This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Keep getting redirected in IE

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Below is my log after running Ad-aware, Spybot and Ewido and rebooting. Please let me know if there is anything to fix. I run these programs but problems keep coming back.

thanks

Logfile of HijackThis v1.99.1
Scan saved at 2:10:35 PM, on 1/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Administrator.OFFICE\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=552…cid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ynoombos.dll",setvm
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\Belkin\11Mbps Wireless Network\Config.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webtrain.com/cabinet/WT0804.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1104344382359
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/w…tWebInstall.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe" /service (file missing)
Hi hokiebay, Welcome to TomCoyote Forums !!

You may wish to print out a copy of these instructions to follow while you complete this procedure

We need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
Open Windows Defender.
Click on Tools, General Settings
Scroll down and uncheck Turn on real-time protection (recommended).
After you uncheck this, click on the Save button and close Windows Defender
After all of the fixes are complete, it is very important that you enable Real-time Protection again

I need you to download some programs to aide in our fix :Do Not Run Them Yet

Download VundoFix.exe© by Atribune to your desktop.

Download ATF (Atribune Temp File) Cleaner© by Atribune

Run ATF Cleaner
Double-click ATF Cleaner.exe
Under Main choose: Select All
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Run VundoFix
Double-click VundoFix.exe
Click the Scan for Vundo button.
When it finishes scanning,
Right Click inside the listbox (white box) and click add more files
Copy&Paste the following files in the 2 boxes :

BOX 1 : C:\WINDOWS\system32\ynoombos.dll
BOX 2 : C:\WINDOWS\SYSTEM32\sobmoony.ini

Click Add Files and Click Close Window
The files will be added to the Scan results list
Click the Remove Vundo button
You will receive a prompt asking if you want to "remove the files", click YES
Once you click yes, your desktop will go blank as it starts removing Vundo
When completed, it will prompt that it will reboot your computer, click OK
The .txt file will be in C:\Vundofix.txt

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot

Post a fresh HijackThis log and the vundofix.txt file here
Linkmaster, Thanks for your help. Here is the HJT logfile and the vundo file.

Hokiebay

Logfile of HijackThis v1.99.1
Scan saved at 11:15:30 PM, on 1/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\Program Files\Creative\ShareDLL\Mediadet.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\Program Files\StorageSync\StrgSync.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\Program Files\TiVo\Desktop\TiVoServer.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\MotiveBrowser\MotiveBrowser.exe
C:\Documents and Settings\hank\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=552…cid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\brajmeut.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\kowhjsbh.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {98FC8664-E208-4AF1-B622-8229EC5F3F12} - C:\WINDOWS\system32\frrlyikl.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: SDWin32 Class - {E3A36A4E-8035-4AA1-B026-805100233657} - C:\WINDOWS\System32\dlmkk.dll (file missing)
O2 - BHO: (no name) - {FE034B90-BF6B-4161-A4D6-CF752E0F76E3} - C:\WINDOWS\ServicePackFiles\idsksvs.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ynoombos.dll",setvm
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry /auto:TivoServer
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\Belkin\11Mbps Wireless Network\Config.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webtrain.com/cabinet/WT0804.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1104344382359
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/w…tWebInstall.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe" /service (file missing)

VUNDO File

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 7:19:32 PM 1/2/2007

Listing files found while scanning….

C:\WINDOWS\SYSTEM32\alrrlnmr.dll
C:\WINDOWS\SYSTEM32\atfffpgd.dll
C:\WINDOWS\SYSTEM32\mbiyxvfj.dll
C:\WINDOWS\SYSTEM32\mkadvgek.dll
C:\WINDOWS\ServicePackFiles\idsksvs.dll
C:\WINDOWS\ServicePackFiles\svsksdi.ini
C:\WINDOWS\ServicePackFiles\svsksdi.bak1
C:\WINDOWS\ServicePackFiles\svsksdi.bak2
C:\WINDOWS\ServicePackFiles\svsksdi.ini2
C:\WINDOWS\ServicePackFiles\svsksdi.tmp

Beginning removal…

Attempting to delete C:\WINDOWS\SYSTEM32\alrrlnmr.dll
C:\WINDOWS\SYSTEM32\alrrlnmr.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\atfffpgd.dll
C:\WINDOWS\SYSTEM32\atfffpgd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mbiyxvfj.dll
C:\WINDOWS\SYSTEM32\mbiyxvfj.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mkadvgek.dll
C:\WINDOWS\SYSTEM32\mkadvgek.dll Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\idsksvs.dll
C:\WINDOWS\ServicePackFiles\idsksvs.dll Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.ini
C:\WINDOWS\ServicePackFiles\svsksdi.ini Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.bak1
C:\WINDOWS\ServicePackFiles\svsksdi.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.bak2
C:\WINDOWS\ServicePackFiles\svsksdi.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.ini2
C:\WINDOWS\ServicePackFiles\svsksdi.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.tmp
C:\WINDOWS\ServicePackFiles\svsksdi.tmp Has been deleted!

Attempting to delete C:\\windows\system32\ynoombos.dll
C:\\windows\system32\ynoombos.dll Has been deleted!

Attempting to delete C:\\windows\system32\sobmoony.ini
C:\\windows\system32\sobmoony.ini Has been deleted!

Performing Repairs to the registry.
Done!
I need you to do the following :
(this will take a bit to finish)

We need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
Open Windows Defender.
Click on Tools, General Settings
Scroll down and uncheck Turn on real-time protection (recommended).
After you uncheck this, click on the Save button and close Windows Defender
After all of the fixes are complete, it is very important that you enable Real-time Protection again

Run VundoFix
Double-click VundoFix.exe
Click the Scan for Vundo button.
When it finishes scanning, Right Click inside the listbox (white box) and click add more files
Copy&Paste the following files in the 2 boxes :

BOX 1 : C:\WINDOWS\system32\brajmeut.dll
BOX 2 : C:\WINDOWS\SYSTEM32\tuemjarb.*

Click Add Files and Click Close Window
The files will be added to the Scan results list

Click the Remove Vundo button
You will receive a prompt asking if you want to "remove the files", click YES
Once you click yes, your desktop will go blank as it starts removing Vundo
When completed, it will prompt that it will reboot your computer, click OK
The .txt file will be in C:\Vundofix.txt

After the reboot, run VundoFix again We have 2 more files to get rid of :

BOX 1 : C:\WINDOWS\system32\kowhjsbh.dll
BOX 2 : C:\WINDOWS\SYSTEM32\hbsjhwok.*
(run Fix)

BOX 1 : C:\WINDOWS\system32\frrlyikl.dll
BOX 2 : C:\WINDOWS\SYSTEM32\lkiylrrf.*
(run Fix)

Vundo needs to be run 3 times total, inserting the files each time, also saving the log for each

After the last file has been removed :

Run HijackThis
Scan and when it finishes, put a check mark only next to these following items : (if present)

O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\brajmeut.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\kowhjsbh.dll
O2 - BHO: (no name) - {98FC8664-E208-4AF1-B622-8229EC5F3F12} - C:\WINDOWS\system32\frrlyikl.dll
O2 - BHO: SDWin32 Class - {E3A36A4E-8035-4AA1-B026-805100233657} - C:\WINDOWS\System32\dlmkk.dll (file missing)
O2 - BHO: (no name) - {FE034B90-BF6B-4161-A4D6-CF752E0F76E3} - C:\WINDOWS\ServicePackFiles\idsksvs.dll (file missing)

O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ynoombos.dll",setvm


Close all browsers and any open Windows, making sure that only HijackThis is open
Click Fix Checked
Close HijackThis


Post a fresh HijackThis log and ALL 3 vundofix.txt files here
Thanks, I will do these steps when I get home tonight. BTW, Windows Defender is running due to some expiration that happened end of year. I guess I need to update that first, then disable the real time protection. Scares me to connect to the internet though. Will try via another PC and flash.
Linkmaster, I ran Vundo and it found no files. I tried to cut and paste BOX 1 : C:\WINDOWS\system32\brajmeut.dll BOX 2 : C:\WINDOWS\SYSTEM32\tuemjarb.* but could not since PASTE was greyed out. I tried just typing in the file names but they were not added. I went ahead and rebooted and ran Vundo again and again it found no files. Now what? thanks
Linkmaster, ran Vundo 3 times removing files as suggested (but in different order, 2nd set first), then ran HJT and checked files as suggested. Attached are all the log files.

thanks again

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 7:19:32 PM 1/2/2007

Listing files found while scanning….

C:\WINDOWS\SYSTEM32\alrrlnmr.dll
C:\WINDOWS\SYSTEM32\atfffpgd.dll
C:\WINDOWS\SYSTEM32\mbiyxvfj.dll
C:\WINDOWS\SYSTEM32\mkadvgek.dll
C:\WINDOWS\ServicePackFiles\idsksvs.dll
C:\WINDOWS\ServicePackFiles\svsksdi.ini
C:\WINDOWS\ServicePackFiles\svsksdi.bak1
C:\WINDOWS\ServicePackFiles\svsksdi.bak2
C:\WINDOWS\ServicePackFiles\svsksdi.ini2
C:\WINDOWS\ServicePackFiles\svsksdi.tmp

Beginning removal…

Attempting to delete C:\WINDOWS\SYSTEM32\alrrlnmr.dll
C:\WINDOWS\SYSTEM32\alrrlnmr.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\atfffpgd.dll
C:\WINDOWS\SYSTEM32\atfffpgd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mbiyxvfj.dll
C:\WINDOWS\SYSTEM32\mbiyxvfj.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mkadvgek.dll
C:\WINDOWS\SYSTEM32\mkadvgek.dll Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\idsksvs.dll
C:\WINDOWS\ServicePackFiles\idsksvs.dll Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.ini
C:\WINDOWS\ServicePackFiles\svsksdi.ini Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.bak1
C:\WINDOWS\ServicePackFiles\svsksdi.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.bak2
C:\WINDOWS\ServicePackFiles\svsksdi.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.ini2
C:\WINDOWS\ServicePackFiles\svsksdi.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.tmp
C:\WINDOWS\ServicePackFiles\svsksdi.tmp Has been deleted!

Attempting to delete C:\\windows\system32\ynoombos.dll
C:\\windows\system32\ynoombos.dll Has been deleted!

Attempting to delete C:\\windows\system32\sobmoony.ini
C:\\windows\system32\sobmoony.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 8:11:35 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 9:22:46 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 10:19:52 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

Attempting to delete c:\windows\system32\kowhjsbh.dll
c:\windows\system32\kowhjsbh.dll Has been deleted!

Performing Repairs to the registry.
Done!

#2


VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 7:19:32 PM 1/2/2007

Listing files found while scanning….

C:\WINDOWS\SYSTEM32\alrrlnmr.dll
C:\WINDOWS\SYSTEM32\atfffpgd.dll
C:\WINDOWS\SYSTEM32\mbiyxvfj.dll
C:\WINDOWS\SYSTEM32\mkadvgek.dll
C:\WINDOWS\ServicePackFiles\idsksvs.dll
C:\WINDOWS\ServicePackFiles\svsksdi.ini
C:\WINDOWS\ServicePackFiles\svsksdi.bak1
C:\WINDOWS\ServicePackFiles\svsksdi.bak2
C:\WINDOWS\ServicePackFiles\svsksdi.ini2
C:\WINDOWS\ServicePackFiles\svsksdi.tmp

Beginning removal…

Attempting to delete C:\WINDOWS\SYSTEM32\alrrlnmr.dll
C:\WINDOWS\SYSTEM32\alrrlnmr.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\atfffpgd.dll
C:\WINDOWS\SYSTEM32\atfffpgd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mbiyxvfj.dll
C:\WINDOWS\SYSTEM32\mbiyxvfj.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mkadvgek.dll
C:\WINDOWS\SYSTEM32\mkadvgek.dll Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\idsksvs.dll
C:\WINDOWS\ServicePackFiles\idsksvs.dll Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.ini
C:\WINDOWS\ServicePackFiles\svsksdi.ini Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.bak1
C:\WINDOWS\ServicePackFiles\svsksdi.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.bak2
C:\WINDOWS\ServicePackFiles\svsksdi.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.ini2
C:\WINDOWS\ServicePackFiles\svsksdi.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.tmp
C:\WINDOWS\ServicePackFiles\svsksdi.tmp Has been deleted!

Attempting to delete C:\\windows\system32\ynoombos.dll
C:\\windows\system32\ynoombos.dll Has been deleted!

Attempting to delete C:\\windows\system32\sobmoony.ini
C:\\windows\system32\sobmoony.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 8:11:35 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 9:22:46 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 10:19:52 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

Attempting to delete c:\windows\system32\kowhjsbh.dll
c:\windows\system32\kowhjsbh.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 11:13:10 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

Attempting to delete c:\windows\system32\brajmeut.dll
c:\windows\system32\brajmeut.dll Has been deleted!

Performing Repairs to the registry.
Done!

#3


VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 7:19:32 PM 1/2/2007

Listing files found while scanning….

C:\WINDOWS\SYSTEM32\alrrlnmr.dll
C:\WINDOWS\SYSTEM32\atfffpgd.dll
C:\WINDOWS\SYSTEM32\mbiyxvfj.dll
C:\WINDOWS\SYSTEM32\mkadvgek.dll
C:\WINDOWS\ServicePackFiles\idsksvs.dll
C:\WINDOWS\ServicePackFiles\svsksdi.ini
C:\WINDOWS\ServicePackFiles\svsksdi.bak1
C:\WINDOWS\ServicePackFiles\svsksdi.bak2
C:\WINDOWS\ServicePackFiles\svsksdi.ini2
C:\WINDOWS\ServicePackFiles\svsksdi.tmp

Beginning removal…

Attempting to delete C:\WINDOWS\SYSTEM32\alrrlnmr.dll
C:\WINDOWS\SYSTEM32\alrrlnmr.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\atfffpgd.dll
C:\WINDOWS\SYSTEM32\atfffpgd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mbiyxvfj.dll
C:\WINDOWS\SYSTEM32\mbiyxvfj.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mkadvgek.dll
C:\WINDOWS\SYSTEM32\mkadvgek.dll Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\idsksvs.dll
C:\WINDOWS\ServicePackFiles\idsksvs.dll Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.ini
C:\WINDOWS\ServicePackFiles\svsksdi.ini Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.bak1
C:\WINDOWS\ServicePackFiles\svsksdi.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.bak2
C:\WINDOWS\ServicePackFiles\svsksdi.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.ini2
C:\WINDOWS\ServicePackFiles\svsksdi.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\ServicePackFiles\svsksdi.tmp
C:\WINDOWS\ServicePackFiles\svsksdi.tmp Has been deleted!

Attempting to delete C:\\windows\system32\ynoombos.dll
C:\\windows\system32\ynoombos.dll Has been deleted!

Attempting to delete C:\\windows\system32\sobmoony.ini
C:\\windows\system32\sobmoony.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 8:11:35 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 9:22:46 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 10:19:52 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

Attempting to delete c:\windows\system32\kowhjsbh.dll
c:\windows\system32\kowhjsbh.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 11:13:10 PM 1/3/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

Attempting to delete c:\windows\system32\brajmeut.dll
c:\windows\system32\brajmeut.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.4

Scan started at 12:03:18 AM 1/4/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

Attempting to delete c:\windows\system32\frrlyikl.dll
c:\windows\system32\frrlyikl.dll Has been deleted!

Performing Repairs to the registry.
Done!

HJT log

Logfile of HijackThis v1.99.1
Scan saved at 8:07:20 AM, on 1/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\StorageSync\StrgSync.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Creative\ShareDLL\Mediadet.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\TiVo\Desktop\TiVoServer.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\Common Files\MotiveBrowser\MotiveBrowser.exe
C:\Documents and Settings\hank\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=552…cid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\brajmeut.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\kowhjsbh.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {98FC8664-E208-4AF1-B622-8229EC5F3F12} - C:\WINDOWS\system32\frrlyikl.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: SDWin32 Class - {E3A36A4E-8035-4AA1-B026-805100233657} - C:\WINDOWS\System32\dlmkk.dll (file missing)
O2 - BHO: (no name) - {FE034B90-BF6B-4161-A4D6-CF752E0F76E3} - C:\WINDOWS\ServicePackFiles\idsksvs.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ynoombos.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry /auto:TivoServer
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\Belkin\11Mbps Wireless Network\Config.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webtrain.com/cabinet/WT0804.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1104344382359
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/w…tWebInstall.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe" /service (file missing)

After HJT fix

Logfile of HijackThis v1.99.1
Scan saved at 8:18:58 AM, on 1/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\StorageSync\StrgSync.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Creative\ShareDLL\Mediadet.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\TiVo\Desktop\TiVoServer.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\Common Files\MotiveBrowser\MotiveBrowser.exe
C:\Documents and Settings\hank\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=552…cid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry /auto:TivoServer
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\Belkin\11Mbps Wireless Network\Config.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webtrain.com/cabinet/WT0804.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1104344382359
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/w…tWebInstall.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe" /service (file missing)
You did great !! :thumbup:

Run Kaspersky WebScanner
Click on Kaspersky Online Scanner
NOTE For Internet Explorer 7 Users : If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then begin downloading t he latest definition files:
Once the files have been downloaded click on NEXT
Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (if available otherwise Standard)

Scan Options:
Scan Archives
Scan Mail Bases

Click OK

Now under select a target to scan:
Select My Computer

Then the program will start and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.

Post a fresh HijackThis Log and the Kaspersky Virus Scan Log here
Let me know how your system is running now !?!?
Thank You !!
Linkmaster, Seems I still have a ways to go. Kasper and HJT logs posted.

Logfile of HijackThis v1.99.1
Scan saved at 3:49:53 PM, on 1/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\StorageSync\StrgSync.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Creative\ShareDLL\Mediadet.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\TiVo\Desktop\TiVoServer.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\Common Files\MotiveBrowser\MotiveBrowser.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\hank\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=552…cid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry /auto:TivoServer
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\Belkin\11Mbps Wireless Network\Config.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webtrain.com/cabinet/WT0804.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1104344382359
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/w…tWebInstall.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe" /service (file missing)

Thursday, January 04, 2007 3:48:42 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 4/01/2007
Kaspersky Anti-Virus database records: 256103


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\
F:\
G:\
H:\

Scan Statistics
Total number of scanned objects 162470
Number of viruses found 20
Number of infected objects 85 / 0
Number of suspicious objects 1
Duration of the scan process 02:20:52

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd002.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01032007-200921.log Object is locked skipped

C:\Documents and Settings\hank\Application Data\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped

C:\Documents and Settings\hank\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Application Data\Musicmatch\Jukebox\mmjbaltlog.txt Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Application Data\Musicmatch\Jukebox\mmjblog.txt Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Application Data\Musicmatch\Jukebox\Portables.log Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Application Data\Musicmatch\MIM\Database\Default.ldb Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Application Data\Musicmatch\MIM\Database\Default.mdb Object is locked skipped

C:\Documents and Settings\hank\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Temp\bbassistant.log Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Temp\JETBCF2.tmp Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe/InpB/TvmBho.dll Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped

C:\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe/InpB/TvmCore.dll Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped

C:\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe/InpB/Tvm.exe Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped

C:\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe/InpB Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped

C:\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe CAB: infected - 4 skipped

C:\Documents and Settings\hank\Local Settings\Temporary Internet Files\AntiPhishing\2997C193-A464-4307-88C9-F9C00083CD16.dat Object is locked skipped

C:\Documents and Settings\hank\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\hank\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\hank\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Common Files\Verizon Online\ConnMgr\VZLog Object is locked skipped

C:\Program Files\McAfee.com\Personal Firewall\data\hwcache.xdb Object is locked skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48/data0003/data0001 Infected: not-a-virus:AdWare.Win32.WebRebates.g skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48/data0003 Infected: not-a-virus:AdWare.Win32.WebRebates.g skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48/data0003 Infected: not-a-virus:AdWare.Win32.WebRebates.b skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48/data0004 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48/data0005 Infected: not-a-virus:AdWare.Win32.WebRebates.b skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48 NSIS: infected - 5 skipped

C:\Program Files\Verizon Online\Help Support\SmartBridge\AlertFilter.log Object is locked skipped

C:\Program Files\Verizon Online\Help Support\SmartBridge\log\httpclient.log Object is locked skipped

C:\Program Files\Verizon Online\Help Support\SmartBridge\SmartBridge.log Object is locked skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP960\A0054261.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP976\A0055550.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP976\A0055551.dll Infected: Packed.Win32.Klone.k skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP976\A0055552.dll Infected: Packed.Win32.Klone.k skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP976\A0055554.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dq skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP976\A0055556.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ft skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP979\A0055645.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\change.log Object is locked skipped

C:\VundoFix Backups\alrrlnmr.dll.bad Infected: Trojan.Win32.BHO.g skipped

C:\VundoFix Backups\atfffpgd.dll.bad Infected: Packed.Win32.Klone.k skipped

C:\VundoFix Backups\brajmeut.dll.bad Infected: Trojan.Win32.BHO.g skipped

C:\VundoFix Backups\idsksvs.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dq skipped

C:\VundoFix Backups\mbiyxvfj.dll.bad Infected: Packed.Win32.Klone.k skipped

C:\VundoFix Backups\ynoombos.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ft skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CatRoot2\edbtmp.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\elvvjrlg.dll Infected: Trojan-Spy.Win32.VBStat.j skipped

C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped

C:\WINDOWS\SYSTEM32\hjagehha.dll Infected: Trojan.Win32.BHO.g skipped

C:\WINDOWS\SYSTEM32\imdukrnp.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\WINDOWS\SYSTEM32\jsqtahwe.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\WINDOWS\SYSTEM32\ktbyaoif.dll Infected: Trojan.Win32.BHO.g skipped

C:\WINDOWS\SYSTEM32\pcxwdmqj.dll Infected: Trojan-Spy.Win32.VBStat.j skipped

C:\WINDOWS\SYSTEM32\pxlksrtn.dll Infected: Trojan.Win32.BHO.g skipped

C:\WINDOWS\SYSTEM32\pyhqjgrr.dll Infected: Trojan.Win32.BHO.g skipped

C:\WINDOWS\SYSTEM32\qqnlxjjs.dll Infected: Trojan-Spy.Win32.VBStat.j skipped

C:\WINDOWS\SYSTEM32\riyqlsoo.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\WINDOWS\SYSTEM32\ropyiwbr.dll Infected: Trojan-Spy.Win32.VBStat.j skipped

C:\WINDOWS\SYSTEM32\slstyjej.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\WINDOWS\SYSTEM32\srjbnrlo.dll Infected: not-a-virus:AdWare.Win32.BHO.v skipped

C:\WINDOWS\SYSTEM32\tfbgfqeq.dll Infected: Trojan.Win32.BHO.o skipped

C:\WINDOWS\SYSTEM32\vkasokul.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\xvyvvqte.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\WINDOWS\SYSTEM32\xxqwdqck.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\WINDOWS\Temp\sqlite_hhJHXgr7shJh2RM Object is locked skipped

C:\WINDOWS\WIADEBUG.LOG Object is locked skipped

C:\WINDOWS\WIASERVC.LOG Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\12149setup.exe/data0002 Infected: not-a-virus:AdWare.Win32.UrlSpy.a skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\12149setup.exe/data0004 Infected: not-a-virus:AdWare.Win32.UrlSpy.a skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\12149setup.exe/data0006 Infected: not-a-virus:AdWare.Win32.UrlSpy.b skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\12149setup.exe/data0007 Infected: not-a-virus:AdWare.Win32.UrlSpy.b skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\12149setup.exe NSIS: infected - 4 skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\cbpsnyfg.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe/InpB/TvmBho.dll Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe/InpB/TvmCore.dll Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe/InpB/Tvm.exe Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe/InpB Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe CAB: infected - 4 skipped

H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temporary Internet Files\Content.IE5\90GF2T1U\deliver46860[1].htm Suspicious: Exploit.HTML.Mht skipped

H:\StorageSync\Drive_C\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48/data0003/data0001 Infected: not-a-virus:AdWare.Win32.WebRebates.g skipped

H:\StorageSync\Drive_C\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48/data0003 Infected: not-a-virus:AdWare.Win32.WebRebates.g skipped

H:\StorageSync\Drive_C\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48/data0003 Infected: not-a-virus:AdWare.Win32.WebRebates.b skipped

H:\StorageSync\Drive_C\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48/data0004 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped

H:\StorageSync\Drive_C\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48/data0005 Infected: not-a-virus:AdWare.Win32.WebRebates.b skipped

H:\StorageSync\Drive_C\Program Files\Microsoft AntiSpyware\Quarantine\379E5F82-B693-4A54-9000-0D78A1\B5419A79-3458-4D14-AB19-2B5A48 NSIS: infected - 5 skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049617.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049618.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049619.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049620.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049621.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049622.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049623.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049624.exe Infected: Trojan.Win32.Small.ju skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049625.exe Infected: Trojan.Win32.Small.ju skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049626.exe Infected: Trojan.Win32.Small.ju skipped

H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP960\A0054261.dll Infected: Trojan.Win32.BHO.g skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\alrrlnmr.dll Infected: Trojan.Win32.BHO.g skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\atfffpgd.dll Infected: Packed.Win32.Klone.k skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\imdukrnp.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\jsqtahwe.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ktbyaoif.dll Infected: Trojan.Win32.BHO.g skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\mbiyxvfj.dll Infected: Packed.Win32.Klone.k skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\riyqlsoo.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ropyiwbr.dll Infected: Trojan-Spy.Win32.VBStat.j skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\slstyjej.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\tfbgfqeq.dll Infected: Trojan.Win32.BHO.o skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xvyvvqte.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xxqwdqck.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ynoombos.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ft skipped

H:\StorageSync\Drive_C\WINDOWS\Temp\setup4.exe/data0002 Infected: not-a-virus:AdWare.Win32.IEDriver.a skipped

H:\StorageSync\Drive_C\WINDOWS\Temp\setup4.exe/data0003 Infected: Trojan-Downloader.Win32.Agent.adz skipped

H:\StorageSync\Drive_C\WINDOWS\Temp\setup4.exe NSIS: infected - 2 skipped

H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.
Empty the contents of the following folders :

C:\Program Files\Microsoft AntiSpyware\Quarantine
H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temp
H:\StorageSync\Drive_C\Program Files\Microsoft AntiSpyware\Quarantine
H:\StorageSync\Drive_C\WINDOWS\Temp

Empty your Recycle Bin

Uninstall Ewido AntiSpyware I want you to use the NEW version here :

Download and Install AVG Anti-Spyware© by Grisoft

Launch AVG Anti-Spyware, there should be an icon on your desktop double-click it.
The program will now go to the main screen
You will need to update AVG Anti-Spyware to the latest definition files.
On the main screen select the icon Update then select the Update now link
Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
Close AVG Anti-Spyware

Reboot to Safe mode
Restart your computer and begin tapping the F8 key on your keyboard just before Windows starts to load
If done right a Windows Advanced Options menu will appear.
Select the Safe Mode option and press Enter

Run ATF Cleaner
Double-click ATF Cleaner.exe
Under Main choose: Select All
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Run AVG Anti-Spyware
Click on Scanner at top
Click on Settings
Once in the Settings screen click on Recommended actions and then select Quarantine
Under Reports, Select Automatically generate report after every scan
Un-Select Only if threats were found
Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan
AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time
Once the scan is complete do the following :
If you have any infections you will prompted, then select Apply all actions
Next select the Reports icon at the top.
Select the Save report as button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
Close AVG Anti-Spyware

Reboot to Normal Mode

Download and Unzip The Avenger© by Swandog46 to your desktop
Copy the entire contents inside the following Quote box to your Clipboard :

files to delete:
C:\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe
C:\WINDOWS\SYSTEM32\elvvjrlg.dll
C:\WINDOWS\SYSTEM32\hjagehha.dll
C:\WINDOWS\SYSTEM32\imdukrnp.dll
C:\WINDOWS\SYSTEM32\jsqtahwe.exe
C:\WINDOWS\SYSTEM32\ktbyaoif.dll
C:\WINDOWS\SYSTEM32\pcxwdmqj.dll
C:\WINDOWS\SYSTEM32\pxlksrtn.dll
C:\WINDOWS\SYSTEM32\pyhqjgrr.dll
C:\WINDOWS\SYSTEM32\qqnlxjjs.dll
C:\WINDOWS\SYSTEM32\riyqlsoo.dll
C:\WINDOWS\SYSTEM32\ropyiwbr.dll
C:\WINDOWS\SYSTEM32\slstyjej.exe
C:\WINDOWS\SYSTEM32\srjbnrlo.dll
C:\WINDOWS\SYSTEM32\tfbgfqeq.dll
C:\WINDOWS\SYSTEM32\vkasokul.exe
C:\WINDOWS\SYSTEM32\xvyvvqte.dll
C:\WINDOWS\SYSTEM32\xxqwdqck.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\alrrlnmr.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\atfffpgd.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\imdukrnp.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\jsqtahwe.exe
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ktbyaoif.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\mbiyxvfj.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\riyqlsoo.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ropyiwbr.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\slstyjej.exe
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\tfbgfqeq.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xvyvvqte.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xxqwdqck.dll
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ynoombos.dll

Folders to delete:
C:\VundoFix Backups


Run The Avenger
Double click the Avenger icon on your desktop
Under Script file to execute choose Input Script Manually
Click on the Magnifying Glass icon which will open a new window titled View/edit script
Paste the text you just copied to clipboard into this window by pressing Ctrl+V
Click Done
Now click on the Green Light to begin execution of the script
Answer Yes twice when prompted.
The Avenger will automatically do the following :

•Restart your computer (In cases where the code to execute contains Drivers to Unload, The Avenger will actually restart your system twice)
•On reboot, it will briefly open a black command window on your desktop, this is normal.
•After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
•The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip

Run Kaspersky WebScanner again

Post a fresh HijackThis log, the contents of the c:\avenger.txt file, the AVG Anti-Spyware log and the Kaspersky WebScanner log here
(You may need to use several replies as the logs may be cut off)
Linkmaster, 2 messages with all the reports. HJT and Avenger here. ARE WE MAKING PROGRESS??

Logfile of HijackThis v1.99.1
Scan saved at 8:02:33 AM, on 1/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Creative\ShareDLL\Mediadet.exe
C:\Program Files\StorageSync\StrgSync.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\Program Files\TiVo\Desktop\TiVoServer.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\Common Files\MotiveBrowser\MotiveBrowser.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\hank\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=552…cid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry /auto:TivoServer
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\Belkin\11Mbps Wireless Network\Config.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webtrain.com/cabinet/WT0804.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1104344382359
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/w…tWebInstall.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe" /service (file missing)


AVENGER

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\lygfhxoc

*******************

Script file located at: \??\C:\WINDOWS\system32\tafncsst.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\Documents and Settings\hank\Local Settings\Temp\tvmupdater.exe deleted successfully.
File C:\WINDOWS\SYSTEM32\elvvjrlg.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\hjagehha.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\imdukrnp.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\jsqtahwe.exe deleted successfully.
File C:\WINDOWS\SYSTEM32\ktbyaoif.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\pcxwdmqj.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\pxlksrtn.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\pyhqjgrr.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\qqnlxjjs.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\riyqlsoo.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\ropyiwbr.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\slstyjej.exe deleted successfully.
File C:\WINDOWS\SYSTEM32\srjbnrlo.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\tfbgfqeq.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\vkasokul.exe deleted successfully.
File C:\WINDOWS\SYSTEM32\xvyvvqte.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\xxqwdqck.dll deleted successfully.


Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\alrrlnmr.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\alrrlnmr.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\alrrlnmr.dll
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\atfffpgd.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\atfffpgd.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\atfffpgd.dll
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\imdukrnp.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\imdukrnp.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\imdukrnp.dll
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\jsqtahwe.exe for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\jsqtahwe.exe failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\jsqtahwe.exe
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ktbyaoif.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ktbyaoif.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ktbyaoif.dll
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\mbiyxvfj.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\mbiyxvfj.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\mbiyxvfj.dll
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\riyqlsoo.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\riyqlsoo.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\riyqlsoo.dll
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ropyiwbr.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ropyiwbr.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ropyiwbr.dll
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\slstyjej.exe for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\slstyjej.exe failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\slstyjej.exe
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\tfbgfqeq.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\tfbgfqeq.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\tfbgfqeq.dll
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xvyvvqte.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xvyvvqte.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xvyvvqte.dll
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xxqwdqck.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xxqwdqck.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xxqwdqck.dll
Status: 0xc000003a



Could not open file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ynoombos.dll for deletion
Deletion of file H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ynoombos.dll failed!

Could not process line:
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ynoombos.dll
Status: 0xc000003a

Folder C:\VundoFix Backups deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
Message 2 of 2 , AVG and Kaspersky logs AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 7:08:43 AM 1/5/2007 + Scan result: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP976\A0055554.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\idsksvs.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP976\A0055551.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP976\A0055552.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). C:\VundoFix Backups\atfffpgd.dll.bad -> Logger.VBStat.e : Cleaned with backup (quarantined). C:\VundoFix Backups\mbiyxvfj.dll.bad -> Logger.VBStat.e : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\atfffpgd.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\mbiyxvfj.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049624.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049625.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049626.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049617.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049618.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049619.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049620.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049621.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049622.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined). H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP860\A0049623.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined). ::Report end Kaspersky log Sunday, January 07, 2007 8:01:50 AM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 7/01/2007 Kaspersky Anti-Virus database records: 256561 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan Statistics Total number of scanned objects 156134 Number of viruses found 16 Number of infected objects 85 / 0 Number of suspicious objects 1 Duration of the scan process 02:15:26 Infected Object Name Virus Name Last Action C:\avenger\backup.zip/avenger/elvvjrlg.dll Infected: Trojan-Spy.Win32.VBStat.j skipped C:\avenger\backup.zip/avenger/hjagehha.dll Infected: Trojan.Win32.BHO.g skipped C:\avenger\backup.zip/avenger/imdukrnp.dll Infected: Trojan-Spy.Win32.VBStat.h skipped C:\avenger\backup.zip/avenger/jsqtahwe.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped C:\avenger\backup.zip/avenger/ktbyaoif.dll Infected: Trojan.Win32.BHO.g skipped C:\avenger\backup.zip/avenger/pcxwdmqj.dll Infected: Trojan-Spy.Win32.VBStat.j skipped C:\avenger\backup.zip/avenger/pxlksrtn.dll Infected: Trojan.Win32.BHO.g skipped C:\avenger\backup.zip/avenger/pyhqjgrr.dll Infected: Trojan.Win32.BHO.g skipped C:\avenger\backup.zip/avenger/qqnlxjjs.dll Infected: Trojan-Spy.Win32.VBStat.j skipped C:\avenger\backup.zip/avenger/riyqlsoo.dll Infected: Trojan-Spy.Win32.VBStat.h skipped C:\avenger\backup.zip/avenger/ropyiwbr.dll Infected: Trojan-Spy.Win32.VBStat.j skipped C:\avenger\backup.zip/avenger/slstyjej.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped C:\avenger\backup.zip/avenger/srjbnrlo.dll Infected: not-a-virus:AdWare.Win32.BHO.v skipped C:\avenger\backup.zip/avenger/tfbgfqeq.dll Infected: Trojan.Win32.BHO.o skipped C:\avenger\backup.zip/avenger/tvmupdater.exe/InpB/TvmBho.dll Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped C:\avenger\backup.zip/avenger/tvmupdater.exe/InpB/TvmCore.dll Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped C:\avenger\backup.zip/avenger/tvmupdater.exe/InpB/Tvm.exe Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped C:\avenger\backup.zip/avenger/tvmupdater.exe/InpB Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped C:\avenger\backup.zip/avenger/tvmupdater.exe Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped C:\avenger\backup.zip/avenger/vkasokul.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped C:\avenger\backup.zip/avenger/VundoFix Backups/alrrlnmr.dll.bad Infected: Trojan.Win32.BHO.g skipped C:\avenger\backup.zip/avenger/VundoFix Backups/brajmeut.dll.bad Infected: Trojan.Win32.BHO.g skipped C:\avenger\backup.zip/avenger/VundoFix Backups/ynoombos.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ft skipped C:\avenger\backup.zip/avenger/xvyvvqte.dll Infected: Trojan-Spy.Win32.VBStat.h skipped C:\avenger\backup.zip/avenger/xxqwdqck.dll Infected: Trojan-Spy.Win32.VBStat.h skipped C:\avenger\backup.zip ZIP: infected - 25 skipped C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd000.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01032007-200921.log Object is locked skipped C:\Documents and Settings\hank\Application Data\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped C:\Documents and Settings\hank\Cookies\index.dat Object is locked skipped C:\Documents and Settings\hank\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\hank\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\hank\Local Settings\Application Data\Musicmatch\Jukebox\mmjbaltlog.txt Object is locked skipped C:\Documents and Settings\hank\Local Settings\Application Data\Musicmatch\Jukebox\mmjblog.txt Object is locked skipped C:\Documents and Settings\hank\Local Settings\Application Data\Musicmatch\MIM\Database\Default.ldb Object is locked skipped C:\Documents and Settings\hank\Local Settings\Application Data\Musicmatch\MIM\Database\Default.mdb Object is locked skipped C:\Documents and Settings\hank\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\hank\Local Settings\Temp\bbassistant.log Object is locked skipped C:\Documents and Settings\hank\Local Settings\Temp\JETB996.tmp Object is locked skipped C:\Documents and Settings\hank\Local Settings\Temporary Internet Files\AntiPhishing\2997C193-A464-4307-88C9-F9C00083CD16.dat Object is locked skipped C:\Documents and Settings\hank\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\hank\NTUSER.DAT Object is locked skipped C:\Documents and Settings\hank\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Common Files\Verizon Online\ConnMgr\VZLog Object is locked skipped C:\Program Files\Verizon Online\Help Support\SmartBridge\AlertFilter.log Object is locked skipped C:\Program Files\Verizon Online\Help Support\SmartBridge\log\httpclient.log Object is locked skipped C:\Program Files\Verizon Online\Help Support\SmartBridge\SmartBridge.log Object is locked skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP960\A0054261.dll Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP976\A0055550.dll Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP976\A0055556.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ft skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP979\A0055645.dll Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055936.dll Infected: Trojan-Spy.Win32.VBStat.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055937.dll Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055939.dll Infected: Trojan-Spy.Win32.VBStat.h skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055940.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055941.dll Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055942.dll Infected: Trojan-Spy.Win32.VBStat.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055943.dll Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055944.dll Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055945.dll Infected: Trojan-Spy.Win32.VBStat.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055947.dll Infected: Trojan-Spy.Win32.VBStat.h skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055948.dll Infected: Trojan-Spy.Win32.VBStat.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055949.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055950.dll Infected: not-a-virus:AdWare.Win32.BHO.v skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055951.dll Infected: Trojan.Win32.BHO.o skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055952.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055953.dll Infected: Trojan-Spy.Win32.VBStat.h skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP982\A0055954.dll Infected: Trojan-Spy.Win32.VBStat.h skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP983\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\WIADEBUG.LOG Object is locked skipped C:\WINDOWS\WIASERVC.LOG Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped H:\StorageSync\Drive_C\Documents and Settings\hank\Local Settings\Temporary Internet Files\Content.IE5\90GF2T1U\deliver46860[1].htm Suspicious: Exploit.HTML.Mht skipped H:\StorageSync\Drive_C\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP960\A0054261.dll Infected: Trojan.Win32.BHO.g skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\alrrlnmr.dll Infected: Trojan.Win32.BHO.g skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\imdukrnp.dll Infected: Trojan-Spy.Win32.VBStat.h skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\jsqtahwe.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ktbyaoif.dll Infected: Trojan.Win32.BHO.g skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\riyqlsoo.dll Infected: Trojan-Spy.Win32.VBStat.h skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ropyiwbr.dll Infected: Trojan-Spy.Win32.VBStat.j skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\slstyjej.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\tfbgfqeq.dll Infected: Trojan.Win32.BHO.o skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xvyvvqte.dll Infected: Trojan-Spy.Win32.VBStat.h skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\xxqwdqck.dll Infected: Trojan-Spy.Win32.VBStat.h skipped H:\StorageSync\Drive_C\WINDOWS\SYSTEM32\ynoombos.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ft skipped H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055709.exe/data0002 Infected: not-a-virus:AdWare.Win32.UrlSpy.a skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055709.exe/data0004 Infected: not-a-virus:AdWare.Win32.UrlSpy.a skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055709.exe/data0006 Infected: not-a-virus:AdWare.Win32.UrlSpy.b skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055709.exe/data0007 Infected: not-a-virus:AdWare.Win32.UrlSpy.b skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055709.exe NSIS: infected - 4 skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055721.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055745.exe/InpB/TvmBho.dll Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055745.exe/InpB/TvmCore.dll Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055745.exe/InpB/Tvm.exe Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055745.exe/InpB Infected: not-a-virus:AdWare.Win32.TotalVelocity.v skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055745.exe CAB: infected - 4 skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055757.exe/data0002 Infected: not-a-virus:AdWare.Win32.IEDriver.a skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055757.exe/data0003 Infected: Trojan-Downloader.Win32.Agent.adz skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP980\A0055757.exe NSIS: infected - 2 skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055887.dll Infected: Packed.Win32.Klone.k skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055888.dll Infected: Packed.Win32.Klone.k skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055889.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055890.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055891.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055892.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055893.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055894.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055895.exe Infected: not-a-virus:Downloader.Win32.WinFixer.r skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055896.exe Infected: Trojan.Win32.Small.ju skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055897.exe Infected: Trojan.Win32.Small.ju skipped H:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP981\A0055898.exe Infected: Trojan.Win32.Small.ju skipped Scan process completed.
Avenger couldn't get in here :
H:\StorageSync\Drive_C\WINDOWS\SYSTEM32

You should clean out that backup.
Maybe even start a new one !

Other than that :

Your log seems to be OK now !!

Just one more thing :
**Turn off System Restore**
On the Desktop, right-click My Computer
Click Properties
Click the System Restore tab.
Check "Turn off System Restore"
Click Apply, then click OK and Reboot

**Turn ON System Restore**
On the Desktop, right-click My Computer
Click Properties
Click the System Restore tab.
UN-Check "Turn off System Restore"
Click Apply, then click OK and Reboot

How is your system running now ??

Here are a few recommendations for protecting your system and reducing your risk of infection again !!

** Windows Update **
It is very important to keep your system up to date with the latest Critical Updates to avoid unnecessary security risks
Visit Microsoft's Windows Update page at the very least monthly to check for updates !!

** Make Your Internet Explorer More Secure **
This can be done by following these simple instructions :
From within Internet Explorer click on the Tools menu and then click on Options
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
Change the Allow paste operations via script to Disable
When all these settings have been made, click on the OK button
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

** Real Time Prevention **
SpywareBlaster© by Javacool Software :
*Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted pests
*Block spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.
*Restrict the actions of potentially dangerous sites in Internet Explorer.
*Consumes no system resources

*Download, run, check for updates, download updates, select all, protect against checked. All done
*Check for updates every couple of weeks. If you have any errors running the program like a missing file see the link at the bottom of the javacool page
IESpyad© by EHowes : This will add several hundred Restricted Sites to the Restricted Site Zone in IE.

** File Cleaners (temp, prefetch, cookie, etc) **
2000/XP Only
ATF (Atribune Temp File) Cleaner© by Atribune
All Windows
CCleaner© by CCleaner.com

** Spyware Scanners **
Some FREE Spyware Scanners for Home use, that will detect and remove trojans, dialers, malware, browser hijackers, tracking components and other forms of Spyware :
SUPERAntiSpyware Home© by SUPERAntiSpyware.com
Ad-aware SE© by Lavasoft
Spybot S&D© by Safer-Networking

** Good Free Antivirus Programs **
AVG© by Grisoft
AntiVir© by H+BEDV Datentechnik GmbH
Avast© by ALWIL Software
NOTE:Remember always have just 1 antivirus program running at a time. Having more than one running causes a conflict between the programs !! You can use one as a backup to run manually

** Firewalls **
If you have an "always on" internet connection, such as DSL or Cable, I recommend a Firewall.
A firewall will make your pc invisible to the outside world and will filter the outgoing and incoming traffic on your pc.
For a good idea of how vulnerable your system(s) are go to GRC
Scroll down to "Shields Up" Click on "Proceed" Then click on "Common Ports"to scan your ports.
Free Personal Firewalls :
Sunbelt Kerio Personal Firewall© by Sunbelt
Jetico Personal Firewall© by Jetico, Inc.
Comodo Personal Firewall© by Comodo Group (XP & 2000 only)

I suggest that you Update Java:
Go to Start, Control Panel, Add/Remove Programs
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment…. ) and select Remove
Then Download and install the newest version :
JAVA SOFTWARE MANUAL DOWNLOAD

Always keep your Antivirus & Spyware Removal Tools current with the latest definitions and updates !!

Following these recommendations will help reduce your risk of future infections !!

Do you have any questions??

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI