This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

1st HJT Log

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all … The common files entry (update.exe) has been removed, …just looking for someone's keen eye to root out anything else suspicious. TIA. Logfile of HijackThis v1.99.1 Scan saved at 10:57:43 PM, on 10/8/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Common Files\{088ACD4D-07D0-1033-1213-020308050001}\Update.exe F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe F:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\Program Files\Plextor\PlexTool.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\CTsvcCDA.exe F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Windows Media Player\wmplayer.exe F:\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" O4 - HKLM\..\Run: [rubvbtl.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rubvbtl.dll,aiqhgkd O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [Yahoo! Pager] "F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O4 - HKCU\..\Run: [Creative Detector] "F:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - Startup: Yahoo! Widget Engine.lnk = F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe O4 - Global Startup: PlexTools Professional.lnk = C:\Program Files\Plextor\PlexTool.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{1A753C59-47C5-4A3C-8D0B-69D864199001}: NameServer = 68.94.156.1 68.94.157.1 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Welcome to the forum.

It's still showing in your log:
C:\Program Files\Common Files\{088ACD4D-07D0-1033-1213-020308050001}\Update.exe

————————-

1. Download combofix.exe from one of the links below:

http://download.bleepingcomputer.com/sUBs/combofix.exe
http://www.techsupportforum.com/sectools/combofix.exe

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

——————–

Then………..

Please download and install the trial version of Ewido Security Suite 4.0 here:
http://www.grisoft.cz/softw/70/filedir/ins…_4.0.0.172a.exe

After it's installed…Check for updates:
Double click on the Ewido icon in the system tray or on the desktop> this will bring up the main program if it's not already up.

On the Main Page click the Update Tab and then Start Update.
Download and install any updates if available.

Select the Scanner icon at the top of the screen, then select the Settings tab.
Once in the Settings screen click on Recommended actions and then select Quarantine.
Under Reports
Select Automatically generate report after every scan
Un-Select Only if threats were found

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:
  • Temporary Files
  • Temporary Internet Files
  • Recycle Bin

Now click the Scanner Icon on top
Click on Complete System Scan
Be patient - it takes a while to run.

Once the scan is complete do the following:
If you have any infections you will prompted, then select Apply All Actions

Next select the Reports icon at the top.
Copy and paste the scan report in your next reply.
Close Ewido

Reboot and post a fresh HJT log, the ComboFix log and the log from Ewido, MrC
Hi Mr.C

..thanks for taking a look. I tried grabbing the combofix.exe, but I'm getting a 404 error, …I did a quick google and couldn't find anything other than the original link —- any other mirrored sites for that?

Also: AVG scanned this morning and found this:

http://img170.imageshack.us/img170/1259/avgssrq0.jpg

It's in the vault, … not sure what to do with it, … I'll just let it sit for now.

One other thing: …how the hell do I stop these ridiculous pop-ups from WinAntiVirus Pro ? …and the other spysoft pop-ups …seem to be taking over lately … ??

thx.

I'll wait to hear from you and I'll keep checking the link to see if the page is back up.
Yes I knew about them - that's why I wanted you to run Ewido.

Please right click on HiJackThis.exe and rename it to abc.exe, now rescan the system (double click on abc.exe) and post that log.
Some malware plays with HiJackThis.exe so it doesn't show the malware.

MrC
Logfile of HijackThis v1.99.1
Scan saved at 10:24:09 PM, on 10/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\Grisoft\AVG Free\avgcc.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\ivox\Desktop\downloads\hijackthis\c1B2A3.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {603B02A5-14E1-4F69-90B6-D8DF246263BB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A2BE9670-2030-4EFE-8157-AC88356E4C3F} - (no file)
O2 - BHO: (no name) - {BB8688E2-7621-4DF9-95CA-771B45AD2125} - (no file)
O2 - BHO: (no name) - {F6023C39-A34B-4503-9CD7-CFC28E061D60} - C:\WINDOWS\system32\awtst.dll
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\RunServices: [RunAlert] C:\Program Files\MSI\PC Alert III\AService.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: PC Alert III.lnk = C:\Program Files\MSI\PC Alert III\alert.exe
O4 - Global Startup: VCenter.lnk = C:\Program Files\MSI\VCenter\VCenter.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1160379832637
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A753C59-47C5-4A3C-8D0B-69D864199001}: NameServer = 68.94.156.1 68.94.157.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awtst - C:\WINDOWS\system32\awtst.dll
O20 - Winlogon Notify: winzzc32 - winzzc32.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 11:31:11 PM 10/10/2006 + Scan result: C:\Program Files\Common Files\{088ACD4D-07D0-1033-1213-020308050001}\{088ACD4D-07D0-1033-1213-020308050001}\Update.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\Program Files\Common Files\{088ACD4D-07D0-1033-1213-020308050001}\{088ACD4D-07D0-1033-1213-020308050001}\services.dll -> Adware.Softomate : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1078081533-1604221776-839522115-1003\Dc27.zip/{088ACD4D-07D0-1033-1213-020308050001}/Update.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1078081533-1604221776-839522115-1003\Dc27.zip/{088ACD4D-07D0-1033-1213-020308050001}/services.dll -> Adware.Softomate : Cleaned with backup (quarantined). :mozilla.26:C:\Documents and Settings\ivox\Application Data\Mozilla\Firefox\Profiles\bn6fobjd.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.25:C:\Documents and Settings\ivox\Application Data\Mozilla\Firefox\Profiles\bn6fobjd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined). :mozilla.27:C:\Documents and Settings\ivox\Application Data\Mozilla\Firefox\Profiles\bn6fobjd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined). :mozilla.28:C:\Documents and Settings\ivox\Application Data\Mozilla\Firefox\Profiles\bn6fobjd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined). :mozilla.29:C:\Documents and Settings\ivox\Application Data\Mozilla\Firefox\Profiles\bn6fobjd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined). :mozilla.12:C:\Documents and Settings\ivox\Application Data\Mozilla\Firefox\Profiles\bn6fobjd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.13:C:\Documents and Settings\ivox\Application Data\Mozilla\Firefox\Profiles\bn6fobjd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.14:C:\Documents and Settings\ivox\Application Data\Mozilla\Firefox\Profiles\bn6fobjd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.15:C:\Documents and Settings\ivox\Application Data\Mozilla\Firefox\Profiles\bn6fobjd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). ::Report end ________________________________ Awaiting instruction … ;)
ComboFix is back up - please download and run it and post the log it creates as well as a fresh HJT log.


Question: If ewido finds an embedded file in a .zip, … is it cool to just quarrantine the whole .zip folder?


Yes - I would, MrC
ivox - 06-10-11 21:06:59.54 Service Pack 2 ComboFix 06.10.11 - Running from: "C:\Documents and Settings\ivox\Desktop\downloads" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\regsvr32.dll C:\Program Files\Common Files\{088ACD4D-07D0-1033-1213-020308050001} ((((((((((((((((((((((((((((((( Files Created from 2006-09-11 to 2006-10-11 )))))))))))))))))))))))))))))))))) 2006-10-11 04:07 143,380 –a—— C:\WINDOWS\system32\nfgsorqu.exe 2006-10-09 18:17 127,208 –a—— C:\WINDOWS\system32\mucltui.dll 2006-10-09 03:54 143,380 –a—— C:\WINDOWS\system32\olptikwk.exe 2006-10-09 03:53 532,683 —hs—- C:\WINDOWS\system32\tstwa.bak2 2006-10-07 17:09 143,380 –a—— C:\WINDOWS\system32\nebkeypw.exe 2006-10-07 17:08 684,084 —hs—- C:\WINDOWS\system32\awtst.dll 2006-10-07 17:08 531,048 —hs—- C:\WINDOWS\system32\tstwa.bak1 2006-10-07 17:02 94,208 –a—— C:\WINDOWS\system32\rubvbtl.dll 2006-10-07 17:02 72,704 –a—— C:\WINDOWS\system32\wokblkc.dll 2006-10-07 17:02 40,973 —hs—- C:\WINDOWS\system32\ddcaxuu.dll 2006-10-07 15:04 1,744,896 –a—— C:\WINDOWS\Water_Illusion.scr 2006-10-07 15:02 906,637 C:\WINDOWSAce Pro Screensaver Creator Uninstaller.exe 2006-10-07 13:24 102,400 –a—— C:\WINDOWS\system32\tsccvid.dll 2006-09-21 01:30 44,032 ——— C:\WINDOWS\system32\CTSVCCDA.EXE 2006-09-21 01:30 25,088 ——— C:\WINDOWS\system32\CTSVCCTL.EXE 2006-09-20 00:12 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys 2006-09-20 00:12 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys 2006-09-20 00:12 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys 2006-09-20 00:05 96,768 –a—— C:\WINDOWS\SlantAdj.dll 2006-09-20 00:05 73,216 –a—— C:\WINDOWS\ADE.DLL 2006-09-20 00:01 131,072 –a—— C:\WINDOWS\system32\Epcmlib.dll 2006-09-20 00:00 98,304 –a—— C:\WINDOWS\system32\E_SAGSET.DLL 2006-09-20 00:00 79,622 –a—— C:\WINDOWS\system32\EBPMON24.DLL 2006-09-20 00:00 64,000 –a—— C:\WINDOWS\system32\ECBTEG.DLL 2006-09-20 00:00 34,304 –a—— C:\WINDOWS\system32\EBPCHP.DLL 2006-09-19 23:59 46,080 –a—— C:\WINDOWS\system32\escimgd.dll 2006-09-19 23:59 29,696 –a—— C:\WINDOWS\system32\escwiad.dll 2006-09-19 23:59 22,528 –a—— C:\WINDOWS\system32\esccmd.dll 2006-09-11 09:37 476,320 ——— C:\WINDOWS\system32\ImagXpr7.dll 2006-09-11 09:37 471,040 ——— C:\WINDOWS\system32\ImagXRA7.dll 2006-09-11 09:37 262,144 ——— C:\WINDOWS\system32\ImagXR7.dll 2006-09-11 09:37 106,496 –a—— C:\WINDOWS\system32\TwnLib20.dll 2006-09-11 09:37 1,568,768 ——— C:\WINDOWS\system32\ImagX7.dll (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-10-11 21:07 ——– d——– C:\Program Files\Mozilla Firefox 2006-10-11 21:07 ——– d——– C:\Program Files\Common Files 2006-10-11 04:07 ——– d——– C:\Program Files\RegScrubXP 2006-10-11 03:47 ——– d——– C:\Program Files\MSI 2006-10-09 03:11 ——– d——– C:\Program Files\Common Files\Microsoft Shared 2006-10-09 03:06 ——– d——– C:\Program Files\OfficeUpdate11 2006-10-08 17:40 ——– d——– C:\Documents and Settings\ivox\Application Data\Lavasoft 2006-10-08 11:11 ——– d——– C:\Program Files\Internet Explorer 2006-10-08 11:06 ——– d——– C:\Program Files\Windows Media Player 2006-10-08 11:06 ——– d——– C:\Program Files\Outlook Express 2006-10-08 11:06 ——– d——– C:\Program Files\Common Files\System 2006-10-08 11:00 ——– d——– C:\Program Files\Messenger 2006-10-07 15:04 ——– d——– C:\Program Files\Nufsoft 2006-10-07 15:02 906637 –a—— C:\WINDOWS\Ace Pro Screensaver Creator Uninstaller.exe 2006-10-06 11:13 ——– d——– C:\Program Files\Next Limit 2006-10-04 23:25 ——– d——– C:\Documents and Settings\ivox\Application Data\SecondLife 2006-10-04 16:05 ——– d——– C:\Documents and Settings\ivox\Application Data\Skype 2006-10-04 15:48 ——– d—s—- C:\Documents and Settings\ivox\Application Data\Microsoft 2006-10-04 15:47 ——– d——– C:\Program Files\MSN Messenger 2006-09-28 14:25 ——– d——– C:\Documents and Settings\ivox\Application Data\Creative 2006-09-28 08:21 778656 –a—— C:\WINDOWS\system32\drivers\avg7core.sys 2006-09-28 06:32 ——– d——– C:\Program Files\File Scavenger 3.0 2006-09-21 01:34 ——– d——– C:\Program Files\Creative 2006-09-20 02:32 ——– d–h—– C:\Program Files\InstallShield Installation Information 2006-09-20 02:30 ——– d——– C:\Program Files\EPSON 2006-09-20 01:31 ——– d——– C:\Documents and Settings\ivox\Application Data\Smart Panel 2006-09-20 01:27 ——– d——– C:\Program Files\Hasbro Interactive 2006-09-20 00:10 ——– d——– C:\Documents and Settings\ivox\Application Data\Leadertech 2006-09-20 00:08 ——– d——– C:\Program Files\ABBYY FineReader 5.0 Sprint 2006-09-20 00:07 ——– d——– C:\Program Files\Smart Panel 2006-09-16 02:47 ——– d——– C:\Program Files\Skype 2006-09-15 23:27 ——– d——– C:\Program Files\ACW 2006-09-15 11:10 ——– d——– C:\Program Files\Audible 2006-09-13 15:10 ——– d——– C:\Program Files\QuickTime 2006-09-13 01:06 ——– d——– C:\Documents and Settings\ivox\Application Data\McNeel 2006-09-13 01:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll 2006-09-11 09:37 ——– d——– C:\Program Files\Common Files\Ahead 2006-09-11 09:37 ——– d——– C:\Program Files\Ahead 2006-09-11 09:36 ——– d——– C:\Program Files\CyberLink 2006-09-11 08:48 ——– d——– C:\Program Files\Executive Software 2006-09-11 06:12 ——– d——– C:\Program Files\Microsoft ActiveSync 2006-09-11 06:12 ——– d——– C:\Program Files\Common Files\Designer 2006-09-11 05:20 ——– d——– C:\Program Files\Common Files\Adobe 2006-09-11 05:17 873 –a—— C:\Documents and Settings\ivox\Application Data\AdobeDLM.log 2006-09-11 05:17 0 –a—— C:\Documents and Settings\ivox\Application Data\dm.ini 2006-09-10 08:23 ——– d——– C:\Program Files\Common Files\LightScribe 2006-09-10 07:49 ——– d——– C:\Program Files\Aladdin Systems 2006-09-10 07:42 ——– d——– C:\Program Files\Rhinoceros 3.0 2006-09-09 18:14 ——– d——– C:\Program Files\activePDF 2006-09-06 11:07 ——– d——– C:\Program Files\JDHill 2006-09-05 10:08 4992 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys 2006-09-05 10:08 4288 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys 2006-09-05 10:08 27904 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys 2006-09-05 10:08 23424 –a—— C:\WINDOWS\system32\drivers\avgmfrs.sys 2006-09-05 10:08 ——– d——– C:\Documents and Settings\ivox\Application Data\AVG7 2006-09-05 10:07 ——– d——– C:\Program Files\Grisoft 2006-09-04 12:22 ——– d——– C:\Documents and Settings\ivox\Application Data\Help 2006-09-04 12:21 ——– d——– C:\Program Files\Common Files\InstallShield 2006-09-04 11:56 ——– d——– C:\Documents and Settings\ivox\Application Data\AdobeUM 2006-09-04 11:55 ——– d——– C:\Documents and Settings\ivox\Application Data\Adobe 2006-09-04 11:53 ——– d——– C:\Program Files\Adobe 2006-09-04 11:41 ——– d——– C:\Program Files\Plextor 2006-09-03 22:35 ——– d——– C:\Program Files\Windows Media Connect 2 2006-09-03 14:34 ——– d——– C:\Documents and Settings\ivox\Application Data\Apple Computer 2006-09-02 22:45 ——– d——– C:\Program Files\Yahoo! 2006-09-02 20:45 ——– d–h—– C:\Program Files\WindowsUpdate 2006-09-02 18:29 ——– d——– C:\Program Files\Movie Maker 2006-09-02 18:28 ——– d——– C:\Program Files\Windows NT 2006-09-02 18:28 ——– d——– C:\Program Files\NetMeeting 2006-09-02 04:56 ——– d——– C:\Documents and Settings\ivox\Application Data\Macromedia 2006-09-02 04:47 ——– d——– C:\Documents and Settings\ivox\Application Data\Mozilla 2006-09-02 04:31 ——– d——– C:\Program Files\TuneXP 2006-09-02 04:30 720896 –a—— C:\WINDOWS\iun6002.exe 2006-09-02 04:28 ——– d——– C:\Program Files\Zone Labs 2006-08-31 12:46 176235 –a—— C:\WINDOWS\system32\Primomonnt.dll 2006-08-31 12:22 ——– d——– C:\Program Files\AMDAGP 2006-08-30 23:37 ——– d——– C:\Program Files\Common Files\McNeel Shared 2006-08-30 23:31 ——– d——– C:\Program Files\AMDEIDE 2006-08-30 23:29 ——– d——– C:\Program Files\AMD AC97 2006-08-30 23:27 ——– d——– C:\Program Files\VIA Technologies, Inc 2006-08-30 22:45 ——– d–h—– C:\Program Files\Uninstall Information 2006-08-30 22:45 ——– d——– C:\Documents and Settings\ivox\Application Data\Identities 2006-08-30 22:42 ——– d——– C:\Program Files\xerox 2006-08-30 22:42 ——– d——– C:\Program Files\microsoft frontpage 2006-08-30 22:39 0 -rahs—- C:\MSDOS.SYS 2006-08-30 22:39 0 -rahs—- C:\IO.SYS 2006-08-30 22:39 0 –a—— C:\CONFIG.SYS 2006-08-30 22:39 0 –a—— C:\AUTOEXEC.BAT 2006-08-30 22:37 ——– d——– C:\Program Files\Online Services 2006-08-30 22:37 ——– d——– C:\Program Files\MSN 2006-08-30 22:37 ——– d——– C:\Program Files\ComPlus Applications 2006-08-30 22:37 ——– d——– C:\Program Files\Common Files\Services 2006-08-30 22:37 ——– d——– C:\Program Files\Common Files\MSSoap 2006-08-30 22:36 ——– d——– C:\Program Files\MSN Gaming Zone 2006-08-30 18:32 62 –ahs—- C:\Documents and Settings\ivox\Application Data\desktop.ini 2006-08-30 18:32 ——– d——– C:\Program Files\Common Files\SpeechEngines 2006-08-30 18:32 ——– d——– C:\Program Files\Common Files\ODBC 2006-08-25 11:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll 2006-08-24 20:26 95288 ——— C:\WINDOWS\system32\WUDFCoinstaller.dll 2006-08-24 19:22 90112 ——— C:\WINDOWS\system32\drivers\WudfRd.sys 2006-08-24 19:19 316416 ——— C:\WINDOWS\system32\WUDFx.dll 2006-08-24 19:19 145920 ——— C:\WINDOWS\system32\WudfHost.exe 2006-08-24 19:18 84864 ——— C:\WINDOWS\system32\drivers\WudfPf.sys 2006-08-24 19:18 56320 ——— C:\WINDOWS\system32\WudfSvc.dll 2006-08-24 19:18 168448 ——— C:\WINDOWS\system32\WudfPlatform.dll 2006-08-21 08:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll 2006-08-21 05:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe 2006-08-21 05:14 128896 ——— C:\WINDOWS\system32\drivers\fltmgr.sys 2006-08-16 07:58 100352 –a—— C:\WINDOWS\system32\6to4svc.dll 2006-08-16 05:37 225664 –a—— C:\WINDOWS\system32\drivers\tcpip6.sys 2006-08-14 06:34 332928 –a—— C:\WINDOWS\system32\drivers\srv.sys 2006-07-29 19:32 48936 –a—— C:\WINDOWS\system32\sirenacm.dll 2006-07-27 09:24 679424 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-07-21 04:24 72704 –a—— C:\WINDOWS\system32\hlink.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="F:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe" "Yahoo! Pager"="\"F:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EPSON Stylus Photo RX500"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2K1.EXE /P24 \"EPSON Stylus Photo RX500\" /O6 \"USB001\" /M \"Stylus Photo RX500\"" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\"" "nwiz"="nwiz.exe /install" "DiskeeperSystray"="\"F:\\Program Files\\Diskeeper Corporation\\Diskeeper\\DkIcon.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,18,01,00,00,00,00,00,00,60,04,00,00,1a,04,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=hex:91,00,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup" "location"="Common Startup" "command"="F:\\PROGRA~1\\ADOBE7~1.0\\Reader\\READER~1.EXE " "item"="Adobe Reader Speed Launch" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk" "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup" "location"="Common Startup" "command"="F:\\PROGRA~1\\MICROS~1\\Office10\\OSA.EXE -b -l" "item"="Microsoft Office" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Creative Detector] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CTDetect" "hkey"="HKCU" "command"="\"C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe\" /R" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\InCD] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="InCD" "hkey"="HKLM" "command"="C:\\Program Files\\Ahead\\InCD\\InCD.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\LGODDFU] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="fwupdate" "hkey"="HKLM" "command"="\"C:\\Program Files\\lg_fwupdate\\fwupdate.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\LiveMonitor] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LMonitor" "hkey"="HKLM" "command"="C:\\Program Files\\MSI\\Live Update 3\\LMonitor.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NeroFilterCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroCheck" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\NeroCheck.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NvCplDaemon] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NvCpl" "hkey"="HKLM" "command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NvMediaCenter] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NvMcTray" "hkey"="HKLM" "command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\nwiz] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="nwiz" "hkey"="HKLM" "command"="nwiz.exe /install" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"F:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtst HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzzc32 HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll Completion time: Wed 10/11/2006 21:08:57.71 ComboFix.txt ____________________________________________________ Logfile of HijackThis v1.99.1 Scan saved at 11:15:08 PM, on 10/11/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\MSI\PC Alert III\alert.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\CTsvcCDA.exe F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe C:\Program Files\Grisoft\AVG Free\avgcc.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\ivox\Desktop\downloads\hijackthis\c1B2A3.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {603B02A5-14E1-4F69-90B6-D8DF246263BB} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {972EB586-826D-4908-BFB2-741335FF02E0} - C:\WINDOWS\system32\awtst.dll O2 - BHO: (no name) - {A2BE9670-2030-4EFE-8157-AC88356E4C3F} - (no file) O2 - BHO: (no name) - {BB8688E2-7621-4DF9-95CA-771B45AD2125} - (no file) O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [Yahoo! Pager] "F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O4 - Global Startup: PC Alert III.lnk = C:\Program Files\MSI\PC Alert III\alert.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - O17 - HKLM\System\CCS\Services\Tcpip\..\{1A753C59-47C5-4A3C-8D0B-69D864199001}: NameServer = 68.94.156.1 68.94.157.1 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: awtst - C:\WINDOWS\system32\awtst.dll O20 - Winlogon Notify: winzzc32 - winzzc32.dll (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - F:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A753C59-47C5-4A3C-8D0B-69D864199001}: NameServer = 68.94.156.1 68.94.157.1
This entry is from:
DALLAS, TEXAS USA, DNS ANYCAST ADDRESSING POOL
Does this sound familiar to you?

———————-

Please do this for me……

Download VirtumundoBeGone

Save it to your Desktop

Close all running programs (including your Internet Browser)

Double-click VirtumundoBeGone.exe on the desktop and follow the instructions. Do not worry if you see a BLUE SCREEN "Fatal Error" Message, this is normal and expected.

When it has finished, reboot.

VirtumundoBeGone generates a "log" file of its own, which it should have placed on your Desktop called VBG.TXT… please copy/paste the VirtumundoBeGone log back here together with a new hijackthis log. MrC
Okay Mr. C,

Saturday morning. This is what I've done, …

Updated definitions: spybot S&D : scanned : nothing

Updated definitions: ewido : scanned : 1 tracking cookie : removed.

Updated definitions: spyware blaster

Updated definitions: AVG : scanned : nothing

Ran VBG.exe here's the report.



[10/14/2006, 10:43:03] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\ivox\Desktop\VirtumundoBeGone.exe" )
[10/14/2006, 10:43:11] - Detected System Information:
[10/14/2006, 10:43:11] - Windows Version: 5.1.2600, Service Pack 2
[10/14/2006, 10:43:11] - Current Username: ivox (Admin)
[10/14/2006, 10:43:11] - Windows is in NORMAL mode.
[10/14/2006, 10:43:11] - Searching for Browser Helper Objects:
[10/14/2006, 10:43:11] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/14/2006, 10:43:11] - BHO 2: {0EB66F05-F449-43C8-BBF3-67B056C79255} ()
[10/14/2006, 10:43:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/14/2006, 10:43:11] - Checking for HKLM\…\Winlogon\Notify\awtst
[10/14/2006, 10:43:11] - Found: HKLM\…\Winlogon\Notify\awtst - This is probably Virtumundo.
[10/14/2006, 10:43:11] - Assigning {0EB66F05-F449-43C8-BBF3-67B056C79255} MSEvents Object
[10/14/2006, 10:43:11] - BHO list has been changed! Starting over…
[10/14/2006, 10:43:11] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/14/2006, 10:43:11] - BHO 2: {0EB66F05-F449-43C8-BBF3-67B056C79255} (MSEvents Object)
[10/14/2006, 10:43:11] - ALERT: Found MSEvents Object!
[10/14/2006, 10:43:11] - BHO 3: {603B02A5-14E1-4F69-90B6-D8DF246263BB} ()
[10/14/2006, 10:43:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/14/2006, 10:43:11] - No filename found. Continuing.
[10/14/2006, 10:43:11] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[10/14/2006, 10:43:11] - BHO 5: {A2BE9670-2030-4EFE-8157-AC88356E4C3F} ()
[10/14/2006, 10:43:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/14/2006, 10:43:11] - No filename found. Continuing.
[10/14/2006, 10:43:11] - BHO 6: {BB8688E2-7621-4DF9-95CA-771B45AD2125} ()
[10/14/2006, 10:43:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/14/2006, 10:43:11] - No filename found. Continuing.
[10/14/2006, 10:43:11] - Finished Searching Browser Helper Objects
[10/14/2006, 10:43:11] - *** Detected MSEvents Object
[10/14/2006, 10:43:11] - Trying to remove MSEvents Object…
[10/14/2006, 10:43:12] - Terminating Process: IEXPLORE.EXE
[10/14/2006, 10:43:12] - Terminating Process: RUNDLL32.EXE
[10/14/2006, 10:43:12] - Disabling Automatic Shell Restart
[10/14/2006, 10:43:12] - Terminating Process: EXPLORER.EXE
[10/14/2006, 10:43:12] - Suspending the NT Session Manager System Service
[10/14/2006, 10:43:13] - Terminating Windows NT Logon/Logoff Manager
[10/14/2006, 10:43:13] - Re-enabling Automatic Shell Restart
[10/14/2006, 10:43:13] - File to disable: C:\WINDOWS\system32\awtst.dll
[10/14/2006, 10:43:13] - Renaming C:\WINDOWS\system32\awtst.dll -> C:\WINDOWS\system32\awtst.dll.vir
[10/14/2006, 10:43:13] - File successfully renamed!
[10/14/2006, 10:43:13] - Removing HKLM\…\Browser Helper Objects\{0EB66F05-F449-43C8-BBF3-67B056C79255}
[10/14/2006, 10:43:13] - Removing HKCR\CLSID\{0EB66F05-F449-43C8-BBF3-67B056C79255}
[10/14/2006, 10:43:13] - Adding Kill Bit for ActiveX for GUID: {0EB66F05-F449-43C8-BBF3-67B056C79255}
[10/14/2006, 10:43:13] - Deleting ATLEvents/MSEvents Registry entries
[10/14/2006, 10:43:13] - Removing HKLM\…\Winlogon\Notify\awtst
[10/14/2006, 10:43:13] - Searching for Browser Helper Objects:
[10/14/2006, 10:43:13] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/14/2006, 10:43:13] - BHO 2: {603B02A5-14E1-4F69-90B6-D8DF246263BB} ()
[10/14/2006, 10:43:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/14/2006, 10:43:13] - No filename found. Continuing.
[10/14/2006, 10:43:13] - BHO 3: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[10/14/2006, 10:43:13] - BHO 4: {A2BE9670-2030-4EFE-8157-AC88356E4C3F} ()
[10/14/2006, 10:43:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/14/2006, 10:43:13] - No filename found. Continuing.
[10/14/2006, 10:43:13] - BHO 5: {BB8688E2-7621-4DF9-95CA-771B45AD2125} ()
[10/14/2006, 10:43:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/14/2006, 10:43:13] - No filename found. Continuing.
[10/14/2006, 10:43:13] - Finished Searching Browser Helper Objects
[10/14/2006, 10:43:13] - Finishing up…
[10/14/2006, 10:43:13] - A restart is needed.
[10/14/2006, 10:43:13] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[10/14/2006, 10:43:29] - Attempting to Restart via STOP error (Blue Screen!)

Ran a new HJT report:

Logfile of HijackThis v1.99.1
Scan saved at 10:53:24 AM, on 10/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Defender\MSASCui.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\ivox\Desktop\TheCleaner\hijackthis\f_virus.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {603B02A5-14E1-4F69-90B6-D8DF246263BB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A2BE9670-2030-4EFE-8157-AC88356E4C3F} - (no file)
O2 - BHO: (no name) - {BB8688E2-7621-4DF9-95CA-771B45AD2125} - (no file)
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [PowerBar] "F:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - Global Startup: PC Alert III.lnk = C:\Program Files\MSI\PC Alert III\alert.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A753C59-47C5-4A3C-8D0B-69D864199001}: NameServer = 68.94.156.1 68.94.157.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awtst - C:\WINDOWS\
O20 - Winlogon Notify: winzzc32 - winzzc32.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - F:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Well Done .

Please disable TeaTimer by opening Spybot SD and on the left menu choose Tools and then Resident. In the right hand pane you will see a check box for TeaTimer and for SDHelper . Please uncheck both boxes and then close Spybot. You can reinstate it later but we don't want it interfering with what we need to do. Reboot when done

—————————-

Close ALL programs down, leaving ONLY HijackThis running - Click Scan and…..
Place a check against the following items:

O2 - BHO: (no name) - {603B02A5-14E1-4F69-90B6-D8DF246263BB} - (no file)
O2 - BHO: (no name) - {A2BE9670-2030-4EFE-8157-AC88356E4C3F} - (no file)
O2 - BHO: (no name) - {BB8688E2-7621-4DF9-95CA-771B45AD2125} - (no file)
O20 - Winlogon Notify: awtst - C:\WINDOWS\
O20 - Winlogon Notify: winzzc32 - winzzc32.dll (file missing)

Click on Fix Checked and exit HijackThis.

—————————-

ComboFix found some files that we need to delete:

Download and unzip the KillBox to a folder.

Now…
Open up the KillBox
Select the option "Delete on reboot".
Click the button: All Files <—important
Now it should flash green

Now copy the next part in blue: (hightlight them > right click and choose copy)

C:\WINDOWS\system32\nfgsorqu.exe
C:\WINDOWS\system32\olptikwk.exe
C:\WINDOWS\system32\tstwa.bak2
C:\WINDOWS\system32\nebkeypw.exe
C:\WINDOWS\system32\awtst.dll
C:\WINDOWS\system32\tstwa.bak1
C:\WINDOWS\system32\rubvbtl.dll
C:\WINDOWS\system32\wokblkc.dll
C:\WINDOWS\system32\ddcaxuu.dll



Open 'file' in the KillBox menu on top and choose Paste from clipboard

Then press the button that looks like a red circle with a white X in it.
Killbox will tell you that all listed files will be removed on next reboot and asks if you would like to Reboot now, click YES
If you don't get that message, reboot manually.

Your computer must reboot now.


Reboot and post a fresh HijackThis log and we'll take another look.

Please let me know how it's running, MrC
I'll be damned !

I just received an email from a well known associate and it had a zip with a password attached.

I didn't check the full email header …. like a complete idiot ,… I began the extraction process.

AVG nailed it right away …. file vaulted / deleted/ healed …etc.

Screen shot: http://img115.imageshack.us/img115/8035/screennf6.jpg

Doing a new scan now … After that … I'm gonna follow the latest instructions and we'll go from there.


btw: thx much for time …. you know I appreciate it. ;)
The system appears to be running fine with no noticeable delays of 'hiccups'. I followed the instructions to the letter and here's the new HJT log as of a few moments ago. ________________________________________________________ Logfile of HijackThis v1.99.1 Scan saved at 10:02:46 AM, on 10/15/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\CTsvcCDA.exe F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe F:\Program Files\ewido anti-spyware 4.0\guard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Documents and Settings\ivox\Desktop\TheCleaner\hijackthis\f_virus.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [Yahoo! Pager] "F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O4 - HKCU\..\Run: [PowerBar] "F:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime O4 - Global Startup: PC Alert III.lnk = C:\Program Files\MSI\PC Alert III\alert.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - O17 - HKLM\System\CCS\Services\Tcpip\..\{1A753C59-47C5-4A3C-8D0B-69D864199001}: NameServer = 68.94.156.1 68.94.157.1 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - F:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI