This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Backdoor.Bot.92301 // Win32/Injector.XJ trojan removal

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone,

I found out this morning that my computer was infected by "Win/32 Injector.XJ trojan" by running an in depth analysis of my computer with NOD32. (my antivirus)

I searched the internet but couldn't find anything in particular about this virus. I then ran a Bitdefender online scan of my computer which found "Backdoor.Bot.92301" which I suppose is the same trojan than the other one, just with a different name.

I found on my computer files that have never been there before, directories full of files infected by this trojan. NOD32 isn't able to clean/destroy these files so the only available option for me is to ignore these files when running a scan.

It seems nearly all of the files on my computer are infected and I am therefore in desperate need for help.

Here is my HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:34:33, on 21/08/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Innovative Solutions\DriverMax\devices.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Program Files\Eset\nod32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.compaqnet.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://www.compaqnet.be
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection -

{4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program

Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program

Files\Xi\NetXfer\NXIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} -

C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -

C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -

C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program

Files\Xi\NetXfer\NXToolBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -

C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control

Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program

Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Windows UDP Control Center] winudpmgr.exe
O4 - HKLM\..\Run: [Microsoft System Service] winupdates.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe

/auto
O4 - HKLM\..\RunServices: [Microsoft System Service] winupdates.exe
O4 - HKCU\..\Run: [pbmini] C:\Program

Files\pcast\PodcastbarMini\PodcastBarMiniStater.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP

Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [swg] C:\Program

Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &

Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative

Solutions\DriverMax\devices.exe" -agent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe"

/background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User

'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User

'SERVICE RÉSEAU')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers

communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program

Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program

Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton

SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL

Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: Téléchargement par NetXfer - C:\Program

Files\Xi\NetXfer\NXAddLink.html
O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program

Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program

Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Téléchargez tous par NetXfer - C:\Program

Files\Xi\NetXfer\NXAddList.html
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} -

C:\Program Files\Fichiers communs\Microsoft Shared\Encarta

Researcher\EROPROJ.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -

C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}

- C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.compaqnet.be
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program

Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers

communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers

communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. -

C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program

Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd -

C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation -

C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program

Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation

- C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel

32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems,

Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program

Files\Eset\nod32krn.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program

Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner -

C:\WINDOWS\system32\UAService7.exe

–
End of file - 10154 bytes
:welcome:

Can't read your log the way you posted it , do it this way please.


Download Trendmicros Hijackthis to your desktop.
  • Double click it to install
  • Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure Wordwrap is Unchecked
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread by using the Submit Reply and not start a New Thread.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Hi ken545, sorry about that other log :s

Here´s my new one:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:37:08, on 25/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Innovative Solutions\DriverMax\devices.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.compaqnet.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.compaqnet.be
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Microsoft System Service] winupdates.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunServices: [Microsoft System Service] winupdates.exe
O4 - HKCU\..\Run: [pbmini] C:\Program Files\pcast\PodcastbarMini\PodcastBarMiniStater.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: Téléchargement par NetXfer - C:\Program Files\Xi\NetXfer\NXAddLink.html
O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Téléchargez tous par NetXfer - C:\Program Files\Xi\NetXfer\NXAddList.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.compaqnet.be
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

–
End of file - 10038 bytes
Hi,

The infection you have is a backdoor trojan that has the capabilities to go out and find other junk to download to your system.
I would strongly urge you that outside of posting here that you stay off the internet until we give you the all clear sign.

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one,
the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O4 - HKLM\..\Run: [Microsoft System Service] winupdates.exe
O4 - HKLM\..\RunServices: [Microsoft System Service] winupdates.exe




Please download Malwarebytes' Anti-Malware from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report and also a new HJT log please
Hi and thank you for your help,

- Here´s my "Malwarebytes' Anti-Malware" report:

Malwarebytes' Anti-Malware 1.40
Database version: 2693
Windows 5.1.2600 Service Pack 3

25/08/2009 13:11:00
mbam-log-2009-08-25 (13-11-00).txt

Scan type: Quick Scan
Objects scanned: 94118
Time elapsed: 10 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 23

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\videosoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OLE\Microsoft System Service (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\dirsvc.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hostsvc.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\svchosting.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\windowshelp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\windowssys.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winhelp32r.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\cxdir.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\cxxdir.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\hellomoto.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\helpwin.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\ntdissys.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\ntsoundfile.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\rdir.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\rundll32.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\soundsys.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\sys32.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\uploadsys.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\win32svc.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\windowshelp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\winhelp32s.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system\ntsound.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system\soundcontrol.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\wmdmhelper.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.

- And here is my new HJT report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:22:08, on 25/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Innovative Solutions\DriverMax\devices.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.compaqnet.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.compaqnet.be
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [pbmini] C:\Program Files\pcast\PodcastbarMini\PodcastBarMiniStater.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: Téléchargement par NetXfer - C:\Program Files\Xi\NetXfer\NXAddLink.html
O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Téléchargez tous par NetXfer - C:\Program Files\Xi\NetXfer\NXAddList.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.compaqnet.be
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

–
End of file - 9954 bytes


By the way, I also ran an in-depth scan and it found 59 other objects infected, should I also clean these ?
Hi,

Malwarebytes removed a bunch of junk and your HJT log looks fine.

You ran an in depth scan with what ? I am not going to tell you to remove anything because I have no idea what the files are.

Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
Hi, the eset online scan didn´t find anything :) Here´s the log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=6.00.2900.5512 (xpsp.080413-2105) # OnlineScanner.ocx=1.0.0.6050 # api_version=3.0.2 # EOSSerial=c565b1bab30e694794bbaff5b40826f0 # end=stopped # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-08-25 06:00:59 # local_time=2009-08-25 08:00:59 (+0100, Paris, Madrid) # country="Belgium" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=8194 21 100 100 2754092656250 # scanned=3566 # found=0 # cleaned=0 # scan_time=126 # nod_component=NOD32MOD_WINNT_ENGLISH_BASE Build:0x11081620 # nod_component=NOD32MOD_WINNT_ENGLISH_INET Build:0x11081620 # nod_component=NOD32MOD_WINNT_ENGLISH_STANDARD Build:0x11081620 esets_scanner_update returned -1 esets_gle=53251 # version=6 # iexplore.exe=6.00.2900.5512 (xpsp.080413-2105) # OnlineScanner.ocx=1.0.0.6050 # api_version=3.0.2 # EOSSerial=c565b1bab30e694794bbaff5b40826f0 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-08-25 07:27:22 # local_time=2009-08-25 09:27:22 (+0100, Paris, Madrid) # country="Belgium" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=8194 21 100 100 2805924360578 # scanned=85345 # found=0 # cleaned=0 # scan_time=4827 # nod_component=NOD32MOD_WINNT_ENGLISH_BASE Build:0x11081620 # nod_component=NOD32MOD_WINNT_ENGLISH_INET Build:0x11081620 # nod_component=NOD32MOD_WINNT_ENGLISH_STANDARD Build:0x11081620
Hi,

I thought my computer was clean because of this online scan, but when i installed nod32 on my computer and ran an in-depth scan, this is what it found:

[external image: Posted Image]


I'm posting this as an image because i don't know where to find the log ?

I don't know what to do next as the program cannot clean these infected files (there are many other infected files, you just can't see them on the picture)
I'm afraid I cant read the picture you posted, its to blurry. ESET came up clean so I am sure those are just tracking cookies , not sure. I am not familiar with Nod32, so open it and search around for logs, it has to be in there someplace. . Usually when it finds things it Quarantines them, look for the Quarantine folder and delete it all, then run another scan and see what it comes up with



We Need to check for Rootkits with RootRepeal
Please download RootRepeal one of these locations and save it to your desktop
Here
Here
Here
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check just these boxes:
  • [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:, and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.





Download DDS by sUBs from one of the following links. Save it to your desktop.
  • DDS.com
  • DDS.scr
  • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control Here


Post both the RootRepeal log and the DDS log please
Hi, I'm unfortunately unable to run Rootrepeal, everytime i try to start it, my computer freezes and i'm unable to do anything (it uses too much RAM) And this is the DDS log: DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 19:45:03,73 on jeu. 27/08/2009 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.644 [GMT 2:00] AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\brss01a.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\UAService7.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\windows\system\hpsysdrv.exe C:\HP\KBD\KBD.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe svchost.exe C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe C:\Program Files\Innovative Solutions\DriverMax\devices.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Documents and Settings\Propriétaire\Bureau\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.compaqnet.be/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.compaqnet.be mDefault_Search_URL = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = ;*.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: NXIECatcher Class: {83b80a9c-d91a-4f22-8dcf-ea7204039f79} - c:\program files\xi\netxfer\NXIEHelper.dll BHO: IeCatch2 Class: {a5366673-e8ca-11d3-9cd9-0090271d075b} - c:\progra~1\flashget\jccatch.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} - c:\progra~1\flashget\fgiebar.dll TB: NetXfer: {c16cbaac-a75c-4db5-a0dd-cdf5cafcdd3a} - c:\program files\xi\netxfer\NXToolBar.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {83DF922D-4B34-4997-8CD6-07750881DD69} - No File TB: MSN: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - EB: &Organise-notes Encarta: {9455301c-cf6b-11d3-a266-00c04f689c50} - c:\program files\fichiers communs\microsoft shared\encarta researcher\EROPROJ.DLL EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [pbmini] c:\program files\pcast\podcastbarmini\PodcastBarMiniStater.exe uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe uRun: [DriverMax] "c:\program files\innovative solutions\drivermax\devices.exe" -agent uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [PS2] c:\windows\system32\ps2.exe mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.5.0_10\bin\jusched.exe" mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto StartupFolder: c:\docume~1\propri~1\menudm~1\progra~1\dmarra~1\adobeg~1.lnk - c:\program files\fichiers communs\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\propri~1\menudm~1\progra~1\dmarra~1\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\norton~1.lnk - c:\program files\norton systemworks\norton goback\GBTray.exe StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe uPolicies-explorer: NoViewOnDrive = 0 (0x0) mPolicies-explorer: = IE: Téléchargement par NetXfer - c:\program files\xi\netxfer\NXAddLink.html IE: Télécharger avec FlashGet - c:\program files\flashget\jc_link.htm IE: Télécharger tout avec FlashGet - c:\program files\flashget\jc_all.htm IE: Téléchargez tous par NetXfer - c:\program files\xi\netxfer\NXAddList.html IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\flashget\flashget.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {9455301C-CF6B-11D3-A266-00C04F689C50} - {9455301C-CF6B-11D3-A266-00C04F689C50} - c:\program files\fichiers communs\microsoft shared\encarta researcher\EROPROJ.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: c:\windows\system32\imon.dll DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll Handler: msero - {B0D92A71-886B-453B-A649-1B91F93801E7} - c:\program files\fichiers communs\microsoft shared\encarta researcher\MSERO.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: igfxcui - igfxsrvc.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\propri~1\applic~1\mozilla\firefox\profiles\ljt6ccrk.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPNXCatcher(Audio).dll FF - plugin: c:\program files\mozilla firefox\plugins\NPNXCatcher(Video).dll FF - plugin: c:\program files\mozilla firefox\plugins\NPNXCatcher.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2007-3-31 15424] R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2007-3-31 552064] R3 rootrepeal1;rootrepeal1;\??\c:\windows\system32\drivers\rootrepeal1.sys –> c:\windows\system32\drivers\rootrepeal1.sys [?] S3 naecd;naecd;\??\c:\docume~1\propri~1\locals~1\temp\naecd.sys –> c:\docume~1\propri~1\locals~1\temp\naecd.sys [?] S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys –> c:\windows\system32\drivers\rootrepeal.sys [?] =============== Created Last 30 ================ 2009-08-25 12:32 –d—– c:\docume~1\propri~1\applic~1\Malwarebytes 2009-08-25 12:32 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-25 12:32 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-25 12:32 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-25 12:32 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-22 17:41 1,089,883 -c—— c:\windows\system32\dllcache\ntprint.cat 2009-08-22 15:04 –d-hr– c:\documents and settings\propriétaire\Recent 2009-08-22 02:08 –d—– c:\windows\system32\XPSViewer 2009-08-22 02:07 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-08-22 02:07 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-22 02:07 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-22 02:07 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-22 02:07 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-08-22 02:07 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-08-22 02:07 117,760 ——– c:\windows\system32\prntvpt.dll 2009-08-22 02:07 –d—– C:\424e6df22c4d3896c20dc9 2009-08-22 02:07 –d—– c:\windows\SxsCaPendDel 2009-08-21 21:36 –d—– c:\windows\system32\fr-fr 2009-08-21 21:36 –d—– c:\windows\system32\fr 2009-08-21 21:36 –d—– c:\windows\l2schemas 2009-08-21 21:26 –d—– c:\windows\network diagnostic 2009-08-21 21:04 128,512 -c—— c:\windows\system32\dllcache\dhtmled.ocx 2009-08-21 21:03 1,315,328 -c—— c:\windows\system32\dllcache\msoe.dll 2009-08-21 16:33 –d—– c:\program files\Trend Micro 2009-08-05 11:00 205,312 -c—— c:\windows\system32\dllcache\mswebdvd.dll 2009-07-29 06:35 119,808 -c—— c:\windows\system32\dllcache\t2embed.dll 2009-07-29 06:35 81,920 -c—— c:\windows\system32\dllcache\fontsub.dll ==================== Find3M ==================== 2009-08-27 19:06 15,466,496 a—h— c:\documents and settings\propriétaire\NTUSER.DAT 2009-08-22 02:14 546,134 a——- c:\windows\system32\perfh00C.dat 2009-08-22 02:14 99,256 a——- c:\windows\system32\perfc00C.dat 2009-08-21 22:19 96,384 a——- c:\windows\system32\drivers\sptd3661.sys 2009-08-05 11:00 205,312 a——- c:\windows\system32\mswebdvd.dll 2009-07-29 06:35 119,808 a——- c:\windows\system32\t2embed.dll 2009-07-29 06:35 81,920 a——- c:\windows\system32\fontsub.dll 2009-07-17 21:03 58,880 a——- c:\windows\system32\atl.dll 2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll 2009-06-26 18:50 670,720 a——- c:\windows\system32\wininet.dll 2009-06-26 18:50 81,920 a——- c:\windows\system32\ieencode.dll 2009-06-25 10:26 736,768 a——- c:\windows\system32\lsasrv.dll 2009-06-25 10:26 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 10:26 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 10:26 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 10:26 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-25 10:26 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-15 12:44 78,848 a——- c:\windows\system32\telnet.exe 2009-06-10 16:14 85,504 a——- c:\windows\system32\avifil32.dll 2009-06-10 09:21 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-06-10 08:15 132,096 a——- c:\windows\system32\wkssvc.dll 2009-06-03 21:10 1,297,408 a——- c:\windows\system32\quartz.dll 2009-03-09 20:12 348,435 a——- c:\program files\daft_punk_-_alive_2007__deluxe_edition-www.livedown.org.rar 2009-03-09 20:11 209,071 a——- c:\program files\00010324.rar 2005-06-12 16:39 774,144 a——- c:\program files\RngInterstitial.dll 2005-04-25 21:02 36,920 a——- c:\docume~1\propri~1\applic~1\GDIPFONTCACHEV1.DAT 2005-04-17 16:13 45,109 a——- c:\program files\rpau3260.dll 2005-04-17 16:13 55,154 a——- c:\program files\RealNetworks License.html 2005-04-17 16:13 55,154 a——- c:\program files\playrlic.html 2005-04-17 16:13 53,279 a——- c:\program files\RealNetworks License.txt 2005-04-17 16:13 53,279 a——- c:\program files\playrlic.txt 2005-04-17 16:13 53,098 a——- c:\program files\presets.rnx 2005-04-17 16:13 480 a——- c:\program files\keys.dat 2005-04-17 16:13 61,495 a——- c:\program files\ssimages.vs 2003-04-23 14:24 0 a–sh— c:\windows\sminst\HPCD.SYS 2005-06-28 22:10 56 —shr– c:\windows\system32\247D9E5260.sys ============= FINISH: 19:46:29,35 ===============
While I am looking over your log, run this program

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi, I attached the Gmer log, because when I posted it here it was all messed up (very hard to read the way it was). Here is an example of the files NOD32 finds (the files you couln't see on the blurry picture): C:\matchslive.rar »RAR »installerKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\matchslive.rar »RAR »self-extractorKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\matchslive.rar »RAR »README-FIRSTKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\matchslive.rar »RAR »self-extractorKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\matchslive.rar »RAR »README-FIRSTKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\matchslive.rar »RAR »setupKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\ml_sc.rar »RAR »setupKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\ml_sc.rar »RAR »self-extractorKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\ml_sc.rar »RAR »installerKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\ml_sc.rar »RAR »readmeKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\ml_sc.rar »RAR »README-FIRSTKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\ml_sc.rar »RAR »InfoKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\nbalp.rar »RAR »self-extractorKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\nbalp.rar »RAR »README-FIRSTKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\nbalp.rar »RAR »InfoKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\nbalp.rar »RAR »readmeKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\nbalp.rar »RAR »README-FIRSTKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\nbalp.rar »RAR »readmeKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\00010309.rar »RAR »patchKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\00010309.rar »RAR »readmeKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\00010310.rar »RAR »self-installerKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\00010310.rar »RAR »setupKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\00010311.rar »RAR »keygenKeyGen.exe - a variant of Win32/Injector.XJ trojan C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\00010311.rar »RAR »readmeKeyGen.exe - a variant of Win32/Injector.XJ trojan

Attachments:

Run this quick scan, wont take long


Please download Rooter Rootkit Detector to your Desktop
  • Doubleclick it to start the tool.
  • A Notepad file containing the report will open, also found at %systemdrive% (usually C:\Rooter.txt.
  • Post the report for me to see.
Hi,

Here is the report:

Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully …
.
Windows XP Home Edition (5.1.2600) Service Pack 3
[32_bits] - x86 Family 6 Model 8 Stepping 1, AuthenticAMD
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Enabled
.
Internet Explorer 6.0.2900.5512
Mozilla Firefox 3.0.13 (fr)
.
A:\ [Removable]
C:\ [Fixed-NTFS] .. ( Total:52 Go - Free:3 Go )
D:\ [Fixed-NTFS] .. ( Total:3 Go - Free:0 Go )
E:\ [CD_Rom]
F:\ [CD_Rom]
G:\ [CD_Rom]
H:\ [CD_Rom]
.
Scan : 19:29.20
Path : C:\Documents and Settings\Propriétaire\Bureau\Rooter.exe
User : Propriétaire ( Administrator -> YES )
.
———————-\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (608)
______ \??\C:\WINDOWS\system32\csrss.exe (656)
______ \??\C:\WINDOWS\system32\winlogon.exe (684)
______ C:\WINDOWS\system32\services.exe (732)
______ C:\WINDOWS\system32\lsass.exe (744)
______ C:\WINDOWS\system32\Ati2evxx.exe (904)
______ C:\WINDOWS\system32\svchost.exe (916)
______ C:\WINDOWS\system32\svchost.exe (1000)
______ C:\WINDOWS\System32\svchost.exe (1048)
______ C:\WINDOWS\System32\svchost.exe (1104)
______ C:\WINDOWS\system32\brsvc01a.exe (1316)
______ C:\WINDOWS\system32\spoolsv.exe (1332)
______ C:\WINDOWS\system32\brss01a.exe (1344)
______ C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (1464)
______ C:\Program Files\Bonjour\mDNSResponder.exe (1480)
______ C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe (1512)
______ C:\Program Files\Java\jre6\bin\jqs.exe (1552)
______ C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe (1608)
______ C:\Program Files\Eset\nod32krn.exe (1652)
______ C:\WINDOWS\system32\PnkBstrA.exe (1668)
______ C:\WINDOWS\system32\PnkBstrB.exe (1680)
______ C:\WINDOWS\system32\wdfmgr.exe (1748)
______ C:\WINDOWS\system32\UAService7.exe (1800)
______ C:\WINDOWS\System32\alg.exe (248)
______ C:\WINDOWS\system32\Ati2evxx.exe (472)
______ C:\WINDOWS\Explorer.EXE (1080)
______ C:\windows\system\hpsysdrv.exe (2020)
______ C:\HP\KBD\KBD.EXE (792)
______ C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (520)
______ C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe (800)
______ C:\Program Files\Eset\nod32kui.exe (1416)
______ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (1856)
______ C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (1716)
______ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (2052)
______ C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (2088)
______ C:\Program Files\Innovative Solutions\DriverMax\devices.exe (2104)
______ C:\Program Files\MSN Messenger\msnmsgr.exe (2172)
______ C:\WINDOWS\System32\svchost.exe (2216)
______ C:\Program Files\Messenger\msmsgs.exe (2240)
______ C:\Program Files\Logitech\SetPoint\SetPoint.exe (2556)
______ C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe (2592)
______ C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (2620)
______ C:\Program Files\SpywareGuard\sgmain.exe (2680)
______ C:\Program Files\SpywareGuard\sgbhp.exe (2868)
______ C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE (2968)
______ C:\WINDOWS\system32\wuauclt.exe (3640)
______ C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe (3932)
______ C:\Program Files\Mozilla Firefox\firefox.exe (480)
______ C:\WINDOWS\System32\svchost.exe (508)
______ C:\WINDOWS\System32\svchost.exe (3784)
______ C:\Documents and Settings\Propriétaire\Bureau\gmer\gmer.exe (2988)
______ C:\WINDOWS\system32\NOTEPAD.EXE (1876)
______ C:\Documents and Settings\Propriétaire\Bureau\Rooter.exe (2316)
.
———————-\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:3471035904)
\Device\Harddisk0\Partition2 –[ MBR ]– (Start_Offset:3471068160 | Length:56540574720)
.
———————-\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Tasks\Symantec NetDetect.job
.
———————-\\ Registry
.
.
———————-\\ Files & Folders
.
C:\PROGRA~1\Adverts
==> Lop <==
.
———————-\\ Scan completed at 19:29.31
.
C:\Rooter$\Rooter_1.txt - (28/08/2009 | 19:29.31)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI