This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

script errors

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

on my computer my wife and I each have admin Privileges, but on hers, she keeps getting a script error, which won't go away and when she goes into Internet Explorer it doesn't take her to her homepage, it gets stuck on a runonce. I've scanned my computer using AdAware, spysubtract, and a few others but I think she might have caught something, here's my log, thanks for any help!!!

Logfile of HijackThis v1.99.1
Scan saved at 11:37:55 PM, on 1/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\D-Link AirPlus\AirPlus.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Nate1\Local Settings\Temp\wz1d2c\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {4D39F094-D985-4F82-BCB4-37C7D402581A} - C:\WINDOWS\system32\MNUTILSE.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1126834498\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [0ce80c5c.dll] RUNDLL32.EXE 0ce80c5c.dll,b 16501328
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [aupd] C:\WINDOWS\system32\sywsvcs.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe
O4 - Startup: Deer Hunter 2005 Registration.lnk = C:\Program Files\Atari\Deer Hunter 2005\ATR1.EXE
O4 - Global Startup: D-Link AirPlus.lnk = ?
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164523961390
O20 - AppInit_DLLs:
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hello ASSOCIATED and Welcome to TomCoyote,

Disable Winpatrol:
Please disable Winpatrol as it may hinder the removal of some entries.
Right click the running icon of Winpatrol, and choose exit.


HijackThis is being run from a temporary folder; this means that any backups it creates as a result of fixes made with it will be lost. Please create a new folder for it and place the program into that new folder.

Please set your system to show all files; please see here if you're unsure how to do this.

Scan with HijackThis. Place a check against each of the following:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - {4D39F094-D985-4F82-BCB4-37C7D402581A} - C:\WINDOWS\system32\MNUTILSE.DLL (file missing)
O4 - HKLM\..\Run: [0ce80c5c.dll] RUNDLL32.EXE 0ce80c5c.dll,b 16501328
O4 - HKCU\..\Run: [aupd] C:\WINDOWS\system32\sywsvcs.exe

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\WINDOWS\system32\sywsvcs.exe<=file
Exit Explorer, and reboot as normal afterwards.

STEP 1.
======
Combofix
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.


Please post(reply) with the ComboFix log, log from Kapersky, and a new hijackthis log.

Enable WinPatrol again.
I was not able to find the c:windows\system32\sywsvcs.exe in safe mode

combo fix report

Combofix log:
Nate1 - 07-01-06 12:03:20.95 Service Pack 2
ComboFix 06.11.27 - Running from: "C:\HijackThis"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\secure32.html
C:\WINDOWS\dh.ini


((((((((((((((((((((((((((((((( Files Created from 2006-12-06 to 2007-01-06 ))))))))))))))))))))))))))))))))))


2007-01-04 00:28 d——– C:\Program Files\InterMute
2007-01-04 00:11 d——– C:\Program Files\BillP Studios
2007-01-04 00:11 d——– C:\Documents and Settings\Nate1\Application Data\WinPatrol
2006-12-25 09:36 d——– C:\Documents and Settings\Nate1\Application Data\Roxio
2006-12-25 09:34 d——– C:\Program Files\Napster
2006-12-25 09:34 d——– C:\Program Files\Common Files\Napster Shared
2006-12-25 09:34 d——– C:\Documents and Settings\All Users\Application Data\Napster


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-06 00:43 ——– d——– C:\Program Files\Steam
2007-01-05 01:41 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2007-01-03 23:50 ——– d——– C:\Program Files\PeerGuardian2
2007-01-03 23:50 ——– d——– C:\Program Files\PeerGuardian pr14
2007-01-03 23:34 ——– d——– C:\Program Files\eMule
2007-01-02 21:46 ——– d——– C:\Documents and Settings\Nate1\Application Data\WeatherBug
2007-01-02 21:38 ——– d——– C:\Documents and Settings\Nate1\Application Data\Temporary
2007-01-02 21:35 ——– d——– C:\Documents and Settings\Nate1\Application Data\MSN6
2007-01-02 21:34 ——– d–h—– C:\Program Files\InstallShield Installation Information
2007-01-02 21:33 ——– d——– C:\Program Files\GameSpy Arcade
2006-12-25 09:34 ——– d——– C:\Program Files\Common Files
2006-12-21 22:41 ——– d——– C:\Program Files\Common Files\aol
2006-12-13 23:04 ——– d——– C:\Program Files\Outlook Express
2006-12-13 23:04 ——– d——– C:\Program Files\Common Files\System
2006-12-06 23:56 ——– d——– C:\Program Files\SpywareBlaster
2006-12-02 11:23 ——– d——– C:\Program Files\Google
2006-11-30 00:27 ——– d——– C:\Program Files\Winamp
2006-11-26 01:04 ——– d——– C:\Program Files\Internet Explorer
2006-11-25 18:29 ——– d——– C:\Program Files\MTV Networks
2006-11-25 18:11 ——– d——– C:\Program Files\Windows Media Player
2006-11-25 18:11 ——– d——– C:\Program Files\Windows Media Connect 2
2006-11-25 15:55 ——– d——– C:\Documents and Settings\Nate1\Application Data\ConvertTemp
2006-11-25 15:03 ——– d——– C:\Documents and Settings\Nate1\Application Data\TransRender
2006-11-25 15:03 ——– d——– C:\Documents and Settings\Nate1\Application Data\Samsung
2006-11-25 13:45 ——– d—s—- C:\Documents and Settings\Nate1\Application Data\Microsoft
2006-11-25 13:36 ——– d——– C:\Program Files\Samsung
2006-11-17 03:01 ——– d——– C:\Program Files\MSXML 4.0
2006-11-07 23:06 679424 –a—— C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-11-07 21:03 6049280 ——— C:\WINDOWS\SYSTEM32\ieframe.dll
2006-11-07 21:03 50688 ——— C:\WINDOWS\SYSTEM32\msfeedsbs.dll
2006-11-07 21:03 458752 ——— C:\WINDOWS\SYSTEM32\msfeeds.dll
2006-11-07 21:03 413696 –a—— C:\WINDOWS\SYSTEM32\vbscript.dll
2006-11-07 21:03 231424 –a—— C:\WINDOWS\SYSTEM32\webcheck.dll
2006-11-07 21:03 180736 ——— C:\WINDOWS\SYSTEM32\ieui.dll
2006-11-07 21:03 156160 –a—— C:\WINDOWS\SYSTEM32\msls31.dll
2006-11-07 03:27 382976 –a—— C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-11-07 03:27 229376 –a—— C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-11-07 03:26 71680 –a—— C:\WINDOWS\SYSTEM32\admparse.dll
2006-11-07 03:26 55296 –a—— C:\WINDOWS\SYSTEM32\iesetup.dll
2006-11-07 03:26 54784 –a—— C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-11-07 03:26 43008 –a—— C:\WINDOWS\SYSTEM32\iernonce.dll
2006-11-07 03:26 152064 –a—— C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-11-07 03:26 13312 –a—— C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-11-07 03:26 123904 –a—— C:\WINDOWS\SYSTEM32\advpack.dll
2006-11-07 03:25 161792 –a—— C:\WINDOWS\SYSTEM32\ieakui.dll
2006-11-04 14:14 1245696 –a—— C:\WINDOWS\SYSTEM32\msxml4.dll
2006-10-19 07:56 713216 –a—— C:\WINDOWS\SYSTEM32\sxs.dll
2006-10-18 21:58 8704 –a—— C:\WINDOWS\SYSTEM32\wdfmgr.exe
2006-10-18 21:58 8704 –a—— C:\WINDOWS\SYSTEM32\uwdf.exe
2006-10-18 21:47 99840 –a—— C:\WINDOWS\SYSTEM32\wmpshell.dll
2006-10-18 21:47 991744 –a—— C:\WINDOWS\SYSTEM32\drmv2clt.dll
2006-10-18 21:47 937984 –a—— C:\WINDOWS\SYSTEM32\WMNetMgr.dll
2006-10-18 21:47 8231936 –a—— C:\WINDOWS\SYSTEM32\wmploc.dll
2006-10-18 21:47 767488 ——— C:\WINDOWS\SYSTEM32\WMVSENCD.dll
2006-10-18 21:47 757248 –a—— C:\WINDOWS\SYSTEM32\WMADMOD.dll
2006-10-18 21:47 7168 –a—— C:\WINDOWS\SYSTEM32\asferror.dll
2006-10-18 21:47 656896 ——— C:\WINDOWS\SYSTEM32\WMVXENCD.dll
2006-10-18 21:47 63488 –a—— C:\WINDOWS\SYSTEM32\wpdmtpus.dll
2006-10-18 21:47 629760 –a—— C:\WINDOWS\SYSTEM32\wpd_ci.dll
2006-10-18 21:47 613376 ——— C:\WINDOWS\SYSTEM32\wmpmde.dll
2006-10-18 21:47 603648 –a—— C:\WINDOWS\SYSTEM32\WMSPDMOD.dll
2006-10-18 21:47 542720 –a—— C:\WINDOWS\SYSTEM32\blackbox.dll
2006-10-18 21:47 535040 ——— C:\WINDOWS\SYSTEM32\wmdrmsdk.dll
2006-10-18 21:47 429056 –a—— C:\WINDOWS\SYSTEM32\wmdrmdev.dll
2006-10-18 21:47 414208 –a—— C:\WINDOWS\SYSTEM32\msscp.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\SYSTEM32\wmvdmoe2.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\SYSTEM32\wmvdmod.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\SYSTEM32\WMVADVE.DLL
2006-10-18 21:47 4096 –a—— C:\WINDOWS\SYSTEM32\WMVADVD.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\SYSTEM32\wmsdmoe2.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\SYSTEM32\wmsdmod.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\SYSTEM32\wdfapi.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\SYSTEM32\MPG4DMOD.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\SYSTEM32\MP4SDMOD.dll
2006-10-18 21:47 4096 –a—— C:\WINDOWS\SYSTEM32\MP43DMOD.dll
2006-10-18 21:47 38400 ——— C:\WINDOWS\SYSTEM32\wpdshextres.dll
2006-10-18 21:47 37376 –a—— C:\WINDOWS\SYSTEM32\wmdmps.dll
2006-10-18 21:47 35840 –a—— C:\WINDOWS\SYSTEM32\wpdconns.dll
2006-10-18 21:47 356352 –a—— C:\WINDOWS\SYSTEM32\wpdsp.dll
2006-10-18 21:47 348672 –a—— C:\WINDOWS\SYSTEM32\wmdrmnet.dll
2006-10-18 21:47 33792 –a—— C:\WINDOWS\SYSTEM32\wmdmlog.dll
2006-10-18 21:47 321536 –a—— C:\WINDOWS\SYSTEM32\mswmdm.dll
2006-10-18 21:47 317440 ——— C:\WINDOWS\SYSTEM32\MP4SDECD.dll
2006-10-18 21:47 314880 –a—— C:\WINDOWS\SYSTEM32\wmpdxm.dll
2006-10-18 21:47 295936 ——— C:\WINDOWS\SYSTEM32\wmpeffects.dll
2006-10-18 21:47 284160 ——— C:\WINDOWS\SYSTEM32\PortableDeviceApi.dll
2006-10-18 21:47 276992 –a—— C:\WINDOWS\SYSTEM32\audiodev.dll
2006-10-18 21:47 27136 –a—— C:\WINDOWS\SYSTEM32\mspmsnsv.dll
2006-10-18 21:47 2603008 ——— C:\WINDOWS\SYSTEM32\WpdShext.dll
2006-10-18 21:47 259072 ——— C:\WINDOWS\SYSTEM32\MPG4DECD.dll
2006-10-18 21:47 259072 ——— C:\WINDOWS\SYSTEM32\MP43DECD.dll
2006-10-18 21:47 2450944 –a—— C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-10-18 21:47 242688 –a—— C:\WINDOWS\SYSTEM32\wmpasf.dll
2006-10-18 21:47 229376 –a—— C:\WINDOWS\SYSTEM32\cewmdm.dll
2006-10-18 21:47 227328 –a—— C:\WINDOWS\SYSTEM32\wmerror.dll
2006-10-18 21:47 222208 –a—— C:\WINDOWS\SYSTEM32\WMASF.dll
2006-10-18 21:47 212992 ——— C:\WINDOWS\SYSTEM32\MFPLAT.dll
2006-10-18 21:47 211456 –a—— C:\WINDOWS\SYSTEM32\qasf.dll
2006-10-18 21:47 204288 –a—— C:\WINDOWS\SYSTEM32\wmpsrcwp.dll
2006-10-18 21:47 199168 ——— C:\WINDOWS\SYSTEM32\PortableDeviceWMDRM.dll
2006-10-18 21:47 179712 –a—— C:\WINDOWS\SYSTEM32\msnetobj.dll
2006-10-18 21:47 175616 –a—— C:\WINDOWS\SYSTEM32\mspmsp.dll
2006-10-18 21:47 166912 ——— C:\WINDOWS\SYSTEM32\PortableDeviceTypes.dll
2006-10-18 21:47 1661440 –a—— C:\WINDOWS\SYSTEM32\wmpencen.dll
2006-10-18 21:47 1574912 ——— C:\WINDOWS\SYSTEM32\WMVENCOD.dll
2006-10-18 21:47 157184 –a—— C:\WINDOWS\SYSTEM32\wmidx.dll
2006-10-18 21:47 154624 –a—— C:\WINDOWS\SYSTEM32\wpdmtp.dll
2006-10-18 21:47 1543680 ——— C:\WINDOWS\SYSTEM32\WMVDECOD.dll
2006-10-18 21:47 1382912 ——— C:\WINDOWS\SYSTEM32\WMVSDECD.dll
2006-10-18 21:47 133632 ——— C:\WINDOWS\SYSTEM32\WPDShServiceObj.dll
2006-10-18 21:47 1329152 –a—— C:\WINDOWS\SYSTEM32\WMSPDMOE.dll
2006-10-18 21:47 132096 ——— C:\WINDOWS\SYSTEM32\PortableDeviceWiaCompat.dll
2006-10-18 21:47 130048 ——— C:\WINDOWS\SYSTEM32\wmpps.dll
2006-10-18 21:47 11264 –a—— C:\WINDOWS\SYSTEM32\LAPRXY.dll
2006-10-18 21:47 1117696 –a—— C:\WINDOWS\SYSTEM32\WMADMOE.dll
2006-10-18 21:47 101888 ——— C:\WINDOWS\SYSTEM32\PortableDeviceClassExtension.dll
2006-10-18 20:03 100864 –a—— C:\WINDOWS\SYSTEM32\logagent.exe
2006-10-18 20:00 249856 ——— C:\WINDOWS\SYSTEM32\drmupgds.exe
2006-10-18 20:00 17408 ——— C:\WINDOWS\SYSTEM32\wpdshextautoplay.exe
2006-10-17 12:06 78336 –a—— C:\WINDOWS\SYSTEM32\ieencode.dll
2006-10-17 12:05 40960 –a—— C:\WINDOWS\SYSTEM32\licmgr10.dll
2006-10-17 12:05 206336 ——— C:\WINDOWS\SYSTEM32\WinFXDocObj.exe
2006-10-17 12:05 105984 –a—— C:\WINDOWS\SYSTEM32\url.dll
2006-10-17 12:04 101376 –a—— C:\WINDOWS\SYSTEM32\occache.dll
2006-10-17 12:03 17408 –a—— C:\WINDOWS\SYSTEM32\corpol.dll
2006-10-17 11:58 61952 ——— C:\WINDOWS\SYSTEM32\icardie.dll
2006-10-17 11:58 12288 ——— C:\WINDOWS\SYSTEM32\msfeedssync.exe
2006-10-17 11:57 36352 –a—— C:\WINDOWS\SYSTEM32\imgutil.dll
2006-10-17 11:57 266752 ——— C:\WINDOWS\SYSTEM32\iertutil.dll
2006-10-17 11:56 45568 –a—— C:\WINDOWS\SYSTEM32\mshta.exe
2006-10-17 11:28 48128 –a—— C:\WINDOWS\SYSTEM32\mshtmler.dll
2006-10-17 11:27 380928 ——— C:\WINDOWS\SYSTEM32\ieapfltr.dll
2006-10-13 06:35 142336 –a—— C:\WINDOWS\SYSTEM32\nwprovau.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Sonic RecordNow!"=""
"Steam"=""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.3640\\GoogleToolbarNotifier.exe"
"Weather"="C:\\PROGRA~1\\AWS\\WEATHE~1\\Weather.exe 1"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"MimBoot"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mimboot.exe"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1126834498\\ee\\AOLHostManager.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"NapsterShell"="C:\\Program Files\\Napster\\napster.exe /systray"
"WinPatrol"="C:\\Program Files\\BillP Studios\\WinPatrol\\winpatrol.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
"{FA010552-4A27-4cb1-A1BB-3E2D697F1639}"="SpySubtract Shell Extension"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"NoSaveSettings"=dword:00000000
"ClassicShell"=dword:00000000
"NoThemesTab"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=""
"NoDriveTypeAutoRun"=hex:5f,00,00,00
"NoCDBurning"=dword:00000000
"NoActiveDesktopChanges"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"



~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

backup-20070106-112005-189
O2 - BHO: (no name) - {4D39F094-D985-4F82-BCB4-37C7D402581A} - C:\WINDOWS\system32\MNUTILSE.DLL (file missing)
backup-20070106-112005-292
O4 - HKCU\..\Run: [aupd] C:\WINDOWS\system32\sywsvcs.exe
backup-20070106-112005-794
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
backup-20070106-112005-826
O4 - HKLM\..\Run: [0ce80c5c.dll] RUNDLL32.EXE 0ce80c5c.dll,b 16501328
backup-20051231-125101-225
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
backup-20051231-125101-219
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
backup-20051231-125101-556
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
backup-20051231-125101-170
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
backup-20051231-125101-903
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
backup-20051231-125101-341
R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = http://www.sharempeg.com/find/
backup-20051231-125101-267
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
backup-20051231-125101-871
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.sharempeg.com/find/
backup-20051231-125101-424
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = http://www.sharempeg.com/find/

Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\McAfee.com Update Check (D3DKLP31-Owner).job
C:\WINDOWS\tasks\McAfee.com Update Check (NATE-jill).job
C:\WINDOWS\tasks\McAfee.com Update Check (NATE-Josh).job
C:\WINDOWS\tasks\McAfee.com Update Check (NATE-Nate1).job
C:\WINDOWS\tasks\XoftSpy.job

Completion time: 07-01-06 12:04:22.45
C:\ComboFix.txt … 07-01-06 12:04


kaspersky report



KASPERSKY ONLINE SCANNER REPORT

















KASPERSKY ONLINE SCANNER REPORT

Saturday, January 06, 2007 2:03:06 PM

Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)

Kaspersky Online Scanner version: 5.0.83.0

Kaspersky Anti-Virus database last update: 6/01/2007

Kaspersky Anti-Virus database records: 242062























































Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true

Scan Target My Computer

A:\

C:\

D:\

E:\

Scan Statistics
Total number of scanned objects 103114
Number of viruses found 30
Number of infected objects 158 / 0
Number of suspicious objects 0
Duration of the scan process 01:08:28







































































































































































































































































































































































































































































Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\stat.class-c68d230-6efe5535.class Infected: Trojan.Java.Nocheat skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-66f3eebb-4674834b.zip/a.class Infected: Trojan.Java.ClassLoader.b skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-66f3eebb-4674834b.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-66f3eebb-4674834b.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.u skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-66f3eebb-4674834b.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-43f1f393.zip/a.class Infected: Trojan.Java.ClassLoader.b skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-43f1f393.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-43f1f393.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.u skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-43f1f393.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-421208e8-73f45132.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-421208e8-73f45132.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-421208e8-73f45132.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.d skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-421208e8-73f45132.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenStream.d skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-421208e8-73f45132.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-42120e89-5d427ed5.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-42120e89-5d427ed5.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-42120e89-5d427ed5.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.d skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-42120e89-5d427ed5.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenStream.d skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-42120e89-5d427ed5.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4f65e3a2-3cb2aca8.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4f65e3a2-3cb2aca8.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4f65e3a2-3cb2aca8.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4f65e3a2-3cb2aca8.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5157872c-614fb82d.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5157872c-614fb82d.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5157872c-614fb82d.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5157872c-614fb82d.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78ee691-15b3a7bb.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78ee691-15b3a7bb.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78ee691-15b3a7bb.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78ee691-15b3a7bb.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78eef63f-40efe173.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78eef63f-40efe173.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78eef63f-40efe173.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78eef63f-40efe173.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-7a8f2bcb-5bdfaff3.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-7a8f2bcb-5bdfaff3.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-7a8f2bcb-5bdfaff3.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-7a8f2bcb-5bdfaff3.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-1803745e-73ea8bac.zip/Beyond.class Infected: Trojan.Java.StartPage.m skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-1803745e-73ea8bac.zip/A.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-1803745e-73ea8bac.zip ZIP: infected - 2 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-511dfc2c-2f89d97a.zip/BlackBox.class Infected: Trojan.Java.ClassLoader.z skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-511dfc2c-2f89d97a.zip/VB.class Infected: Trojan.Java.ClassLoader.ak skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-511dfc2c-2f89d97a.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-511dfc2c-2f89d97a.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6c1459c8-788b1c0f.zip/BlackBox.class Infected: Trojan.Java.ClassLoader.z skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6c1459c8-788b1c0f.zip/VB.class Infected: Trojan.Java.ClassLoader.ak skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6c1459c8-788b1c0f.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6c1459c8-788b1c0f.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6cbdefdc-2781d1d2.zip/BlackBox.class Infected: Trojan.Java.ClassLoader.z skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6cbdefdc-2781d1d2.zip/VB.class Infected: Trojan.Java.ClassLoader.ak skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6cbdefdc-2781d1d2.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6cbdefdc-2781d1d2.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7a5f0150-60b62a25.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7a5f0150-60b62a25.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7a5f0150-60b62a25.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.d skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7a5f0150-60b62a25.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenStream.d skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7a5f0150-60b62a25.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-18524c9e.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-18524c9e.zip/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-18524c9e.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-18524c9e.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-18524c9e.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-75a26503.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-75a26503.zip/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify
Well, we need to do some cleaning up. I will reply. Your Kapersky log was cut off but since there were so many infected items, I will suggest some other scans that clean.

Saturday, January 06, 2007 2:03:06 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 6/01/2007
Kaspersky Anti-Virus database records: 242062


Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 103114
Number of viruses found 30
Number of infected objects 158 / 0
Number of suspicious objects 0
Duration of the scan process 01:08:28

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp Object is locked skipped

C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\stat.class-c68d230-6efe5535.class Infected: Trojan.Java.Nocheat skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-66f3eebb-4674834b.zip/a.class Infected: Trojan.Java.ClassLoader.b skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-66f3eebb-4674834b.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-66f3eebb-4674834b.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.u skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-66f3eebb-4674834b.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-43f1f393.zip/a.class Infected: Trojan.Java.ClassLoader.b skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-43f1f393.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-43f1f393.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.u skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-43f1f393.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-421208e8-73f45132.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-421208e8-73f45132.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-421208e8-73f45132.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.d skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-421208e8-73f45132.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenStream.d skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-421208e8-73f45132.zip ZIP: infected - 4 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-42120e89-5d427ed5.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-42120e89-5d427ed5.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-42120e89-5d427ed5.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.d skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-42120e89-5d427ed5.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenStream.d skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar.jar-42120e89-5d427ed5.zip ZIP: infected - 4 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4f65e3a2-3cb2aca8.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4f65e3a2-3cb2aca8.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4f65e3a2-3cb2aca8.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4f65e3a2-3cb2aca8.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5157872c-614fb82d.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5157872c-614fb82d.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5157872c-614fb82d.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5157872c-614fb82d.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78ee691-15b3a7bb.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78ee691-15b3a7bb.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78ee691-15b3a7bb.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78ee691-15b3a7bb.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78eef63f-40efe173.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78eef63f-40efe173.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78eef63f-40efe173.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-78eef63f-40efe173.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-7a8f2bcb-5bdfaff3.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-7a8f2bcb-5bdfaff3.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-7a8f2bcb-5bdfaff3.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-7a8f2bcb-5bdfaff3.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-1803745e-73ea8bac.zip/Beyond.class Infected: Trojan.Java.StartPage.m skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-1803745e-73ea8bac.zip/A.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-1803745e-73ea8bac.zip ZIP: infected - 2 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-511dfc2c-2f89d97a.zip/BlackBox.class Infected: Trojan.Java.ClassLoader.z skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-511dfc2c-2f89d97a.zip/VB.class Infected: Trojan.Java.ClassLoader.ak skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-511dfc2c-2f89d97a.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-511dfc2c-2f89d97a.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6c1459c8-788b1c0f.zip/BlackBox.class Infected: Trojan.Java.ClassLoader.z skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6c1459c8-788b1c0f.zip/VB.class Infected: Trojan.Java.ClassLoader.ak skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6c1459c8-788b1c0f.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6c1459c8-788b1c0f.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6cbdefdc-2781d1d2.zip/BlackBox.class Infected: Trojan.Java.ClassLoader.z skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6cbdefdc-2781d1d2.zip/VB.class Infected: Trojan.Java.ClassLoader.ak skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6cbdefdc-2781d1d2.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6cbdefdc-2781d1d2.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7a5f0150-60b62a25.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7a5f0150-60b62a25.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7a5f0150-60b62a25.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.d skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7a5f0150-60b62a25.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenStream.d skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7a5f0150-60b62a25.zip ZIP: infected - 4 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-18524c9e.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-18524c9e.zip/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-18524c9e.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-18524c9e.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-18524c9e.zip ZIP: infected - 4 skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-75a26503.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped

C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-11faa9ed-75a26503.zip/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify

Please post (reply) with a fresh hijackthis log.



New hijack:

Logfile of HijackThis v1.99.1
Scan saved at 1:33:41 AM, on 1/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Napster\napster.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\D-Link AirPlus\AirPlus.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\MSIMN.EXE
C:\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1126834498\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Deer Hunter 2005 Registration.lnk = C:\Program Files\Atari\Deer Hunter 2005\ATR1.EXE
O4 - Global Startup: D-Link AirPlus.lnk = ?
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164523961390
O20 - AppInit_DLLs:
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


Thanks for your help!!
Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Your scan showed one of more viruses in your Sun Java Runtime Environment (JRE) cache. Delete those by clearing the JRE cache.
http://support.f-secure.com/enu/home/virus…javacache.shtml
How to Clean a Java Cache Folder

In some rare cases a few infected files and archives with infected files are detected inside Java cache folder. The location of this folder usually is:
C:\Documents and Settings\\Application Data\Sun\Java\Deployment\cache\

In your case it is the following:
C:\Documents and Settings\Nate1\Application Data\Sun\Java\Deployment\cache\<=only delete files contained within cache folder (do not delete the cache folder!)

Removing infection
To empty the cache folder, access it with Windows Explorer. Select all files and subfolders and then press the "Delete" button on a keyboard, or select the File->Delete menu option. As this folder contains only cached files, no actual data is lost in the operation.

WARNING! Please be careful when deleting files.Make sure that you are deleting files only inside the Java cache folder, otherwise you may damage your system!

This scan works with Internet Explorer.

STEP 1.
======
Panda Active Scan
Please go to Panda ActiveScan.
Once you are on the Panda site click the Scan your PC button
A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on Local Disks to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, by using Add Reply.
Let us know if any problems persist.
panda:


Incident Status Location

Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\jill\Cookies\jill@advertising[1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\jill\Cookies\jill@apmebf[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\jill\Cookies\jill@doubleclick[2].txt
Virus:trj/jupillites.a Disinfected C:\Documents and Settings\Nate1\access
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Nate1\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Nate1\Desktop\smitRem.exe[smitRem/Process.exe]
Adware:adware/dollarrevenue Not disinfected C:\WINDOWS\drsmartloadb1.dat
Adware:adware/webattaker Not disinfected C:\WINDOWS\uniq
Hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 3:22:33 PM, on 1/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\D-Link AirPlus\AirPlus.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\winlogon.exe
C:\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1126834498\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Deer Hunter 2005 Registration.lnk = C:\Program Files\Atari\Deer Hunter 2005\ATR1.EXE
O4 - Global Startup: D-Link AirPlus.lnk = ?
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164523961390
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Please update your Java.

Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 6.0.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.

Please set your system to show all files; please see here if you're unsure how to do this.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\WINDOWS\drsmartloadb1.dat<=file
C:\WINDOWS\uniq<=file

Exit Explorer, and reboot as normal afterwards.

STEP 1.
======
Combofix
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Please post the ComboFix log and a new hijackthis log. How is your computer running now?
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI