This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adware:Virtumonde, winfixer...here is HJT log

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear Friend
Here is HJT log file contents. My system is effected with virtumonde, winfixer, winantivirus pro etc etc.. tried a lot to get rid of these but could not get though. i'd appreciate if you can help me to get rid of all this. I do not want to re-format my hard drive as system is running fine and I do not wanna put any exra bugs on this.
Please suggest.
Here we go :


Logfile of HijackThis v1.99.1
Scan saved at 6:29:25 PM, on 9/14/2a006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Ajay Sharma\Desktop\Unused Desktop Shortcuts\hjt\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://www.charter.net/diskless/bin/tgctlcm.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/downl…lscbase5059.cab
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://www.sidestep.com/get/k42037/sb02b.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://www.homesteadhotels.com/minisite/ac…nd/MSSurVid.cab
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} - http://download.redswoosh.net/Installer/113/rssoft.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe (file missing)

Thanks
Dynamic, :D

Welcome to the forum, don't know what you did or did not do but I see no evidence of any of the infections that you say you have.


DO THIS FIRST
Your HIJACKTHIS program is current, but it is very important that it resides in its own folder.
We will use Hijackthis (HJT) to make changes to your system and HJT will make backups of those changes,
If HJT is not in its own folder, those backups could be lost.

Easy to fix.
  • just go to My Computer > YOUR C:\ DRIVE > Program Files and create a new folder and name it Hijackthis .
  • Now scroll to where you have HJT currently, right click on the HJT icon and select CUT .
  • Now open the new folder you just created and right click within that folder and select PASTE .
  • Now HJT should reside in C:\Program Files\Hijackthis\Hijackthis.exe
Please do not proceed until you have moved HJT




Open HJT Scan Only, close your browser and all open windows, check these and click on Fix Checked.


O15 - Trusted Zone: http://locator.cdn.imageservr.com

O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://www.sidestep.com/get/k42037/sb02b.cab
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} - http://download.redswoosh.net/Installer/113/rssoft.cab




Go to the folder that you have HJT in and right click on the HJT icon [external image: Posted Image] and rename it to Analyser.exe and post a new log into this thread.

Ken :D
Hello Ken Thanks for your quick response. I really appreciate your assistance. I do not know why HJT log has not any info about winfixer, virtumonde etc but I keep getting messages from ewido anti-spyware that I do have virtumonde spyware in my system . My norton anti virus says about winfixer and PC tool's spyware doctor detect winantivirus infection in registry but not getting it cleaned. I'll make the changes that you told today and post the new hjt log. I'm in US EST time zone and right now in office. i can do this only after office ..mean after 8 - 9 hours by now. Thanks once again for your time. Dynamic
Dynamic, :D

The lowlife that write garbage like virtumonde are getting pretty cagey, they have written it to avoid detection by HJT, when you rename it, it will pick up that infecton if its present. If nothing shows up after renaming HJT, then we can run the tools for removing them and that will also tell us if there present.

Ken :D
Hi Ken :)
Here we go …


Logfile of HijackThis v1.99.1
Scan saved at 5:28:31 PM, on 9/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\Analyser.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {DE5C65B4-829E-470D-BB80-80A12605CF36} - (no file)
O2 - BHO: (no name) - {FB3F3C18-2976-40AA-9F61-837CF1F5748D} - C:\WINDOWS\system32\yabbc.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/downl…lscbase5059.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O20 - Winlogon Notify: tuvwxuv - tuvwxuv.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O20 - Winlogon Notify: yabbc - C:\WINDOWS\system32\yabbc.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe (file missing)

Norton is poping winfixer alert again n again….
thanks
Dynamic, :D

Worked like a charm, you are indeed infected wiht Vundo.


Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.



Open HJT Scan Only , close your browser and all open windows, if any of these entries are still present, check them and click on Fix Checked.

O2 - BHO: (no name) - {DE5C65B4-829E-470D-BB80-80A12605CF36} - (no file)

O2 - BHO: (no name) - {FB3F3C18-2976-40AA-9F61-837CF1F5748D} - C:\WINDOWS\system32\yabbc.dll

O20 - Winlogon Notify: tuvwxuv - tuvwxuv.dll (file missing)

O20 - Winlogon Notify: yabbc - C:\WINDOWS\system32\yabbc.dll


FYI
This is your Vundo infection C:\WINDOWS\system32\yabbc.dll


Run this system cleaner

Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.


Let me see the report from Vundo and a new HJT log.
Yes Ken, you are right.. yabbc.dll is the file which iz effected with vundo…(ewido shows me this), but not able to remove this…even I tried this through command prompt but no success. I think it countinusily reads registry thats why systm denied to delete this.

Anyway, I'm done with what you asked me to do. Still, i can see few files which you mentioned to delete but its not deleteing.. Bad news is even vundofix.exe could not detect the presence. few days before i ran norton's tool (vundofix.exe) but that also did not work..

Here are the log files of vundofix and hjt .

—————————————————————–
VundoFix V6.1.5

Checking Java version…

Java version is 1.4.2.3

Java version is 1.4.2.6

Java version is 1.5.0.2

Java version is 1.5.0.4

Java version is 1.5.0.6

Scan started at 7:50:49 PM 9/15/2006

Listing files found while scanning….

No infected files were found.


Beginning removal…
———————————————————————-

Logfile of HijackThis v1.99.1
Scan saved at 8:14:37 PM, on 9/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Hijackthis\Analyser.exe

O2 - BHO: (no name) - {46B00B0B-32E2-4199-922F-AAE3601CFF89} - C:\WINDOWS\system32\yabbc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/downl…lscbase5059.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O20 - Winlogon Notify: yabbc - C:\WINDOWS\system32\yabbc.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe (file missing)

————————————————————————————————

Today norton got new spyware called 'errorsafe' … looks like sister of winfixer……. I think all are from same family………:-)…
wifixer…..run iexplore.exe and give me message ' clean ur virus etc etc..bla bla..' what I do is I press ctrl + alt + del and delet the iexplore.exe process so i think it stops its further action. I use firefox browser so no way iexplore.exe should be there…. the one i get i guess is becaz of winfixer.. (just guessing),

Recently I got few other problems also like windows standard applications like volume control, paint and then windows media player disappered one by one… initially I lost volume control and later i missed paint and today I noticed that windows media player is missing….now I'm scared…….:)..I do not know ifs its becaz of all this or something else…..

standard windows update are not working properly…. it say update failed and then again give message that new updates are available and when i install its failed..so this is going on from last couple of months…….is it related with these infections..?

sorry, gave you a lot of stuff to read…:)
ken, your pofiles says that you are also in USA in EST zone….. if its okay with you then feel free to give me a call whenever you get chance. My cell number is [removed]. (I do not know ifs its okay with mod.)

Sorry if i wrote anything wrong.

Thanks
Dynamic
This is a stubborn infection to remove, lets try a few other options.

Please start by downloading

VirtumondoBegone to your desktop.
  • Reboot your computer into Safemode
  • Go to START/ SHUT OF YOUR COMPUTER/ RESTART
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
  • Then press the ENTER KEY ON YOUR KEYBOARD
  • Doubleclick on VirtumundoBeGone.exe and follow the instructions.
  • Do not worry if you see a BLUE SCREEN "Fatal Error" Message, it is normal and expected.
  • When it has finished, reboot and post the log that is created on your desktop called VBG.TXT in your next reply.
Open HJT Scan Only and remove these entries.

O2 - BHO: (no name) - {46B00B0B-32E2-4199-922F-AAE3601CFF89} - C:\WINDOWS\system32\yabbc.dll
O20 - Winlogon Notify: yabbc - C:\WINDOWS\system32\yabbc.dll






Download Pocket Killbox to your desktop, unzip it to a folder that you can find

C:\WINDOWS\system32\yabbc.dll


Highlight the file with the complete path in the Quote Box and press Ctrl C on your keyboard.
  • Open Pocket Killbox
  • Go to File > Paste from clipboard
  • Set it to Delete on Reboot
  • Tick the box that says End Explorer shell while killing file
  • If its not greyed out..Click the radio button that say Unregister .dll before deleting.
  • Make sure Single File is selected
  • Click on the Red circle with the white X
  • It will ask you to confirm the deletion…Say yes
  • It will ask you to reboot, say yes

You have Ewido installed, set it up and run it this way, be sure to check for updates, run the scan and save the report. When you open Ewido, disalbe the background guard, it may be interfering with the fix.
  • Once you have downloaded Ewido Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run Ewido and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close Ewido Anti-Spyware <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch Ewido-Anti-Spyware by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • Ewido will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close Ewido
Let me see the report from Vundobegone, the Ewido Report and a new HJT log.
Hello Ken
Here are the logs
—————————–virtumondebegone————————————————-

[09/16/2006, 8:51:23] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ajay Sharma\Desktop\VirtumundoBeGone.exe" )
[09/16/2006, 8:51:33] - Detected System Information:
[09/16/2006, 8:51:33] - Windows Version: 5.1.2600, Service Pack 2
[09/16/2006, 8:51:33] - Current Username: Ajay Sharma (Admin)
[09/16/2006, 8:51:33] - Windows is in SAFE mode with Networking.
[09/16/2006, 8:51:33] - Searching for Browser Helper Objects:
[09/16/2006, 8:51:33] - BHO 1: {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} (PCTools Site Guard)
[09/16/2006, 8:51:33] - BHO 2: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[09/16/2006, 8:51:33] - BHO 3: {B56A7D7D-6927-48C8-A975-17DF180C71AC} (PCTools Browser Monitor)
[09/16/2006, 8:51:33] - BHO 4: {B8715432-3534-4711-A9D9-3CC63FB04B4B} ()
[09/16/2006, 8:51:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[09/16/2006, 8:51:33] - Checking for HKLM\…\Winlogon\Notify\yabbc
[09/16/2006, 8:51:33] - Found: HKLM\…\Winlogon\Notify\yabbc - This is probably Virtumundo.
[09/16/2006, 8:51:33] - Assigning {B8715432-3534-4711-A9D9-3CC63FB04B4B} MSEvents Object
[09/16/2006, 8:51:33] - BHO list has been changed! Starting over…
[09/16/2006, 8:51:33] - BHO 1: {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} (PCTools Site Guard)
[09/16/2006, 8:51:33] - BHO 2: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[09/16/2006, 8:51:33] - BHO 3: {B56A7D7D-6927-48C8-A975-17DF180C71AC} (PCTools Browser Monitor)
[09/16/2006, 8:51:33] - BHO 4: {B8715432-3534-4711-A9D9-3CC63FB04B4B} (MSEvents Object)
[09/16/2006, 8:51:33] - ALERT: Found MSEvents Object!
[09/16/2006, 8:51:33] - Finished Searching Browser Helper Objects
[09/16/2006, 8:51:33] - *** Detected MSEvents Object
[09/16/2006, 8:51:33] - Trying to remove MSEvents Object…
[09/16/2006, 8:51:34] - Terminating Process: IEXPLORE.EXE
[09/16/2006, 8:51:35] - Terminating Process: RUNDLL32.EXE
[09/16/2006, 8:51:35] - Disabling Automatic Shell Restart
[09/16/2006, 8:51:35] - Terminating Process: EXPLORER.EXE
[09/16/2006, 8:51:35] - Suspending the NT Session Manager System Service
[09/16/2006, 8:51:35] - Terminating Windows NT Logon/Logoff Manager
[09/16/2006, 8:51:35] - Re-enabling Automatic Shell Restart
[09/16/2006, 8:51:35] - File to disable: C:\WINDOWS\system32\yabbc.dll
[09/16/2006, 8:51:35] - Renaming C:\WINDOWS\system32\yabbc.dll -> C:\WINDOWS\system32\yabbc.dll.vir
[09/16/2006, 8:51:36] - File successfully renamed!
[09/16/2006, 8:51:36] - Removing HKLM\…\Browser Helper Objects\{B8715432-3534-4711-A9D9-3CC63FB04B4B}
[09/16/2006, 8:51:36] - Removing HKCR\CLSID\{B8715432-3534-4711-A9D9-3CC63FB04B4B}
[09/16/2006, 8:51:36] - Adding Kill Bit for ActiveX for GUID: {B8715432-3534-4711-A9D9-3CC63FB04B4B}
[09/16/2006, 8:51:36] - Deleting ATLEvents/MSEvents Registry entries
[09/16/2006, 8:51:36] - Removing HKLM\…\Winlogon\Notify\yabbc
[09/16/2006, 8:51:36] - Searching for Browser Helper Objects:
[09/16/2006, 8:51:36] - BHO 1: {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} (PCTools Site Guard)
[09/16/2006, 8:51:36] - BHO 2: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[09/16/2006, 8:51:36] - BHO 3: {B56A7D7D-6927-48C8-A975-17DF180C71AC} (PCTools Browser Monitor)
[09/16/2006, 8:51:36] - Finished Searching Browser Helper Objects
[09/16/2006, 8:51:36] - Finishing up…
[09/16/2006, 8:51:36] - A restart is needed.
[09/16/2006, 8:51:36] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[09/16/2006, 8:51:59] - Attempting to Restart via STOP error (Blue Screen!)
———————————————————————————————————

————————————ewido————————————————
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 11:00:41 AM 9/16/2006

+ Scan result:



C:\!KillBox\yabbc.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\Program Files\Hijackthis\backups\backup-20060915-201120-525.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\Program Files\Hijackthis\backups\backup-20060915-201256-719.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\VundoFix Backups\yabbc.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\yabbc.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.41:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup (quarantined).
:mozilla.92:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.186:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.216:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.195:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.196:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.197:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.198:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.185:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.80:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.82:C:\Documents and Settings\Ajay Sharma\Application Data\Mozilla\Firefox\Profiles\2gn2os3b.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).


::Report end

—————————————-HJT—————————————–
Logfile of HijackThis v1.99.1
Scan saved at 8:14:37 PM, on 9/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Hijackthis\Analyser.exe

O2 - BHO: (no name) - {46B00B0B-32E2-4199-922F-AAE3601CFF89} - C:\WINDOWS\system32\yabbc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/downl…lscbase5059.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O20 - Winlogon Notify: yabbc - C:\WINDOWS\system32\yabbc.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe (file missing)

—————————————————————————————

What do you think after looking at these reports..? So far I did not get any message but I'm not sure if its gone…….what about winfixer and winantivirus ? do we need to take them saparetly or these are also gone?
Please suggest.
Thanks
Dyn…..
Vundobegone shows that it removed it but these two entries and still present


O2 - BHO: (no name) - {46B00B0B-32E2-4199-922F-AAE3601CFF89} - C:\WINDOWS\system32\yabbc.dll
O20 - Winlogon Notify: yabbc - C:\WINDOWS\system32\yabbc.dll



We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.




Boot into Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard


Open HJT Scan Only and remove both these entries.

O2 - BHO: (no name) - {46B00B0B-32E2-4199-922F-AAE3601CFF89} - C:\WINDOWS\system32\yabbc.dll
O20 - Winlogon Notify: yabbc - C:\WINDOWS\system32\yabbc.dll



Still in safemode, look for and delete this file

C:\WINDOWS\system32\yabbc.dll


Reboot and post a new HJT log please.
looks like yabbc.dll is no more… here is the hjt log


Logfile of HijackThis v1.99.1
Scan saved at 12:43:11 PM, on 9/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\Analyser.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/downl…lscbase5059.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe (file missing)

————————————————————————————
But spyware doctor still detect winantivirus infection in registry. can we take this now……?
Please suggest..
Thanks
Dynamic :D

Its gone , good job :thumbup:


Remove these two entries with HJT.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =



I would like you to run this other system cleaner that has a registry cleaner also.

If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
Download and Install CCleaner
* Click on Run Cleaner
* Run the Issues Scan < When it asks you to backup the Registry..Say Yes
Tutorial for CCleaner


Reboot and see if Spyware Doctor still picks it up. The infection is no more, you just have leftover entries in the registry. If its still there, we can run another registry cleaner.

Ken :D
Ken, Thanks for your help…. virtumonde is gone but winfixer and winantivirus are still there and spyware doctor detect 24 infecting in registry files…. but not able to remove that.. i tried in safe and nomal mode both..but no use….I'm still worried about this infectation as others ccome after this only…. here is the log from spyware doctor…….not that clear (its messy), but you can have idea what are the registry files it detects. I tried to clean these manuall through 'regedit' but not able to delete or modify them…it recovers itself……please have a glance and let me know how can I get rid of this crab… ————————————————————————————————- 9/16/2006 9:28:51 PM 20060916212851 9/16/2006 9:31:57 PM 9/15/2006 1:01:40 AM WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF## Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF##NextInstance Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000 Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000## Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000##Capabilities Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000##Class Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000##ClassGUID Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000##ConfigFlags Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000##DeviceDesc Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000##Legacy Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000##Service Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK## Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK##NextInstance Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000 Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000## Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000##Capabilities Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000##Class Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000##ClassGUID Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000##ConfigFlags Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000##DeviceDesc Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000##Legacy Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll WinAntiVirus Registry HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000##Service Elevated WinAntiVirus is a rogue anti-virus program from WinSoftware which has been known to be downloaded by some trojans. It claims to remove virus infections but instead shows detections of legitimate keys and files to urge users to buy its application. Removal of this software is advisable if it is not installed for a purpose. regscanner.dll 9/16/2006 9:34:49 PM 36762 24 0 General Scanner, Process Scanner, LSP Scanner, Startup Scanner, Registry Scanner, Hosts Scanner, Browser Scanner, Browser Activity Scanner, Disk Scanner, ActiveX Scanner Scan Results: scan start: scan stop: scanned items: found items: found and ignored: tools used: Infection Name Location Risk Removed / Quarantined Infections: Removed Infection Related To Removed Quarantined Scan Results: scan start: scan stop: scanned items: found items: found and ignored: tools used: Infection Name Location Risk Risk Removed / Quarantined Infections: Removed Infection Related To Removed Quarantined 9/16/2006 9:28:51 PM - Spyware Doctor started 9/16/2006 9:29:41 PM - Init OK. 9/16/2006 9:29:50 PM - Init OK. 9/16/2006 9:29:56 PM - Init OK. 4.0.0.2602 3.05590 9/15/2006 70834 9/16/2006 55 ON Startup Guard, Exploit Guard, Browser Guard, Immunizer, Keylogger Guard, Network Guard, Popup Blocker, Process Guard, Scheduler, Site Guard Ajay Sharma C:\Program Files\Spyware Doctor\ English No Yes Yes No Yes 20 Yes no action No No No Value Data ————————————————————————————– thanks Dyanamic
Here we go….. AC3Filter (remove only) Ad-Aware SE Personal Adobe Flash Player 9 ActiveX Adobe Reader 7.0.8 Adobe SVG Viewer 3.0 Adobe® Photoshop® Album Starter Edition 3.0 Advanced RAR Password Recovery (remove only) Advanced System Optimizer (Shareware Release) Advanced ZIP Password Recovery (remove only) Alarm Master Plus v 4.13 ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver Belarc Advisor 7.1 Bluetooth by hp Broadcom 802.11 Wireless LAN Adapter burnatonce ccCommon CCleaner (remove only) Creative WebCam Center Creative WebCam Instant Driver (1.01.02.0729) DivX DivX Converter DivX Player DivX Web Player Dr Watson for Microsoft Windows OneCare Live v1.0.0971.20 ewido anti-spyware 4.0 Globe7 Google Earth Google Talk (remove only) Google Toolbar for Firefox HighMAT Extension to Microsoft Windows XP CD Writing Wizard Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows XP (KB915865) HP Deskjet Preloaded Printer Drivers HP Help and Support HP Photosmart Cameras 4.5 HP Software Update InterActual Player Internet Worm Protection InterVideo WinDVD InterVideo WinDVD Creator 2 I-ON Video CD Player 1.01 j2 Messenger J2SE Runtime Environment 5.0 Update 1 J2SE Runtime Environment 5.0 Update 2 J2SE Runtime Environment 5.0 Update 4 J2SE Runtime Environment 5.0 Update 6 Java 2 Runtime Environment, SE v1.4.2_03 Java 2 Runtime Environment, SE v1.4.2_06 KRyLack Password Recovery 2.11 LiveUpdate 3.0 (Symantec Corporation) Living Marine Aquarium 2 Screen Saver Living Marine Aquarium 2.0 Animated Wallpaper Memories Disc Creator 2.0 MetaFrame Presentation Server Web Client for Win32 Microsoft .NET Framework 2.0 Microsoft Office FrontPage 2003 Microsoft Office Professional Edition 2003 Microsoft Office Standard Edition 2003 Microsoft Speech Recognition Engine 4.0 (English) Microsoft Windows Journal Viewer Microsoft Works 7.0 Mozilla Firefox (1.5.0.7) MSN Messenger 6.2 Musicmatch® Jukebox Need for Speed Underground 2 Norton AntiVirus 2006 Norton AntiVirus 2006 (Symantec Corporation) Norton AntiVirus Help Norton AntiVirus Parent MSI Norton AntiVirus SYMLT MSI Norton Protection Center Norton WMI Update Photosmart 140,240,7200,7600,7700,7900 Series PowerISO RAR Password Recovery v1.1 RC16 (remove only) RealArcade RealPlayer REALTEK Gigabit and Fast Ethernet NIC Driver Realtek RTL8139/810x Fast Ethernet NIC Driver Setup RecordNow! SAP Front End Security Task Manager 1.6f Security Update for Microsoft .NET Framework 2.0 (KB917283) Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Skype 1.4 Sonic Update Manager SoundMAX SPBBC Spyware Doctor 4.0 SpywareBot [removed] Symantec Synaptics Pointing Device Driver System Cleaner 5 Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB914882) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Vbuzzer – Voip Your World VideoLAN VLC media player 0.8.1 Viewpoint Media Player VoipCheapCom Winamp (remove only) Windows Defender Signatures Windows Genuine Advantage v1.3.0254.0 Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Live Safety Scanner Windows Media Format Runtime Windows Media Player 10 Windows Media Player 10 Hotfix - KB895316 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinRAR archiver WinZip WordWeb Yahoo! Messenger ————————————————————————————– Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI