMT,HijackThis,C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE,208.50.77.136:80,N/A
FWIN,2009/05/11,18:29:40 -7:00 GMT,192.168.1.3:0,192.168.1.101:0,ICMP (type:3/subtype:2)
,2009/05/11,18:30:04 -7:00 GMT,
FWOUT,2009/05/11,18:30:44 -7:00 GMT,192.168.1.101:1026,68.87.69.146:53,UDP
PE,2009/05/11,18:31:08 -7:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,0.0.0.0:135,N/A
OSFW,2009/05/11,18:36:04 -7:00 GMT,BLOCKED,Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,18:36:04 -7:00 GMT,BLOCKED,Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,18:36:04 -7:00 GMT,BLOCKED,Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
OSFW,2009/05/11,18:36:04 -7:00 GMT,BLOCKED,Autostart program viewer,C:\DOCUMENTS AND SETTINGS\CAL MCGRATH\Desktop\Autoruns\autoruns.exe,FILE,WRITE,SRC,WINSYSDIR\ZoneLabs*
AV/scan,2009/05/11,19:16:52 -7:00 GMT,C:\,Scan Completed,Manual
ZLUpdate,2009/05/11,19:17:00 -7:00 GMT,,,Auto
ZLUpdate,2009/05/11,19:17:04 -7:00 GMT,,,Auto
OSFW,2009/05/11,20:19:26 -7:00 GMT,BLOCKED,Run a DLL as an App,C:\WINDOWS\system32\rundll32.exe,FILE,WRITE,SRC,ZLDIR*
OSFW,2009/05/11,20:21:28 -7:00 GMT,UNKNOWN(0),UNINSTALL.EXE,C:\PROGRAM FILES\STORAGESYNC\UNINSTALL.EXE,REGISTRY,DELVALUE,SRC,HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN,StrgSync.exe

Here is my Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:39:29 PM, on 5/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\iPod\Bin\iPodWatcher.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\TPPALDR.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod\Bin\iPodSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Adobe\Acrobat 6.0\Acrobat\Acrobat.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [iPodWatcher] C:\Program Files\iPod\Bin\iPodWatcher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135750765541
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://www.carilloncams.com/activex/AMC.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://unicornhro.webex.com/client/v_myweb…bex/ieatgpc.cab
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
O16 - DPF: {FD18DD5E-B398-452A-B22A-B54636BA9F0D} (Aurigma Image Uploader 2.5) - http://www.boats.com/listing/ImageUploader2.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2CE0824-09C3-4785-8286-C5EE0CE24F60}: NameServer = 4.2.2.1,4.2.2.2
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iPodSrv - Unknown owner - C:\Program Files\iPod\Bin\iPodSrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 9058 bytes

I'm attaching a screen shot of my Antivirus software.

Please let me know what other information would be helpful in order to try and remove these malware issues from my computer.

Thank you in advance for all of your assistance!
Hi chamski,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

There is nothing obvious showing. Let's try this:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hi Tomk,

Thank you very much for taking the time to look into this and help me. Here are the logs that you requested.

Malwarebytes' Anti-Malware 1.36
Database version: 2149
Windows 5.1.2600 Service Pack 3

5/18/2009 9:20:51 PM
mbam-log-2009-05-18 (21-20-51).txt

Scan type: Quick Scan
Objects scanned: 81965
Time elapsed: 10 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv (Rootkit.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\9129837.exe (Trojan.Agent) -> Quarantined and deleted successfully.







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:34:51 PM, on 5/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\iPod\Bin\iPodWatcher.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\TPPALDR.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod\Bin\iPodSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [iPodWatcher] C:\Program Files\iPod\Bin\iPodWatcher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135750765541
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://www.carilloncams.com/activex/AMC.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://unicornhro.webex.com/client/v_myweb…bex/ieatgpc.cab
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
O16 - DPF: {FD18DD5E-B398-452A-B22A-B54636BA9F0D} (Aurigma Image Uploader 2.5) - http://www.boats.com/listing/ImageUploader2.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2CE0824-09C3-4785-8286-C5EE0CE24F60}: NameServer = 4.2.2.1,4.2.2.2
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iPodSrv - Unknown owner - C:\Program Files\iPod\Bin\iPodSrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8916 bytes




System seems fine, although while the Malwarebytes scan was running, I didn't realize it, but my ZoneAlarm anti-virus was also running and before the Malwarebytes scan was finished, the ZoneAlarm anti-virus found the Trojan.Win32.Inject.zvb, but this time it was in a different location than before. This time it was in: C:\Documents and Settings\Cal McGrath\Local Settings\Temp\~TM7.tmp. Here's the ZoneAlarm Log.



ZoneAlarm Logging Client v8.0.298.035
Windows XP-5.1.2600-Service Pack 3-SP
type,date,time,source,destination,transport (Security)
type,date,time,virus name,file name,mode,e-mail id (Anti-Virus)
type,date,time,source,destination,action,service (IM Security)
type,date,time,source,destination,program,action (Malicious Code Protection)
type,date,time,action,product,file,event,subevent,class,data,data,… (OSFirewall)
type,date,time,name,type,mode (Anti-Spyware)
OSFW,2009/05/18,21:07:18 -7:00 GMT,UNKNOWN(0),Setup/Uninstall,C:\Documents and Settings\Cal McGrath\Local Settings\Temp\is-C9TCH.tmp\MBAM-SETUP.TMP,REGISTRY,SETVALUE,SRC,HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE,Malwarebytes' Anti-Malware
OSFW,2009/05/18,21:07:34 -7:00 GMT,UNKNOWN(0),Setup/Uninstall,C:\Documents and Settings\Cal McGrath\Local Settings\Temp\is-C9TCH.tmp\MBAM-SETUP.TMP,PROCESS,SPAWNPROCESS,SRC,C:\WINDOWS\system32\regsvr32.exe,80000112
PE,2009/05/18,21:08:22 -7:00 GMT,Malwarebytes' Anti-Malware,C:\PROGRAM FILES\MALWAREBYTES' ANTI-MALWARE\mbam.exe,127.0.0.1:3429,N/A
PE,2009/05/18,21:08:32 -7:00 GMT,Malwarebytes' Anti-Malware,C:\PROGRAM FILES\MALWAREBYTES' ANTI-MALWARE\mbam.exe,68.142.123.254:80,N/A
OSFW,2009/05/18,21:09:56 -7:00 GMT,UNKNOWN(0),Malwarebytes' Anti-Malware,C:\PROGRAM FILES\MALWAREBYTES' ANTI-MALWARE\mbam.exe,PROCESS,OPENPROCESS,DST,\SystemRoot\System32\smss.exe
AV/update,2009/05/18,21:14:02 -7:00 GMT,,Update Install Completed,Auto
AV/treatment,2009/05/18,21:17:54 -7:00 GMT,Trojan.Win32.Inject.zvb,C:\Documents and Settings\Cal McGrath\Local Settings\Temp\~TM7.tmp,File Repair Failed,Auto
,2009/05/18,21:17:58 -7:00 GMT,
,2009/05/18,21:28:02 -7:00 GMT,
FWOUT,2009/05/18,21:28:30 -7:00 GMT,192.168.1.101:1026,68.87.69.146:53,UDP
PE,2009/05/18,21:29:06 -7:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,0.0.0.0:135,N/A
FWIN,2009/05/18,21:34:10 -7:00 GMT,192.168.1.3:0,192.168.1.101:0,ICMP (type:3/subtype:2)



I'll run another ZoneAlarm virus scan in the morning and see what it finds this time. If you want me to disable ZoneAlarm temporarily while we troubleshoot this issue, please let me know. Overall, my computer seems fine, but I'm concerned about the fact that ZoneAlarm keeps finding this Trojan in different locations and can't seem to fix them, thereby resulting in the Trojan's being quarantined. My laptop does start up slowly, although it may be just because of the software that has been loaded over the years.

Please let me know what you'd like me to do next…. Thank you!
chamski,

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
Here's the log from Rooter.exe: Microsoft Windows XP Professional (5.1.2600) Service Pack 3 C:\ [Fixed] - NTFS - (Total:76316 Mo/Free:272 Mo) D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) Tue 05/19/2009| 7:44 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\WINDOWS\Explorer.EXE ———- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe ———- C:\WINDOWS\AGRSMMSG.exe ———- C:\Program Files\Apoint2K\Apoint.exe ———- C:\WINDOWS\system32\hkcmd.exe ———- C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe ———- C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe ———- C:\Program Files\iPod\Bin\iPodWatcher.exe ———- C:\Program Files\Apoint2K\Apntex.exe ———- C:\Program Files\iTunes\iTunesHelper.exe ———- C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe –Locked– zlclient.exe ———- C:\Program Files\Java\jre6\bin\jusched.exe ———- C:\WINDOWS\TPPALDR.EXE ———- C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE ———- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe ———- C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe ———- C:\Program Files\Bonjour\mDNSResponder.exe ———- C:\Program Files\iPod\Bin\iPodSrv.exe ———- C:\Program Files\Java\jre6\bin\jqs.exe ———- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe ———- C:\WINDOWS\system32\svchost.exe –Locked– vsmon.exe ———- C:\Program Files\Canon\CAL\CALMAIN.exe –Locked– ScanningProcess.exe ———- C:\WINDOWS\system32\wuauclt.exe ———- C:\WINDOWS\system32\wbem\wmiprvse.exe ———- C:\Program Files\iPod\bin\iPodService.exe ———- C:\Program Files\HPQ\shared\hpqwmi.exe ———- C:\Program Files\Internet Explorer\iexplore.exe ———- C:\WINDOWS\system32\wuauclt.exe ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! 1 - "C:\Rooter$\Rooter_1.txt" - Tue 05/19/2009| 7:45 ———————-\\ Scan completed at 7:45 ZoneAlarm ran again this morning, but didn't find anything, so that's good. I am uploading a screen shot of the ZoneAlarm virus quarantine. I'd like to know if I can highlight these and then click the Delete button or possibly highlight them and then click the Restore button, but then run Malwarebytes again or something. Thank you very much for your continuing assistance with these issues!
chamski,

It looks like you can delete them all.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Hi Tomk, I deleted the items in ZoneAlarm's quarantine, then downloaded and ran the Kaspersky online scanner. It took several hours to complete and when I clicked on Save Report As, then before I had a chance to specify a location, the browser window seems to have refreshed and then there were no more viruses listed, nor was there any way to get back to the report to save it. I'm running the online scanner again, so I'll post something either later tonight or tomorrow sometime. Thanks!
Here's the scan from Kaspersky: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Wednesday, May 20, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, May 20, 2009 04:48:32 Records in database: 2201860 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 100625 Threat name: 7 Infected objects: 25 Suspicious objects: 2 Duration of the scan: 03:18:40 File name / Threat name / Threats count C:\Documents and Settings\Cal McGrath\Local Settings\Application Data\Identities\{19EACC22-9FC3-44AC-BE26-32AF110DA34C}\Microsoft\Outlook Express\Byyhome.dbx Infected: Virus.MSWord.Marker.o 6 C:\Documents and Settings\Cal McGrath\Local Settings\Application Data\Identities\{19EACC22-9FC3-44AC-BE26-32AF110DA34C}\Microsoft\Outlook Express\Byyhome.dbx Infected: Virus.MSWord.Marker.r 3 C:\Documents and Settings\Cal McGrath\Local Settings\Application Data\Identities\{19EACC22-9FC3-44AC-BE26-32AF110DA34C}\Microsoft\Outlook Express\Byyhome.dbx Infected: Email-Worm.Win32.PrettyPark 1 C:\Documents and Settings\Cal McGrath\Local Settings\Application Data\Identities\{19EACC22-9FC3-44AC-BE26-32AF110DA34C}\Microsoft\Outlook Express\Inbox.dbx Infected: Trojan-Spy.HTML.Bayfraud.g 1 C:\Documents and Settings\Cal McGrath\Local Settings\Application Data\Identities\{19EACC22-9FC3-44AC-BE26-32AF110DA34C}\Microsoft\Outlook Express\Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Documents and Settings\Cal McGrath\Local Settings\Application Data\Identities\{19EACC22-9FC3-44AC-BE26-32AF110DA34C}\Microsoft\Outlook Express\Inbox.dbx Infected: Trojan-Spy.HTML.Bayfraud.hn 2 C:\Documents and Settings\Cal McGrath\Local Settings\Application Data\Identities\{19EACC22-9FC3-44AC-BE26-32AF110DA34C}\Microsoft\Outlook Express\Inbox.dbx Infected: Email-Worm.Win32.Bagle.ai 1 C:\Personal\Archive\e-mail\Outlook Express\Inbox.dbx Infected: Virus.MSWord.Marker.r 1 C:\Personal\OutlookExpress\Byyhome.dbx Infected: Virus.MSWord.Marker.o 4 C:\Personal\OutlookExpress\Byyhome.dbx Infected: Virus.MSWord.Marker.r 2 C:\Personal\OutlookExpress\Byyhome.dbx Infected: Email-Worm.Win32.PrettyPark 1 C:\Personal\OutlookExpress\Inbox.dbx Infected: Trojan-Spy.HTML.Bayfraud.g 1 C:\Personal\OutlookExpress\Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Personal\OutlookExpress\Inbox.dbx Infected: Trojan-Spy.HTML.Bayfraud.hn 1 C:\Personal\OutlookExpress\Inbox.dbx Infected: Email-Worm.Win32.Bagle.ai 1 The selected area was scanned.
chamski, You've got a bunch of infected emails. You need to go through all of your mail in Outlook Express and delete all the emails that you don't need/want/recognize. I can't tell which emails they are. All I know is that there are contaminated emails in your inbox folder, a folder called byyhome, your archive folders. Odds are that the infected emails will have an attachment or at least a link. Therefore, don't open any attachments or click on any links. Once you have finished your deletions, please empty your deleted mail folder. Then please post a new HijackThis log and let me know how things are running.
Hi Tomk,

Those were old email files, so I ended up just deleting all of them. Here is the latest from HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:00:57 PM, on 5/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\iPod\Bin\iPodWatcher.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\TPPALDR.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod\Bin\iPodSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [iPodWatcher] C:\Program Files\iPod\Bin\iPodWatcher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135750765541
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://www.carilloncams.com/activex/AMC.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://unicornhro.webex.com/client/v_myweb…bex/ieatgpc.cab
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
O16 - DPF: {FD18DD5E-B398-452A-B22A-B54636BA9F0D} (Aurigma Image Uploader 2.5) - http://www.boats.com/listing/ImageUploader2.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2CE0824-09C3-4785-8286-C5EE0CE24F60}: NameServer = 4.2.2.1,4.2.2.2
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iPodSrv - Unknown owner - C:\Program Files\iPod\Bin\iPodSrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8792 bytes
Seems like it is running fine. I'll reboot in the morning to see if I can tell any difference in startup time. I haven't rebooted since I ran one of the malware removal programs per your instructions and was prompted to reboot. Otherwise, things seem to be running fine. Anything else I should check? My antivirus software didn't detect anything this morning when it did a full scan, so that was good. I was going to run Kaspersky again in the morning to double check that I successfully deleted all the emails. Thanks!
Hi Tomk, It seems to be running fine, although when I boot up the computer, after I get to the login screen and enter my U/N and P/W, then it shows the desktop quickly and launches the anti-virus software quickly, but then takes at least 4 or 5 minutes (with the hard drive spinning) before it establishes network connectivity and before I can really do anything. Is there some way for me to determine what it's trying to do on startup that might be causing it to hang for 4 or 5 minutes? It seems like after it keeps trying to do something multiple times, it finally just gives up and then completes the initial startup process. I'm running the Kaspersky scan first this morning, then will be running a scan using my anti-virus software. I'll let you know how it goes when they are finished. Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI