hankr
Topic Starter
thankyou for your attention in advance,
ran my own virus scan (AVG Free 8.5) and followed self help procedures with mbam, ATF and HJThis.
scans are now clean and computer will NOW function in windows. Before just in SAFE mode w/commnd prompt.
there are four error messages at boot up.
X Windows cannot find 'C:\WINDOWS\system32\mszsu.exe'
! Could not load or run 'C:\WINDOWS\system32\mszsu.exe'
X Windows cannot find 'C:\WINDOWS\system32\msxgl.exe'
! Could not load or run 'C:\WINDOWS\system32\msxgl.exe'
system restore has NO restore points available.
Any suggestions for the errrors or how to clean up further? Thankyou. Have not been back on the net since infection.
LOGS
****************************
AVG 8.5 Anti-Virus command line scanner
Copyright © 1992 - 2009 AVG Technologies
Program version 8.0.354, engine 8.0.387
Virus Database: Version 270.13.13/2236 2009-07-13
C:\WINDOWS\fonts\services.exe Trojan horse Clicker.AAKG Object was moved to Virus Vault.
C:\WINDOWS\Fonts\services.exe (1216) Trojan horse Clicker.AAKG Object was moved to Virus Vault.
C:\WINDOWS\system32\net.net Trojan horse Clicker.AAJC Object was moved to Virus Vault.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\net Found registry key with reference to infected file C:\WINDOWS\system32\net.net Object was moved to Virus Vault.
C:\Documents and Settings\All Users\Application Data\12887034\12887034.exe Trojan horse FakeAlert.LN Object was moved to Virus Vault.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\12887034 Found registry key with reference to infected file C:\Documents and Settings\All Users\Application Data\12887034\12887034.exe Object was moved to Virus Vault.
C:\benfuse.exe Trojan horse FakeAlert.LM Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
C:\Documents and Settings\Henry Rogers\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\a.exe Trojan horse SHeur2.AQSN Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\b.exe Trojan horse SHeur2.AQSN Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\e.exe Trojan horse SHeur2.AQSN Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\installb[2].exe Trojan horse FakeAlert.LM Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\prun.tmp Trojan horse Clicker.AAJC Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\tfhs3xrjdr6djkrserz46.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\UAC4030.tmp Trojan horse Generic13.BZPM Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\UACe9b3.tmp Trojan horse Downloader.Zlob.ANPI Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\UACea5f.tmp Trojan horse Crypt.FNK Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\uyfvnixrns.tmp Virus identified Packed.Monder Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\xpre.tmp Trojan horse Downloader.Generic8.BAJR Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\zodin_1247527861.exe Trojan horse SHeur2.AQLB Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\zodin_1247544688.exe Trojan horse Rootkit-Agent.EA Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\NTUSER.DAT Locked file. Not tested.
C:\Documents and Settings\Henry Rogers\ntuser.dat.LOG Locked file. Not tested.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\AVXWJBYY\w[1].bin Trojan horse Downloader.Delf.CVK Object was moved to Virus Vault.
C:\Documents and Settings\NetworkService\NTUSER.DAT Locked file. Not tested.
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Locked file. Not tested.
C:\fhlyeby.exe Trojan horse SHeur2.ANGW Object was moved to Virus Vault.
C:\fwot.exe Trojan horse Generic14.BHT Object was moved to Virus Vault.
C:\pagefile.sys Locked file. Not tested.
C:\Program Files\PC_Security2009\wscui.cpl Potentially harmful program Fake_AntiSpyware.CVS Object was moved to Virus Vault.
C:\System Volume Information\ Locked file. Not tested.
C:\WINDOWS\Fonts\cooecp.tlb Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\Fonts\logcde.dll Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\Fonts\services.exe Trojan horse Clicker.AAKG Object was moved to Virus Vault.
C:\WINDOWS\Fonts\windef.dll Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\Fonts\windef.Log Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\Fonts\winpaged.ocx Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\6to4v32.dll Trojan horse Generic14.ASM Object was moved to Virus Vault.
C:\WINDOWS\system32\config\DEFAULT Locked file. Not tested.
C:\WINDOWS\system32\config\default.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SAM Locked file. Not tested.
C:\WINDOWS\system32\config\SAM.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SECURITY Locked file. Not tested.
C:\WINDOWS\system32\config\SECURITY.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SOFTWARE Locked file. Not tested.
C:\WINDOWS\system32\config\software.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SYSTEM Locked file. Not tested.
C:\WINDOWS\system32\config\system.LOG Locked file. Not tested.
C:\WINDOWS\system32\drivers\UACrvrjiertalkdwksru.sys Trojan horse BackDoor.Generic11.ABLC Object was moved to Virus Vault.
C:\WINDOWS\system32\mscmn.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mscpluk.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msdprztt.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msdtsd.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msecfh.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msfmw.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msgnjauc.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mshuose.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msitjsb.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msmkqy.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msnopjh.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msodnq.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msoeqcdw.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msohtduo.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msojg.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msqmbn.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msqqgc.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msvzun.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mswlxnnj.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mswwdfj.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msxgl.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msxof.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mszar.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mszsu.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\pcmstub.sys Trojan horse PSW.OnlineGames_r.AE Object was moved to Virus Vault.
C:\WINDOWS\system32\sopidkc.exe Trojan horse Downloader.Delf.CVF Object was moved to Virus Vault.
C:\WINDOWS\system32\tpsaxyd.exe Trojan horse Downloader.Delf.CVK Object was moved to Virus Vault.
C:\WINDOWS\system32\UACmobltpkdamrothbly.dll Virus found Win32/Cryptor Object was moved to Virus Vault.
C:\WINDOWS\system32\UACqnbhcvvtfrmwybiiv.dll Virus found Win32/Cryptor Object was moved to Virus Vault.
C:\WINDOWS\system32\UACthlsmahlkupllduvu.dll Trojan horse Generic13.ATPH Object was moved to Virus Vault.
C:\WINDOWS\system32\UACxjnvtlbequbtxemjl.dll Trojan horse Generic13.BQVV Object was moved to Virus Vault.
C:\WINDOWS\system32\wiawow32.sys Trojan horse Clicker.AALQ Object was moved to Virus Vault.
C:\WINDOWS\system32\wiwow64.exe Trojan horse Downloader.Delf.CVK Object was moved to Virus Vault.
C:\WINDOWS\Temp\UAC4120.tmp Trojan horse Downloader.Zlob.ANPC Object was moved to Virus Vault.
————————————————————
Objects scanned : 222763
Found infections : 63
Found PUPs : 1
Healed infections : 63
Healed PUPs : 1
Warnings : 0
————————————————————
********************************************************************************
*********************************************************************************
*********************
Malwarebytes' Anti-Malware 1.39
Database version: 2421
Windows 5.1.2600 Service Pack 3
7/14/2009 4:09:05 PM
mbam-log-2009-07-14 (16-09-05).txt
Scan type: Full Scan (C:\|)
Objects scanned: 164170
Time elapsed: 1 hour(s), 28 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 15
Registry Data Items Infected: 7
Folders Infected: 4
Files Infected: 61
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{40196867-19f8-7157-c097-ecaff653c9ad} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msncache (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\pc_security2009 (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\net (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\PC_Security2009 (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pc security 2009 (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\braviax (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\FirstInstallFlag (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mms (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\exec (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.bat\(default) (Hijacked.BatFile) -> Bad: (csfile) Good: (batfile) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.com\(default) (Hijacked.ComFile) -> Bad: (csfile) Good: (comfile) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (csfile) Good: (exefile) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\Henry Rogers\Start Menu\Programs\PC_Security2009 (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
C:\Program Files\PC_Security2009 (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\data (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\Microsoft.VC80.CRT (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\PC_Security2009\PC_Security2009.exe (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051464.exe (Rogue.Installer) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051465.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051466.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051467.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051469.tlb (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051470.dll (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051471.dll (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051472.ocx (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051473.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051474.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051475.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051476.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051477.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051478.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051479.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051480.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051481.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051482.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051483.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051484.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051485.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051486.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051487.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051488.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051489.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051490.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051491.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051492.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051493.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051494.sys (Trojan.Backdoor) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051495.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\msncache.dll (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\henry rogers\start menu\Programs\pc_security2009\PC_Security2009.lnk (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\documents and settings\henry rogers\start menu\Programs\pc_security2009\Uninstall.lnk (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\htmlayout.dll (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\pthreadVC2.dll (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\Uninstall.exe (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\data\daily.cvd (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\microsoft.vc80.crt\Microsoft.VC80.CRT.manifest (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\microsoft.vc80.crt\msvcm80.dll (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\microsoft.vc80.crt\msvcp80.dll (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\microsoft.vc80.crt\msvcr80.dll (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
C:\WINDOWS\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\msb.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\ld12.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\delself.bat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\beep.sys (Fake.Beep.sys) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dllcache\beep.sys (Fake.Beep.sys) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\braviax.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\010112010146118114.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\0101120101464849.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry Rogers\Application Data\Microsoft\Internet Explorer\Quick Launch\PC_Security2009.lnk (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wisdstr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\UACvumtgxuijxtetouyg.dll (Trojan.Agent) -> Quarantined and deleted successfully.
********************************************************************************
*********************************************************************************
**********************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:44:39 PM, on 7/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
D:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\mszsu.exe
F3 - REG:win.ini: run=C:\WINDOWS\system32\msxgl.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Cognac] C:\DOCUME~1\HENRYR~1\LOCALS~1\Temp\c.exe
O4 - HKCU\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
–
End of file - 6184 bytes
ran my own virus scan (AVG Free 8.5) and followed self help procedures with mbam, ATF and HJThis.
scans are now clean and computer will NOW function in windows. Before just in SAFE mode w/commnd prompt.
there are four error messages at boot up.
X Windows cannot find 'C:\WINDOWS\system32\mszsu.exe'
! Could not load or run 'C:\WINDOWS\system32\mszsu.exe'
X Windows cannot find 'C:\WINDOWS\system32\msxgl.exe'
! Could not load or run 'C:\WINDOWS\system32\msxgl.exe'
system restore has NO restore points available.
Any suggestions for the errrors or how to clean up further? Thankyou. Have not been back on the net since infection.
LOGS
****************************
AVG 8.5 Anti-Virus command line scanner
Copyright © 1992 - 2009 AVG Technologies
Program version 8.0.354, engine 8.0.387
Virus Database: Version 270.13.13/2236 2009-07-13
C:\WINDOWS\fonts\services.exe Trojan horse Clicker.AAKG Object was moved to Virus Vault.
C:\WINDOWS\Fonts\services.exe (1216) Trojan horse Clicker.AAKG Object was moved to Virus Vault.
C:\WINDOWS\system32\net.net Trojan horse Clicker.AAJC Object was moved to Virus Vault.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\net Found registry key with reference to infected file C:\WINDOWS\system32\net.net Object was moved to Virus Vault.
C:\Documents and Settings\All Users\Application Data\12887034\12887034.exe Trojan horse FakeAlert.LN Object was moved to Virus Vault.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\12887034 Found registry key with reference to infected file C:\Documents and Settings\All Users\Application Data\12887034\12887034.exe Object was moved to Virus Vault.
C:\benfuse.exe Trojan horse FakeAlert.LM Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
C:\Documents and Settings\Henry Rogers\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\a.exe Trojan horse SHeur2.AQSN Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\b.exe Trojan horse SHeur2.AQSN Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\e.exe Trojan horse SHeur2.AQSN Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\installb[2].exe Trojan horse FakeAlert.LM Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\prun.tmp Trojan horse Clicker.AAJC Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\tfhs3xrjdr6djkrserz46.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\UAC4030.tmp Trojan horse Generic13.BZPM Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\UACe9b3.tmp Trojan horse Downloader.Zlob.ANPI Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\UACea5f.tmp Trojan horse Crypt.FNK Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\uyfvnixrns.tmp Virus identified Packed.Monder Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\xpre.tmp Trojan horse Downloader.Generic8.BAJR Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\zodin_1247527861.exe Trojan horse SHeur2.AQLB Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\Local Settings\Temp\zodin_1247544688.exe Trojan horse Rootkit-Agent.EA Object was moved to Virus Vault.
C:\Documents and Settings\Henry Rogers\NTUSER.DAT Locked file. Not tested.
C:\Documents and Settings\Henry Rogers\ntuser.dat.LOG Locked file. Not tested.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\AVXWJBYY\w[1].bin Trojan horse Downloader.Delf.CVK Object was moved to Virus Vault.
C:\Documents and Settings\NetworkService\NTUSER.DAT Locked file. Not tested.
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Locked file. Not tested.
C:\fhlyeby.exe Trojan horse SHeur2.ANGW Object was moved to Virus Vault.
C:\fwot.exe Trojan horse Generic14.BHT Object was moved to Virus Vault.
C:\pagefile.sys Locked file. Not tested.
C:\Program Files\PC_Security2009\wscui.cpl Potentially harmful program Fake_AntiSpyware.CVS Object was moved to Virus Vault.
C:\System Volume Information\ Locked file. Not tested.
C:\WINDOWS\Fonts\cooecp.tlb Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\Fonts\logcde.dll Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\Fonts\services.exe Trojan horse Clicker.AAKG Object was moved to Virus Vault.
C:\WINDOWS\Fonts\windef.dll Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\Fonts\windef.Log Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\Fonts\winpaged.ocx Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\6to4v32.dll Trojan horse Generic14.ASM Object was moved to Virus Vault.
C:\WINDOWS\system32\config\DEFAULT Locked file. Not tested.
C:\WINDOWS\system32\config\default.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SAM Locked file. Not tested.
C:\WINDOWS\system32\config\SAM.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SECURITY Locked file. Not tested.
C:\WINDOWS\system32\config\SECURITY.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SOFTWARE Locked file. Not tested.
C:\WINDOWS\system32\config\software.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SYSTEM Locked file. Not tested.
C:\WINDOWS\system32\config\system.LOG Locked file. Not tested.
C:\WINDOWS\system32\drivers\UACrvrjiertalkdwksru.sys Trojan horse BackDoor.Generic11.ABLC Object was moved to Virus Vault.
C:\WINDOWS\system32\mscmn.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mscpluk.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msdprztt.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msdtsd.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msecfh.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msfmw.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msgnjauc.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mshuose.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msitjsb.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msmkqy.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msnopjh.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msodnq.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msoeqcdw.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msohtduo.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msojg.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msqmbn.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msqqgc.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msvzun.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mswlxnnj.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mswwdfj.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msxgl.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\msxof.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mszar.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\mszsu.exe Trojan horse Downloader.VB.CBF Object was moved to Virus Vault.
C:\WINDOWS\system32\pcmstub.sys Trojan horse PSW.OnlineGames_r.AE Object was moved to Virus Vault.
C:\WINDOWS\system32\sopidkc.exe Trojan horse Downloader.Delf.CVF Object was moved to Virus Vault.
C:\WINDOWS\system32\tpsaxyd.exe Trojan horse Downloader.Delf.CVK Object was moved to Virus Vault.
C:\WINDOWS\system32\UACmobltpkdamrothbly.dll Virus found Win32/Cryptor Object was moved to Virus Vault.
C:\WINDOWS\system32\UACqnbhcvvtfrmwybiiv.dll Virus found Win32/Cryptor Object was moved to Virus Vault.
C:\WINDOWS\system32\UACthlsmahlkupllduvu.dll Trojan horse Generic13.ATPH Object was moved to Virus Vault.
C:\WINDOWS\system32\UACxjnvtlbequbtxemjl.dll Trojan horse Generic13.BQVV Object was moved to Virus Vault.
C:\WINDOWS\system32\wiawow32.sys Trojan horse Clicker.AALQ Object was moved to Virus Vault.
C:\WINDOWS\system32\wiwow64.exe Trojan horse Downloader.Delf.CVK Object was moved to Virus Vault.
C:\WINDOWS\Temp\UAC4120.tmp Trojan horse Downloader.Zlob.ANPC Object was moved to Virus Vault.
————————————————————
Objects scanned : 222763
Found infections : 63
Found PUPs : 1
Healed infections : 63
Healed PUPs : 1
Warnings : 0
————————————————————
********************************************************************************
*********************************************************************************
*********************
Malwarebytes' Anti-Malware 1.39
Database version: 2421
Windows 5.1.2600 Service Pack 3
7/14/2009 4:09:05 PM
mbam-log-2009-07-14 (16-09-05).txt
Scan type: Full Scan (C:\|)
Objects scanned: 164170
Time elapsed: 1 hour(s), 28 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 15
Registry Data Items Infected: 7
Folders Infected: 4
Files Infected: 61
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{40196867-19f8-7157-c097-ecaff653c9ad} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msncache (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\pc_security2009 (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\net (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\PC_Security2009 (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pc security 2009 (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\braviax (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\FirstInstallFlag (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mms (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\exec (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.bat\(default) (Hijacked.BatFile) -> Bad: (csfile) Good: (batfile) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.com\(default) (Hijacked.ComFile) -> Bad: (csfile) Good: (comfile) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (csfile) Good: (exefile) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\Henry Rogers\Start Menu\Programs\PC_Security2009 (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
C:\Program Files\PC_Security2009 (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\data (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\Microsoft.VC80.CRT (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\PC_Security2009\PC_Security2009.exe (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051464.exe (Rogue.Installer) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051465.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051466.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051467.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051469.tlb (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051470.dll (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051471.dll (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051472.ocx (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051473.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051474.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051475.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051476.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051477.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051478.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051479.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051480.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051481.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051482.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051483.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051484.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051485.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051486.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051487.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051488.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051489.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051490.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051491.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051492.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051493.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051494.sys (Trojan.Backdoor) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP818\A0051495.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\msncache.dll (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\henry rogers\start menu\Programs\pc_security2009\PC_Security2009.lnk (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\documents and settings\henry rogers\start menu\Programs\pc_security2009\Uninstall.lnk (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\htmlayout.dll (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\pthreadVC2.dll (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\Uninstall.exe (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\data\daily.cvd (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\microsoft.vc80.crt\Microsoft.VC80.CRT.manifest (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\microsoft.vc80.crt\msvcm80.dll (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\microsoft.vc80.crt\msvcp80.dll (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
c:\program files\pc_security2009\microsoft.vc80.crt\msvcr80.dll (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
C:\WINDOWS\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\msb.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\ld12.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\delself.bat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\beep.sys (Fake.Beep.sys) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dllcache\beep.sys (Fake.Beep.sys) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\braviax.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\010112010146118114.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\0101120101464849.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry Rogers\Application Data\Microsoft\Internet Explorer\Quick Launch\PC_Security2009.lnk (Rogue.PCSecurity2009) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wisdstr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\UACvumtgxuijxtetouyg.dll (Trojan.Agent) -> Quarantined and deleted successfully.
********************************************************************************
*********************************************************************************
**********************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:44:39 PM, on 7/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
D:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\mszsu.exe
F3 - REG:win.ini: run=C:\WINDOWS\system32\msxgl.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Cognac] C:\DOCUME~1\HENRYR~1\LOCALS~1\Temp\c.exe
O4 - HKCU\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
–
End of file - 6184 bytes