This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Very slow computer/ restarts randomly

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been running very slow lately and it restarts randomly. Can you please tell me what's wrong? Thanks!



Logfile of HijackThis v1.99.1
Scan saved at 10:14:27 PM, on 11/24/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\NMSSvc.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\System32\hkcmd.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\GWMDMMSG.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe
C:\WINDOWS\System32\svchost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Documents and Settings\Owner\My Documents\My Pictures\mark\Program Setups\virus removal\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gatewaybiz.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\system32\dzd.dll
O2 - BHO: (no name) - {D8074F73-72AD-E5D9-9D00-1256B599AA8B} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [rvqkvze] C:\WINDOWS\rvqkvze.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunOnce: [System Mechanic Cache Cleanup] C:\Program Files\iolo\System Mechanic 4\SysMech4.exe /COMPLETECACHE
O4 - HKLM\..\RunOnce: [dvd4r.exe] C:\WINDOWS\System32\dvd4r.exe /k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe"
O4 - HKCU\..\Run: [Kop4RTK5j] rpcvw.exe
O4 - HKCU\..\Run: [Oconjll] C:\WINDOWS\System32\t?skmgr.exe
O4 - HKCU\..\Run: [Ltho] "C:\Program Files\sder\dees.exe" -vt yazr
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
I still have the same problem… slow computer… randomly restarts… here's a new log:

Logfile of HijackThis v1.99.1
Scan saved at 4:11:51 PM, on 12/6/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\NMSSvc.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\GWMDMMSG.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\c6mpjwp.exe
C:\Documents and Settings\Owner\My Documents\My Pictures\mark\Program Setups\virus removal\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gatewaybiz.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\system32\ao9z.dll
O2 - BHO: (no name) - {D8074F73-72AD-E5D9-9D00-1256B599AA8B} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [rvqkvze] C:\WINDOWS\rvqkvze.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [System Mechanic Cache Cleanup] C:\Program Files\iolo\System Mechanic 4\SysMech4.exe /COMPLETECACHE
O4 - HKLM\..\RunOnce: [qp5yxx.exe] C:\WINDOWS\System32\qp5yxx.exe /k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe"
O4 - HKCU\..\Run: [Kop4RTK5j] rpcvw.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
STEP 1.
======
SpySweeper
Please download WebRoot SpySweeper .
(It's a 2 week trial):
  • Click the Free Trial link under to "SpySweeper" to download the program.
  • Install it.
  • Once the program is installed, it will open.
  • It will prompt you to update to the latest definitions, click Yes.
  • Once the definitions are installed, click Sweep Now on the left side.
  • Click the Start button.
  • When it's done scanning, click the Next button.
  • Make sure everything has a check next to it, then click the Next button.
  • It will remove all of the items found.
  • Click Session Log in the upper right corner, copy everything in that window.
  • Click the Summary tab and click Finish.
  • Paste the contents of the session log you copied into your next reply.
STEP 2.
======
Download Ewido
  • Download and install Ewido Security Suite It is a free trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
STEP 3.
======
Update Ewido
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use Ewido manual updates

STEP 4.
======
Ewido Scan
Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.**
    o You will need to step through the process of cleaning files one-by-one.
    o If ewido detects a file you KNOW to be legitimate, select none as the action.
    o DO NOT select "Perform action on all infections"
    o If you are unsure of any entry found select none for now.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")


STEP 5.
======
CWShredder

Please download and run CWShredder
Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

STEP 6.
======

Please do an onlione scan here >>>> http://housecall.trendmicro.com/ and allow it to clean/remove what it finds.


Please post the results from SpySweeper, ewido and a new hijackthis log
Here's the logs…


********
6:25 PM: | Start of Session, Tuesday, December 06, 2005 |
6:25 PM: Spy Sweeper started
6:25 PM: Sweep initiated using definitions version 578
6:25 PM: Starting Memory Sweep
6:36 PM: Memory Sweep Complete, Elapsed Time: 00:10:09
6:36 PM: Starting Registry Sweep
6:36 PM: Found Adware: bookedspace
6:36 PM: HKLM\software\configuration manager\cfgmgr52\ (168 subtraces) (ID = 104873)
6:36 PM: Found Adware: internetoptimizer
6:36 PM: HKLM\software\classes\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\ (7 subtraces) (ID = 128897)
6:36 PM: HKCR\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\ (7 subtraces) (ID = 128933)
6:36 PM: Found Adware: moneytree
6:36 PM: HKCR\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\ (7 subtraces) (ID = 128933)
6:36 PM: HKLM\software\classes\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\1.0\flags\ (1 subtraces) (ID = 135204)
6:36 PM: HKLM\software\classes\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\1.0\helpdir\ (1 subtraces) (ID = 135205)
6:36 PM: Found Adware: neededware
6:36 PM: HKCR\clsid\{41aa3336-2d3f-4bc6-a06e-f8dcccd1a40a}\ (17 subtraces) (ID = 135803)
6:36 PM: HKCR\clsid\{687d80d2-17e5-40df-a5a9-426dc36b6ad1}\ (1 subtraces) (ID = 135807)
6:36 PM: HKCR\epxactivex.epxactivexctrl.1\ (3 subtraces) (ID = 135812)
6:36 PM: HKLM\software\classes\clsid\{41aa3336-2d3f-4bc6-a06e-f8dcccd1a40a}\ (17 subtraces) (ID = 135822)
6:36 PM: HKLM\software\classes\clsid\{687d80d2-17e5-40df-a5a9-426dc36b6ad1}\ (1 subtraces) (ID = 135826)
6:36 PM: HKLM\software\classes\epxactivex.epxactivexctrl.1\ (3 subtraces) (ID = 135831)
6:36 PM: HKLM\software\classes\typelib\{7acd8c16-81e3-4b54-95d6-6e8d600654c3}\ (9 subtraces) (ID = 135837)
6:36 PM: HKLM\software\classes\typelib\{375743f3-736c-4377-86b6-06618f1cd726}\ (9 subtraces) (ID = 135838)
6:36 PM: HKLM\software\classes\typelib\{df454277-1009-4413-bfdc-502d1b8bd49e}\ (9 subtraces) (ID = 135841)
6:36 PM: HKCR\typelib\{7acd8c16-81e3-4b54-95d6-6e8d600654c3}\ (9 subtraces) (ID = 135852)
6:36 PM: HKCR\typelib\{375743f3-736c-4377-86b6-06618f1cd726}\ (9 subtraces) (ID = 135853)
6:36 PM: HKCR\typelib\{df454277-1009-4413-bfdc-502d1b8bd49e}\ (9 subtraces) (ID = 135856)
6:36 PM: Found Adware: mirinda
6:36 PM: HKCR\clsid\{7a1693a1-afaf-4f1e-9b05-eec38a85fbf3}\ (4 subtraces) (ID = 501125)
6:36 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{7a1693a1-afaf-4f1e-9b05-eec38a85fbf3}\ (ID = 501141)
6:36 PM: Found Adware: clkoptimizer
6:36 PM: HKLM\software\qstat\ (5 subtraces) (ID = 769771)
6:36 PM: Found Adware: ezula ilookup
6:36 PM: HKLM\software\microsoft\webext\ (1 subtraces) (ID = 828947)
6:36 PM: HKLM\software\qstat\ || brr (ID = 877670)
6:36 PM: Found Adware: safesurf
6:36 PM: HKLM\software\rasmon\ (19 subtraces) (ID = 966765)
6:36 PM: HKLM\software\microsoft\windows\currentversion\uninstall\rasmon\ (2 subtraces) (ID = 966833)
6:36 PM: HKLM\system\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\irasyncd.exe\ (1 subtraces) (ID = 966837)
6:36 PM: HKLM\software\microsoft\windows\currentversion\uninstall\webnexus\ (2 subtraces) (ID = 1006191)
6:36 PM: Found Adware: browseraid
6:36 PM: HKU\S-1-5-21-1060284298-1637723038-839522115-1003\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (1 subtraces) (ID = 105078)
6:36 PM: Found Adware: drsnsrch.com hijack
6:36 PM: HKU\S-1-5-21-1060284298-1637723038-839522115-1003\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
6:36 PM: Found Trojan Horse: trojan-downloader-moneymind
6:36 PM: HKU\S-1-5-21-1060284298-1637723038-839522115-1003\software\xjado\ (1 subtraces) (ID = 144725)
6:36 PM: Found Adware: websearch toolbar
6:36 PM: HKU\S-1-5-21-1060284298-1637723038-839522115-1003\software\microsoft\internet explorer\urlsearchhooks\ || _{8952a998-1e7e-4716-b23d-3dbe03910972} (ID = 146465)
6:36 PM: Found Trojan Horse: trojan-downloader-pacisoft
6:36 PM: HKU\S-1-5-21-1060284298-1637723038-839522115-1003\software\apd123\ (12 subtraces) (ID = 861435)
6:37 PM: Registry Sweep Complete, Elapsed Time:00:00:58
6:37 PM: Starting Cookie Sweep
6:37 PM: Found Spy Cookie: 2o7.net cookie
6:37 PM: owner@2o7[1].txt (ID = 1957)
6:37 PM: Found Spy Cookie: yieldmanager cookie
6:37 PM: [removed][2].txt (ID = 3751)
6:37 PM: Found Spy Cookie: hbmediapro cookie
6:37 PM: [removed][2].txt (ID = 2768)
6:37 PM: Found Spy Cookie: adrevolver cookie
6:37 PM: owner@adrevolver[1].txt (ID = 2088)
6:37 PM: owner@adrevolver[2].txt (ID = 2088)
6:37 PM: Found Spy Cookie: ask cookie
6:37 PM: owner@ask[1].txt (ID = 2245)
6:37 PM: Found Spy Cookie: atwola cookie
6:37 PM: owner@atwola[1].txt (ID = 2255)
6:37 PM: Found Spy Cookie: banner cookie
6:37 PM: owner@banner[2].txt (ID = 2276)
6:37 PM: Found Spy Cookie: bluestreak cookie
6:37 PM: owner@bluestreak[2].txt (ID = 2314)
6:37 PM: Found Spy Cookie: casalemedia cookie
6:37 PM: owner@casalemedia[1].txt (ID = 2354)
6:37 PM: Found Spy Cookie: realmedia cookie
6:37 PM: owner@realmedia[2].txt (ID = 3235)
6:37 PM: Found Spy Cookie: tradedoubler cookie
6:37 PM: owner@tradedoubler[1].txt (ID = 3575)
6:37 PM: Found Spy Cookie: trafficmp cookie
6:37 PM: owner@trafficmp[1].txt (ID = 3581)
6:37 PM: Found Spy Cookie: zedo cookie
6:37 PM: owner@zedo[2].txt (ID = 3762)
6:37 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
6:37 PM: Starting File Sweep
6:37 PM: c:\windows\cfgmgr52 (10 subtraces) (ID = -2147479590)
6:38 PM: stlb2.xml (ID = 51947)
6:38 PM: unrasmon.exe (ID = 187013)
6:41 PM: winstat11.dat (ID = 70669)
6:42 PM: winstat10.dll (ID = 93792)
6:42 PM: Warning: Failed to open file "c:\windows\winsxs\\msvcirt.dll". The system cannot find the file specified
6:43 PM: Warning: Failed to open file "c:\windows\winsxs\\msvcirt.dll". The system cannot find the file specified
6:43 PM: Found Adware: apropos
6:43 PM: wingenerics.dll (ID = 50187)
6:45 PM: Warning: Failed to open file "c:\windows\winsxs\\msvcrt.dll". The system cannot find the file specified
6:45 PM: Warning: Failed to open file "c:\windows\winsxs\\msvcrt.dll". The system cannot find the file specified
6:47 PM: fran-hot.exe (ID = 179190)
6:47 PM: osd4.osd (ID = 70665)
6:47 PM: File Sweep Complete, Elapsed Time: 00:10:15
6:47 PM: Full Sweep has completed. Elapsed time 00:21:32
6:47 PM: Traces Found: 399
6:49 PM: Removal process initiated
6:49 PM: Quarantining All Traces: clkoptimizer
6:49 PM: Quarantining All Traces: trojan-downloader-moneymind
6:49 PM: Quarantining All Traces: websearch toolbar
6:49 PM: Quarantining All Traces: apropos
6:49 PM: apropos is in use. It will be removed on reboot.
6:49 PM: wingenerics.dll is in use. It will be removed on reboot.
6:49 PM: Quarantining All Traces: internetoptimizer
6:49 PM: Quarantining All Traces: trojan-downloader-pacisoft
6:49 PM: Quarantining All Traces: bookedspace
6:49 PM: Quarantining All Traces: browseraid
6:49 PM: Quarantining All Traces: drsnsrch.com hijack
6:49 PM: Quarantining All Traces: ezula ilookup
6:49 PM: Quarantining All Traces: mirinda
6:49 PM: Quarantining All Traces: moneytree
6:49 PM: Quarantining All Traces: neededware
6:49 PM: Quarantining All Traces: safesurf
6:49 PM: Quarantining All Traces: 2o7.net cookie
6:49 PM: Quarantining All Traces: adrevolver cookie
6:49 PM: Quarantining All Traces: ask cookie
6:49 PM: Quarantining All Traces: atwola cookie
6:49 PM: Quarantining All Traces: banner cookie
6:49 PM: Quarantining All Traces: bluestreak cookie
6:49 PM: Quarantining All Traces: casalemedia cookie
6:49 PM: Quarantining All Traces: hbmediapro cookie
6:49 PM: Quarantining All Traces: realmedia cookie
6:49 PM: Quarantining All Traces: tradedoubler cookie
6:49 PM: Quarantining All Traces: trafficmp cookie
6:49 PM: Quarantining All Traces: yieldmanager cookie
6:49 PM: Quarantining All Traces: zedo cookie
6:50 PM: Removal process completed. Elapsed time 00:00:49
********
6:22 PM: | Start of Session, Tuesday, December 06, 2005 |
6:22 PM: Spy Sweeper started
6:24 PM: Messenger service has been disabled.
6:25 PM: Your spyware definitions have been updated.
6:25 PM: | End of Session, Tuesday, December 06, 2005 |




———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 7:49:28 PM, 12/6/2005
+ Report-Checksum: 2A758417

+ Scan result:

C:\Documents and Settings\Owner\Local Settings\Temp\0oi.sys -> Trojan.Kolweb.g : Cleaned without backup
C:\WINDOWS\0oi.sys -> Trojan.Kolweb.g : Cleaned without backup
C:\WINDOWS\system32\0oi.sys -> Trojan.Kolweb.g : Cleaned without backup
C:\WINDOWS\system32\ao9z.dll -> Trojan.Kolweb.f : Cleaned without backup
C:\WINDOWS\system32\c6mpjwp.exe -> Trojan.Kolweb.g : Cleaned without backup
C:\WINDOWS\system32\qp5yxx.exe -> Trojan.Kolweb.g : Cleaned without backup


::Report End


Logfile of HijackThis v1.99.1
Scan saved at 8:21:09 PM, on 12/6/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\GWMDMMSG.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\My Documents\My Pictures\mark\Program Setups\virus removal\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gatewaybiz.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\system32\ao9z.dll (file missing)
O2 - BHO: (no name) - {D8074F73-72AD-E5D9-9D00-1256B599AA8B} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [rvqkvze] C:\WINDOWS\rvqkvze.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe"
O4 - HKCU\..\Run: [Kop4RTK5j] rpcvw.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Scan with hijackthis and put a check besdie these lines and then choose FIX

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\system32\ao9z.dll (file missing)
O2 - BHO: (no name) - {D8074F73-72AD-E5D9-9D00-1256B599AA8B} - (no file)

O4 - HKLM\..\Run: [rvqkvze] C:\WINDOWS\rvqkvze.exe
O4 - HKCU\..\Run: [Kop4RTK5j] rpcvw.exe

O15 - Trusted Zone: http://www.neededware.com

O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab

O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\

Then boot to safe mode (tap f8 wile bioe loads) make sure all hidden files/folders and visable

1.
On the Tools menu in Windows Explorer, click Folder Options.

2.
Click the View tab.

3.
Under Hidden files and folders, click Show hidden files and folders.

Then look for and delete these files if present

C:\WINDOWS\rvqkvze.exe
rpcvw.exe

Reboot.

Please do a scan here >>>> http://www.kaspersky.com/virusscanner

Post the log it produces and a new hijackthis log please.
——————————————————————————-
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, December 07, 2005 06:08:48
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 6/12/2005
Kaspersky Anti-Virus database records: 163482
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 28070
Number of viruses found: 14
Number of infected objects: 39
Number of suspicious objects: 1
Duration of the scan process: 2533 sec

Infected Object Name - Virus Name
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP216\A0070384.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP219\A0072383.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP219\A0072391.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP219\A0073389.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP223\A0077408.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP224\A0079407.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP238\A0095624.exe Infected: Trojan-Downloader.Win32.Agent.vp
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP238\A0095626.dll Infected: not-a-virus:AdWare.Win32.Winsta.a
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP246\A0098689.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102759.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102760.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102761.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102762.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102763.sys Suspicious: Rootkit.Win32.Agent.ao
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP253\A0103753.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP253\A0103754.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP256\A0104945.exe Infected: Trojan-Dropper.Win32.Agent.abb
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP256\A0104949.exe/data0006 Infected: Trojan-Dropper.Win32.VB.kk
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP256\A0104949.exe Infected: Trojan-Dropper.Win32.VB.kk
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106855.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106856.exe Infected: Trojan-Downloader.Win32.VB.nw
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106857.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106858.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106860.cpl Infected: Trojan-Downloader.Win32.Qoologic.at
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106861.dll Infected: Trojan-Downloader.Win32.Qoologic.at
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106898.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP259\A0106905.dll Infected: Trojan.Win32.Kolweb.f
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP259\A0106909.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP259\A0106910.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111942.exe Infected: Trojan-Dropper.Win32.Agent.abb
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111947.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111954.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111955.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111956.dll Infected: Trojan.Win32.Kolweb.f
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111957.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111958.exe Infected: Trojan.Win32.Kolweb.g
C:\WINDOWS\hosts Infected: Trojan.Win32.Qhost.en
C:\WINDOWS\icont.exe Infected: not-a-virus:AdWare.Win32.AdURL.c
C:\WINDOWS\system32\msshed32.exe Infected: Trojan-Downloader.Win32.Delf.zw
C:\WINDOWS\system32\pdhncode.dll Infected: Trojan.Win32.Crypt.t

Scan process completed.



Logfile of HijackThis v1.99.1
Scan saved at 6:18:23 AM, on 12/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\GWMDMMSG.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\My Documents\My Pictures\mark\Program Setups\virus removal\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gatewaybiz.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
Sorry it took so long to reply… i had some trouble with the scanners…. here are the new logs…


——————————————————————————-
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, December 14, 2005 19:39:24
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 15/12/2005
Kaspersky Anti-Virus database records: 165201
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 28348
Number of viruses found: 14
Number of infected objects: 40
Number of suspicious objects: 1
Duration of the scan process: 2622 sec

Infected Object Name - Virus Name
C:\Documents and Settings\Owner\.housecall\Quarantine\msshed32.exe.bac_a05492 Infected: Trojan-Downloader.Win32.Delf.zw
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP216\A0070384.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP219\A0072383.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP219\A0072391.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP219\A0073389.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP223\A0077408.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP224\A0079407.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP238\A0095624.exe Infected: Trojan-Downloader.Win32.Agent.vp
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP238\A0095626.dll Infected: not-a-virus:AdWare.Win32.Winsta.a
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP246\A0098689.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102759.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102760.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102761.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102762.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102763.sys Suspicious: Rootkit.Win32.Agent.ao
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP253\A0103753.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP253\A0103754.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP256\A0104945.exe Infected: Trojan-Dropper.Win32.Agent.abb
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP256\A0104949.exe/data0006 Infected: Trojan-Dropper.Win32.VB.kk
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP256\A0104949.exe Infected: Trojan-Dropper.Win32.VB.kk
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106855.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106856.exe Infected: Trojan-Downloader.Win32.VB.nw
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106857.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106858.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106860.cpl Infected: Trojan-Downloader.Win32.Qoologic.at
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106861.dll Infected: Trojan-Downloader.Win32.Qoologic.at
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106898.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP259\A0106905.dll Infected: Trojan.Win32.Kolweb.f
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP259\A0106909.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP259\A0106910.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111942.exe Infected: Trojan-Dropper.Win32.Agent.abb
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111943.dll Infected: not-a-virus:AdWare.Win32.Winsta.b
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111947.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111954.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111955.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111956.dll Infected: Trojan.Win32.Kolweb.f
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111957.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111958.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP277\A0122246.exe Infected: Trojan-Downloader.Win32.Delf.zw
C:\WINDOWS\icont.exe Infected: not-a-virus:AdWare.Win32.AdURL.c
C:\WINDOWS\system32\pdhncode.dll Infected: Trojan.Win32.Crypt.t

Scan process completed.





Logfile of HijackThis v1.99.1
Scan saved at 7:41:12 PM, on 12/14/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\GWMDMMSG.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\My Documents\My Pictures\mark\Program Setups\virus removal\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gatewaybiz.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
Scan with hijackthis and put a chek beside this line and choose FIX

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

NEXT

Download TheKillbox from here http://www.downloads.subratam.org/KillBox.zip Save to your Desktop and double click it to open it up. In the 'Enter Full Path and Filename to Delete' box, copy and paste these entries one by one, clicking 'Find and Kill This File' after each one:

C:\WINDOWS\icont.exe


C:\WINDOWS\system32\pdhncode.dll

Then reboot and post a new hijackthis log and Kapersky log please.
——————————————————————————-
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, December 14, 2005 22:27:37
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 15/12/2005
Kaspersky Anti-Virus database records: 165234
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 28019
Number of viruses found: 14
Number of infected objects: 42
Number of suspicious objects: 1
Duration of the scan process: 2963 sec

Infected Object Name - Virus Name
C:\!KillBox\icont.exe Infected: not-a-virus:AdWare.Win32.AdURL.c
C:\!KillBox\pdhncode.dll Infected: Trojan.Win32.Crypt.t
C:\Documents and Settings\Owner\.housecall\Quarantine\msshed32.exe.bac_a05492 Infected: Trojan-Downloader.Win32.Delf.zw
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP216\A0070384.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP219\A0072383.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP219\A0072391.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP219\A0073389.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP223\A0077408.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP224\A0079407.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP238\A0095624.exe Infected: Trojan-Downloader.Win32.Agent.vp
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP238\A0095626.dll Infected: not-a-virus:AdWare.Win32.Winsta.a
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP246\A0098689.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102759.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102760.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102761.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102762.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP252\A0102763.sys Suspicious: Rootkit.Win32.Agent.ao
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP253\A0103753.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP253\A0103754.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP256\A0104945.exe Infected: Trojan-Dropper.Win32.Agent.abb
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP256\A0104949.exe/data0006 Infected: Trojan-Dropper.Win32.VB.kk
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP256\A0104949.exe Infected: Trojan-Dropper.Win32.VB.kk
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106855.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106856.exe Infected: Trojan-Downloader.Win32.VB.nw
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106857.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106858.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106860.cpl Infected: Trojan-Downloader.Win32.Qoologic.at
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106861.dll Infected: Trojan-Downloader.Win32.Qoologic.at
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP258\A0106898.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP259\A0106905.dll Infected: Trojan.Win32.Kolweb.f
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP259\A0106909.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP259\A0106910.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111942.exe Infected: Trojan-Dropper.Win32.Agent.abb
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111943.dll Infected: not-a-virus:AdWare.Win32.Winsta.b
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111947.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111954.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111955.sys Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111956.dll Infected: Trojan.Win32.Kolweb.f
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111957.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP269\A0111958.exe Infected: Trojan.Win32.Kolweb.g
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP277\A0122246.exe Infected: Trojan-Downloader.Win32.Delf.zw
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP277\A0122253.exe Infected: not-a-virus:AdWare.Win32.AdURL.c
C:\System Volume Information\_restore{D31DE61E-9219-4DBE-AF32-1DA3B21E2EE7}\RP277\A0122254.dll Infected: Trojan.Win32.Crypt.t

Scan process completed.




Logfile of HijackThis v1.99.1
Scan saved at 3:46:58 PM, on 12/15/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\GWMDMMSG.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\My Documents\My Pictures\mark\Program Setups\virus removal\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gatewaybiz.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
It's been running a lot better. I haven't had it restart at all on its own in quite a while. I do need help with those things in the system restore files that kaspersky is detecting though because the mcafee anti virus program that i use detects them all the time and im not sure if it'd be safe to delete them or not. The overall performance of my pc has gotten a lot better though.
Lets do some cleaning see if that helps

Download ccleaner from the link below, save it to your desktop. Open ccleaner and click on run ccleaner at the bottom right.

http://www.majorgeeks.com/download4191.html

Next download Regseeker from the link below. Save it to your destop. Open Regseeker and click on clean registry, next click ok. Once the scan is complete make sure the make backups is checked and then select all and delete it.

http://www.majorgeeks.com/download2579.html

Reboot.

Then turn restore off then back on.

To turn off Windows XP System Restore:

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives" as shown in this illustration:
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Proceed with what you need to do; for example, virus removal. When you have finished, restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.


How is it running now?
Lets do some cleaning see if that helps

Download ccleaner from the link below, save it to your desktop. Open ccleaner and click on run ccleaner at the bottom right.

http://www.majorgeeks.com/download4191.html

Next download Regseeker from the link below. Save it to your destop. Open Regseeker and click on clean registry, next click ok. Once the scan is complete make sure the make backups is checked and then select all and delete it.

http://www.majorgeeks.com/download2579.html

Reboot.

Then turn restore off then back on.

To turn off Windows XP System Restore:

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives" as shown in this illustration:
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Proceed with what you need to do; for example, virus removal. When you have finished, restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.


How is it running now

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI