This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis logs

122 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My apologies for gatecrashing this thread, but, as for that C:\WINDOWS\system\PDFAid.dll file, the chance it is really by Adobe as it wants you to believe is not great.

It could possibly be a parasite. Would you mind terribly going back to the SpyKiller forum and upload that file for analysis as well, so that we can make sure whether or not it really does belong on your computer?

Thanks a lot for your cooperation. :)
Thank you very much for submitting that file; it is most certainly a baddie, and related to the SVCH0ST.EXE file you were asked to delete previously.

Please run Hijack This, then check, and have it fix the following line:

O2 - BHO: IEHelp Class - {ED863792-FADB-4D21-8B20-409DA940B7A2} - C:\WINDOWS\system\PDFAid.dll


Then restart your computer, run HT once again, and post a fresh log for Mr_JAk3 to take a look at.

Thanks! :)
Hi, here is a fresh HJT log after the advise from TonyKlein:

Logfile of HijackThis v1.99.1
Scan saved at 3:24:43 PM, on 2/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe
C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe
C:\New Folder\NCHGBIOS2SVC.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\00THotkey.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shef.ac.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /runonce
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122799085395
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149591663124
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://lycosmail.lycos.com/hanmail-ax/AttachMail.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{518C1918-DA95-4A79-B798-B8C2D34F9ABA}: NameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{55C7B976-17A7-4768-A31A-8BCD308FA9B2}: NameServer = 192.168.2.1
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Erdas - Macrovision Corporation - C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe
O23 - Service: ESRI License Manager - Unknown owner - C:\Program Files\ESRI\License\lmgrd.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NCHGBIOS2SVC - TOSHIBA Corporation - C:\New Folder\NCHGBIOS2SVC.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Thank you. :)
Thank you very much Tony, I completely forgot the file :wall: @meehailam: Looks that we got rid of the service and HijackThis log is looking good too. I recommend that you update your Norton's definitions and run a full system scan. How is the computer running at the moment, any issues ? :thumbup:
Hi, the Norton return clean scanning, not a single suspicious thing at all. I tried AVG Anti-Spyware as well and here is the log (I didn't delete anything yet): C:\Documents and Settings\Lam\Desktop\requested-files[2007-02-11_11_46].cab/C:\WINDOWS\system32\drivers\feachida.sys -> Adware.BDSearch : No action taken. C:\Documents and Settings\Lam\DoctorWeb\Quarantine\A0102469.sys -> Adware.BDSearch : No action taken. C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP185\A0104487.sys -> Adware.BDSearch : No action taken. C:\Documents and Settings\Lam\Desktop\requested-files[2007-02-11_11_46].cab/C:\WINDOWS\system32\wbem\setupcnn.exe -> Adware.Cdnup : No action taken. C:\Documents and Settings\Lam\DoctorWeb\Quarantine\A0102470.exe -> Adware.Cdnup : No action taken. C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP185\A0104489.exe -> Adware.Cdnup : No action taken. C:\_OTMoveIt\MovedFiles\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll -> Adware.Cinmus : No action taken. C:\Documents and Settings\Lam\DoctorWeb\Quarantine\A0102468.dll -> Adware.Minibug : No action taken. C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\SSVDWBKU\stat[1].htm -> Downloader.AQM : No action taken. C:\Documents and Settings\Lam\DoctorWeb\Quarantine\A0102545.exe -> Downloader.QQHelper.da : No action taken. C:\Documents and Settings\Lam\Desktop\requested-files[2007-02-11_11_46].cab/C:\WINDOWS\system32\drivers\nwlnksipx.sys -> Hijacker.StartPage.amo : No action taken. C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP185\A0104488.sys -> Hijacker.StartPage.amo : No action taken. C:\Documents and Settings\Lam\Cookies\lam@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Lam\Cookies\lam@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken. C:\Documents and Settings\Lam\Cookies\lam@advertising[2].txt -> TrackingCookie.Advertising : No action taken. C:\Documents and Settings\Lam\Cookies\lam@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken. C:\Documents and Settings\Lam\Cookies\lam@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken. C:\Documents and Settings\Lam\Cookies\lam@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken. C:\Documents and Settings\Lam\Cookies\lam@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken. C:\Documents and Settings\Lam\Cookies\[removed][2].txt -> TrackingCookie.Onestat : No action taken. C:\Documents and Settings\Lam\Cookies\lam@overture[1].txt -> TrackingCookie.Overture : No action taken. C:\Documents and Settings\Lam\Cookies\lam@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken. C:\Documents and Settings\Lam\Cookies\lam@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken. C:\Documents and Settings\Lam\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : No action taken. So far the laptop is working smoothly and speed is good. BTW, I have an external hardisk which from the kaspersky scan showed some infection in the D:\System Volume Information\_restore {…..} blahblahblah… So if I connect it to my laptop will it affect or infect the system again? I will post a new HJT for my wife's computer together with the external hardisk attach in a new thread soon. Thanks. :)
Ok good :)

The System Restore can easily be cleaned (Check the stay clean instructions below)

Run ATF Cleaner Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Now you can clean AVG's Quarantine:
  • Open AVG Anti-Spyware
  • Click Infections
  • Click Quarantine tab
  • Click Select all
  • Click Remove finally
  • Close the program
You can remove the tools we used.
You can delete the following backup folders and that cab file:
C:\Documents and Settings\Lam\Desktop\requested-files[2007-02-11_11_46].cab
C:\Documents and Settings\Lam\DoctorWeb\Quarantine
C:\_OTMoveIt

Now you can make your hidden files hidden again.
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Check "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.
=============

Now that you seem to be clean, please follow these simple steps in order to keep your computer clean and secure:
  • Clear your system restore
    This will clear the system restore folders from possible malware that was left behind during the cleaning process.
  • Use ATF Cleaner
    Download and install ATF Cleaner. Clean your temporary files & folders with it regularly.
  • Use Ad-Aware
    Download and install Ad-Aware. Update it and scan your computer regularly with it.
  • Use AVG Anti-Spyware
    Update it and scan your computer regularly with it.
  • Use Spybot S&D
    Download and install Spybot S&D. Update it and scan your computer regularly with it.
  • Install SpywareBlaster
    SpywareBlaster will prevent spyware from being installed.
  • Install MVPS Hosts file
    This prevents your computer from connecting to harmful sites.
  • Use Firefox browser
    Firefox is faster, safer and better browser than Internet Explorer.
  • Keep your systen up-to-date
    Visit Windows Update regularly.
  • Keep your antivirus and firewall up-to-date
    Scan your computer regularly with your antivirus.
  • Read this article by TonyKlein
    So how did I get infected in the first place?
  • Stand Up and Be Counted !
    The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.
Stay clean and be safe ;)
Hi, one last one… I can't remove the C:\_OTMoveIt folder or its contents. Still having problem with the 'pctools' thing. Any other way that I can try? Thanks. :)
Hi :) So pctools doesn't want to go away ? You mean the file inside OTMoveIt folder ? Please try to delete it in safe mode and let me know the results :)
Hi, yes the 'pctools.dll' inside the OTMoveIt folder can't be removed. Either deleting the whole folder or the pctools.dll file will return massage "Cannot delete pctools.dll: Access denied". Even in safe mode. Seems like a naughty one…let me know if you can think of some way to deal with it. Thanks.
Very interesting :)

Could you please run a new registry search with the tool that we used earlier.
Run a search for these:

pctools.dll
385AB8C6-FB22-4D17-8834-064E2BA0A6F0

Post the results to here when ready :thumbup:
Hi, here are the results: REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "pctools.dll" 2/13/2007 8:28:02 PM ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{385AB8C6-FB22-4D17-8834-064E2BA0A6F0}\InprocServer32] @="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\PCTools\\pctools.dll" REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "385AB8C6-FB22-4D17-8834-064E2BA0A6F0" 2/13/2007 8:51:05 PM ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{385AB8C6-FB22-4D17-8834-064E2BA0A6F0}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{385AB8C6-FB22-4D17-8834-064E2BA0A6F0}\InprocServer32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{385AB8C6-FB22-4D17-8834-064E2BA0A6F0}\TypeLib] Thanks. Should nail it this time :)
Hi :)

Ok looks that there is something…

Backup your registry:
  • Start
  • Run
  • Type the following to the box and hit Ok: regedit
  • A window opens, click on File
  • Choose Export form the menu
  • Change the save location to C:\
  • Give the filename, RegBackUp
  • Make sure that the filetype is set to Registryfiles (*.reg)
  • Click on Save and Close the window
Open Notepad (NOT WORDPAD!) and copy the following lines from the quote box below into a new document, leaving a blank line at the end. (don't forget to copy and paste the word REGEDIT4) :

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{385AB8C6-FB22-4D17-8834-064E2BA0A6F0}]


Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

Save the document to your desktop as Fix.reg and filetype: All Files
Go to your desktop and double click on the file to run Fix.reg and when it asks you if you want to merge the contents to the registry, click yes/ok.

Please run ComboFix again and post the fresh log to here :thumbup:
Hi, done as instructed and here is the Combofix's log:

"Lam" - 07-02-14 11:57:02 Service Pack 2
ComboFix 07-02-11 - Running from: "C:\Documents and Settings\Lam\My Documents\For HJT"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

C:\WINDOWS\system32\advport.dll
C:\WINDOWS\system32\Score.txt
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools

((((((((((((((((((((((((((((((( Files Created from 2007-01-14 to 2007-02-14 ))))))))))))))))))))))))))))))))))

2007-02-12 23:17 57,344 –a—— C:\WINDOWS\CTREBOOT.EXE
2007-02-09 21:47 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Nero
2007-02-09 16:25 d——– C:\Program Files\Nero
2007-02-08 11:17 d——– C:\_OTMoveIt
2007-02-06 10:57 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-02-05 15:10 80 –a—— C:\WINDOWS\gmer_uninstall.cmd
2007-02-05 15:09 405,504 –a—— C:\WINDOWS\system\WINS0CK32.dll
2007-02-05 14:05 d——– C:\Program Files\Sunbelt Software
2007-02-04 16:29 d——– C:\DOCUME~1\Lam\DoctorWeb
2007-02-02 20:32 15,760 –a—— C:\RegBackUp.reg
2007-02-02 20:24 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-02 20:23 d——– C:\Program Files\Grisoft
2007-02-02 10:36 d——– C:\WINDOWS\system32\ActiveScan
2007-02-01 09:58 98,304 –a—— C:\WINDOWS\system32\MScff1.exe
2007-02-01 09:58 98,304 –a—— C:\WINDOWS\system\PDFAid.dll
2007-02-01 09:58 405,504 –a—— C:\WINDOWS\MSd89.dll
2007-02-01 09:58 22 –a—— C:\WINDOWS\system32\drivers\MS884.sys
2007-02-01 09:58 d——– C:\WINDOWS\cursor
2007-02-01 09:58 d——– C:\DOCUME~1\ALLUSE~1\Application Data\g
2007-01-29 10:29 d——– C:\WINDOWS\erdnt
2007-01-28 22:17 d——– C:\Program Files\Hijackthis
2007-01-28 22:15 d——– C:\HJT
2007-01-28 20:43 d——– C:\Program Files\Registry Mechanic
2007-01-28 19:20 8 -r-hs—- C:\WINDOWS\system32\432282CA19.sys
2007-01-28 18:43 d——– C:\Program Files\WinHTTrack
2007-01-27 01:09 20 —h—– C:\DOCUME~1\ALLUSE~1\Application Data\PKP_DLbz.DAT
2007-01-27 01:09 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Logs
2007-01-24 09:24 d——– C:\DOCUME~1\ALLUSE~1\Application Data\espionServerData
2007-01-16 08:45 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-01-14 12:54 9,175,040 –a—— C:\DOCUME~1\Lam\ntuser.dat
2007-01-14 12:54 237,568 –a—— C:\DOCUME~1\LOCALS~1\ntuser.dat

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-02-14 12:08 ——– d——– C:\Program Files\symantec antivirus
2007-02-14 11:38 ——– d——– C:\Documents and Settings\Lam\Application Data\skype
2007-02-09 21:04 ——– d——– C:\Program Files\Common Files\symantec shared
2007-02-09 20:11 ——– d——– C:\Program Files\flashget
2007-02-09 12:04 ——– d——– C:\Program Files\freecommander
2007-02-05 23:20 ——– d——– C:\Program Files\emule
2007-02-02 11:54 ——– d——– C:\Program Files\save flash
2007-01-29 16:52 ——– d——– C:\Program Files\selteco
2007-01-28 19:25 7362 –ahsc— C:\WINDOWS\system32\kgygaavl.sys
2007-01-28 19:15 ——– d–h—– C:\Program Files\installshield installation information
2007-01-28 19:15 ——– d——– C:\Program Files\fileamigo 6.0
2007-01-28 19:03 ——– d——– C:\Documents and Settings\Lam\Application Data\toshiba
2007-01-28 18:54 ——– d——– C:\Program Files\mp3 file editor
2007-01-28 18:42 ——– d——– C:\Program Files\Common Files\adobe
2007-01-28 18:42 ——– d——– C:\Documents and Settings\Lam\Application Data\adobe
2007-01-27 16:33 268 -r-h—– C:\Documents and Settings\Lam\Application Data\stingers
2007-01-27 01:08 ——– d——– C:\Documents and Settings\Lam\Application Data\nikon
2007-01-27 00:54 ——– d——– C:\Program Files\Common Files\nikon
2007-01-27 00:53 ——– d——– C:\Program Files\nikon
2007-01-16 08:40 ——– d——– C:\Documents and Settings\Lam\Application Data\adobeum
2007-01-04 15:39 1024 –a—— C:\WINDOWS\system32\pdf2word.dat
2007-01-04 15:38 ——– d——– C:\Program Files\pdf2word v1.4
2006-12-07 05:29 2374472 –a—— C:\WINDOWS\system32\wmvcore.dll

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"LogitechSoftwareUpdate"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"SmoothView"="C:\\Program Files\\TOSHIBA\\TOSHIBA Zooming Utility\\SmoothView.exe"
"SigmaTel StacMon"="C:\\Program Files\\SigmaTel\\SigmaTel AC97 Audio Drivers\\stacmon.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Enterprise"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"PadTouch"="C:\\Program Files\\TOSHIBA\\Touch and Launch\\PadExe.exe"
"00THotkey"="C:\\WINDOWS\\system32\\00THotkey.exe"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe"
"pdfFactory Pro Dispatcher v2"="\"C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\fppdis2a.exe\" /runonce"
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"KernelFaultCheck"="%systemroot%\\system32\\dumprep 0 -k"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^blueyonder Instant Support Tool.lnk]
"backup"="C:\\WINDOWS\\pss\\blueyonder Instant Support Tool.lnkCommon Startup"
"location"="Common Startup"
"item"="blueyonder Instant Support Tool"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Cisco Systems VPN Client.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Cisco Systems VPN Client.lnk"
"backup"="C:\\WINDOWS\\pss\\Cisco Systems VPN Client.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\CISCOS~1\\VPNCLI~1\\vpngui.exe \"-user_logon\""
"item"="Cisco Systems VPN Client"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
"backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup"
"location"="Common Startup"
"item"="Logitech Desktop Messenger"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="\"C:\\Program Files\\Microsoft Office\\Office\\OSA9.EXE\" -b -l"
"item"="Microsoft Office"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkvMon.exe.lnk]
"backup"="C:\\WINDOWS\\pss\\NkvMon.exe.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Nikon\\NkView5\\NkvMon.exe "
"item"="NkvMon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lam^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Microsoft Office OneNote 2003 Quick Launch.lnkStartup"
"location"="Startup"
"command"="\"C:\\Program Files\\Microsoft Office\\OFFICE11\\ONENOTEM.EXE\" /tsr"
"item"="Microsoft Office OneNote 2003 Quick Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\000StTHK]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="000StTHK"
"hkey"="HKLM"
"command"="000StTHK.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AGRSMMSG"
"hkey"="HKLM"
"command"="AGRSMMSG.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Apoint"
"hkey"="HKLM"
"command"="C:\\Program Files\\Apoint2K\\Apoint.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="InCD"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPrint Tray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iPrint Tray"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\iprntctl.exe TRAY_ICON"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LanguageShortcut"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BackWeb-8876480"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ManifestEngine"
"hkey"="HKCU"
"inimapping"="0"
"command"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ISStart"
"hkey"="HKLM"
"inimapping"="0"
"command"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LogiTray"
"hkey"="HKLM"
"inimapping"="0"
"command"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LVCOMSX"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="blueyonder-istnotifier"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Pro Dispatcher v2]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pdfFactory Pro Dispatcher v2"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\fppdis2a.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegClean Expert Scheduler]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RegClean Expert Scheduler"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RemoteControl"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Skype"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFNF5]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TFNF5"
"hkey"="HKLM"
"command"="TFNF5.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TkBellExe"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TOSCDSPD"
"hkey"="HKCU"
"command"="C:\\Program Files\\TOSHIBA\\TOSCDSPD\\toscdspd.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TouchED]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TouchED"
"hkey"="HKLM"
"command"="C:\\Program Files\\TOSHIBA\\TouchED\\TouchED.Exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TPSMain"
"hkey"="HKLM"
"command"="TPSMain.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="updateMgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_8 -reboot 1"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UUPLAYER]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UUPlayer"
"hkey"="HKLM"
"command"="C:\\Program Files\\UUSee\\\\UUPlayer.exe -v vermini_x_hy.ini"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Workflow]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Workflow"
"hkey"="HKLM"
"command"="D:\\Workflow.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ypager"
"hkey"="HKCU"
"command"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="Eudora's Shell Extension"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ C:\Documents and Settings\Lam\My Documents\Digi Cam Picture\New Folder\DSCN6494.JPG

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0

HKLM\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
Live

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{233e5c60-9086-11db-b755-000cf153e66d}]
Shell\Auto\command AdobeR.exe e
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …
scanning hidden services …
scanning hidden autostart entries …
scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************
Completion time: 07-02-14 12:11:09
C:\ComboFix2.txt … 07-01-29 10:45
Hi :)

Ok there are still some files that don't look clean. Let's see what we can find.

Make your hidden files visible:
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Uncheck "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.
Go to virustotal.com
Copy the following to the box next to "Browse" button:
C:\WINDOWS\system32\MScff1.exe
Click on Send
Wait for the scan to end.

Scan these files too:
C:\WINDOWS\MSd89.dll
C:\WINDOWS\system32\drivers\MS884.sys

Post the results to here.

Then please see if there are files/folders inside these two folders:

C:\WINDOWS\cursor
C:\Documents and Settings\All Users\Application Data\g

Please list some files names if there aren't too many of them.
Hi, here are the logs: Complete scanning result of "MScff1.exe", received in VirusTotal at 02.14.2007, 22:49:22 (CET). Antivirus Version Update Result AntiVir 7.3.1.37 02.14.2007 ADSPY/PDFAid.A Authentium 4.93.8 02.14.2007 no virus found Avast 4.7.936.0 02.14.2007 no virus found AVG 386 02.14.2007 no virus found BitDefender 7.2 02.14.2007 no virus found CAT-QuickHeal 9.00 02.14.2007 no virus found ClamAV devel-20060426 02.14.2007 no virus found DrWeb 4.33 02.14.2007 no virus found eSafe 7.0.14.0 02.14.2007 no virus found eTrust-Vet 30.4.3397 02.14.2007 no virus found Ewido 4.0 02.14.2007 Adware.PDFAid Fortinet 2.85.0.0 02.14.2007 no virus found F-Prot 4.2.1.29 02.14.2007 no virus found F-Secure 6.70.13030.0 02.14.2007 no virus found Ikarus T3.1.0.31 02.14.2007 no virus found Kaspersky 4.0.2.24 02.14.2007 no virus found McAfee 4963 02.14.2007 no virus found Microsoft 1.2204 02.14.2007 no virus found NOD32v2 2061 02.14.2007 no virus found Norman 5.80.02 02.14.2007 no virus found Panda 9.0.0.4 02.14.2007 Suspicious file Prevx1 V2 02.14.2007 no virus found Sophos 4.14.0 02.13.2007 no virus found Sunbelt 2.2.907.0 02.09.2007 no virus found Symantec 10 02.14.2007 no virus found TheHacker 6.1.6.057 02.11.2007 no virus found UNA 1.83 02.14.2007 no virus found VBA32 3.11.2 02.14.2007 no virus found VirusBuster 4.3.19:9 02.14.2007 no virus found Aditional Information File size: 98304 bytes MD5: dc3d7df382584e1b79432c3c02693eb4 SHA1: 184739156022a034185b52e1b5f8576ccd5dbe90 Complete scanning result of "MSd89.dll", received in VirusTotal at 02.14.2007, 22:54:40 (CET). Antivirus Version Update Result AntiVir 7.3.1.37 02.14.2007 no virus found Authentium 4.93.8 02.14.2007 no virus found Avast 4.7.936.0 02.14.2007 no virus found AVG 386 02.14.2007 no virus found BitDefender 7.2 02.14.2007 no virus found CAT-QuickHeal 9.00 02.14.2007 no virus found ClamAV devel-20060426 02.14.2007 no virus found DrWeb 4.33 02.14.2007 no virus found eSafe 7.0.14.0 02.14.2007 no virus found eTrust-Vet 30.4.3397 02.14.2007 no virus found Ewido 4.0 02.14.2007 no virus found Fortinet 2.85.0.0 02.14.2007 no virus found F-Prot 4.2.1.29 02.14.2007 no virus found F-Secure 6.70.13030.0 02.14.2007 no virus found Ikarus T3.1.0.31 02.14.2007 no virus found Kaspersky 4.0.2.24 02.14.2007 not-a-virus:AdWare.Win32.Agent.bx McAfee 4963 02.14.2007 no virus found Microsoft 1.2204 02.14.2007 no virus found NOD32v2 2061 02.14.2007 no virus found Norman 5.80.02 02.14.2007 no virus found Panda 9.0.0.4 02.14.2007 no virus found Prevx1 V2 02.14.2007 no virus found Sophos 4.14.0 02.13.2007 no virus found Sunbelt 2.2.907.0 02.09.2007 no virus found Symantec 10 02.14.2007 no virus found TheHacker 6.1.6.057 02.14.2007 no virus found UNA 1.83 02.14.2007 no virus found VBA32 3.11.2 02.14.2007 no virus found VirusBuster 4.3.19:9 02.14.2007 no virus found Aditional Information File size: 405504 bytes MD5: e8d7e61f8f3ccd79ca5fc54c8f72c9b0 SHA1: 8d1d1f6bf01e3a20901f962b45e320a1a8a73cf9 Complete scanning result of "MS884.sys", received in VirusTotal at 02.14.2007, 23:01:09 (CET). Antivirus Version Update Result AntiVir 7.3.1.37 02.14.2007 no virus found Authentium 4.93.8 02.14.2007 no virus found Avast 4.7.936.0 02.14.2007 no virus found AVG 386 02.14.2007 no virus found BitDefender 7.2 02.14.2007 no virus found CAT-QuickHeal 9.00 02.14.2007 no virus found ClamAV devel-20060426 02.14.2007 no virus found DrWeb 4.33 02.14.2007 no virus found eSafe 7.0.14.0 02.14.2007 no virus found eTrust-Vet 30.4.3397 02.14.2007 no virus found Ewido 4.0 02.14.2007 no virus found Fortinet 2.85.0.0 02.14.2007 no virus found F-Prot 4.2.1.29 02.14.2007 no virus found F-Secure 6.70.13030.0 02.14.2007 no virus found Ikarus T3.1.0.31 02.14.2007 no virus found Kaspersky 4.0.2.24 02.14.2007 no virus found McAfee 4963 02.14.2007 no virus found Microsoft 1.2204 02.14.2007 no virus found NOD32v2 2061 02.14.2007 no virus found Norman 5.80.02 02.14.2007 no virus found Panda 9.0.0.4 02.14.2007 no virus found Prevx1 V2 02.14.2007 no virus found Sophos 4.14.0 02.13.2007 no virus found Sunbelt 2.2.907.0 02.09.2007 no virus found Symantec 10 02.14.2007 no virus found TheHacker 6.1.6.057 02.11.2007 no virus found UNA 1.83 02.14.2007 no virus found VBA32 3.11.2 02.14.2007 no virus found VirusBuster 4.3.19:9 02.14.2007 no virus found Aditional Information File size: 22 bytes MD5: bf96650a880469fd10d6a436783f45e5 SHA1: d82127d973d4989b650c64eea50d65c0178bd40d In C:\WINDOWS\cursor there is only 1 file which is MS15 (file type = 'cursor', size = 1kb). I send it to virustotal for scanning as well: Complete scanning result of "cursor", received in VirusTotal at 02.14.2007, 23:30:29 (CET). Antivirus Version Update Result AntiVir 7.3.1.37 02.14.2007 no virus found Authentium 4.93.8 02.14.2007 no virus found Avast 4.7.936.0 02.14.2007 no virus found AVG 386 02.14.2007 no virus found BitDefender 7.2 02.14.2007 no virus found CAT-QuickHeal 9.00 02.14.2007 no virus found ClamAV devel-20060426 02.14.2007 no virus found DrWeb 4.33 02.14.2007 no virus found eSafe 7.0.14.0 02.14.2007 no virus found eTrust-Vet 30.4.3397 02.14.2007 no virus found Ewido 4.0 02.14.2007 no virus found Fortinet 2.85.0.0 02.14.2007 no virus found F-Prot 4.2.1.29 02.14.2007 no virus found F-Secure 6.70.13030.0 02.14.2007 no virus found Ikarus T3.1.0.31 02.14.2007 no virus found Kaspersky 4.0.2.24 02.14.2007 no virus found McAfee 4963 02.14.2007 no virus found Microsoft 1.2204 02.14.2007 no virus found NOD32v2 2061 02.14.2007 no virus found Norman 5.80.02 02.14.2007 no virus found Panda 9.0.0.4 02.14.2007 no virus found Prevx1 V2 02.14.2007 no virus found Sophos 4.14.0 02.13.2007 no virus found Sunbelt 2.2.907.0 02.09.2007 no virus found Symantec 10 02.14.2007 no virus found TheHacker 6.1.6.057 02.14.2007 no virus found UNA 1.83 02.14.2007 no virus found VBA32 3.11.2 02.14.2007 no virus found VirusBuster 4.3.19:9 02.14.2007 no virus found Aditional Information File size: 0 bytes MD5: d41d8cd98f00b204e9800998ecf8427e SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709 In C:\Documents and Settings\All Users\Application Data\g have 1 empty folder named 'd' and files are f1.3, h1.3, i1.3 (all are of file type = '3 File', all are also 1kb size) Complete scanning result of "f1.3", received in VirusTotal at 02.14.2007, 23:09:16 (CET). Antivirus Version Update Result AntiVir 7.3.1.37 02.14.2007 no virus found Authentium 4.93.8 02.14.2007 no virus found Avast 4.7.936.0 02.14.2007 no virus found AVG 386 02.14.2007 no virus found BitDefender 7.2 02.14.2007 no virus found CAT-QuickHeal 9.00 02.14.2007 no virus found ClamAV devel-20060426 02.14.2007 no virus found DrWeb 4.33 02.14.2007 no virus found eSafe 7.0.14.0 02.14.2007 no virus found eTrust-Vet 30.4.3397 02.14.2007 no virus found Ewido 4.0 02.14.2007 no virus found Fortinet 2.85.0.0 02.14.2007 no virus found F-Prot 4.2.1.29 02.14.2007 no virus found F-Secure 6.70.13030.0 02.14.2007 no virus found Ikarus T3.1.0.31 02.14.2007 no virus found Kaspersky 4.0.2.24 02.14.2007 no virus found McAfee 4963 02.14.2007 no virus found Microsoft 1.2204 02.14.2007 no virus found NOD32v2 2061 02.14.2007 no virus found Norman 5.80.02 02.14.2007 no virus found Panda 9.0.0.4 02.14.2007 no virus found Prevx1 V2 02.14.2007 no virus found Sophos 4.14.0 02.13.2007 no virus found Sunbelt 2.2.907.0 02.09.2007 no virus found Symantec 10 02.14.2007 no virus found TheHacker 6.1.6.057 02.14.2007 no virus found UNA 1.83 02.14.2007 no virus found VBA32 3.11.2 02.14.2007 no virus found VirusBuster 4.3.19:9 02.14.2007 no virus found Aditional Information File size: 128 bytes MD5: b8d23b4274b4fc30fb60e509ff8bf369 SHA1: bf492fbdd1b8cd323254de924cd056ee3e5ca30a Complete scanning result of "h1.3", received in VirusTotal at 02.14.2007, 23:18:28 (CET). Antivirus Version Update Result AntiVir 7.3.1.37 02.14.2007 no virus found Authentium 4.93.8 02.14.2007 no virus found Avast 4.7.936.0 02.14.2007 no virus found AVG 386 02.14.2007 no virus found BitDefender 7.2 02.14.2007 no virus found CAT-QuickHeal 9.00 02.14.2007 no virus found ClamAV devel-20060426 02.14.2007 no virus found DrWeb 4.33 02.14.2007 no virus found eSafe 7.0.14.0 02.14.2007 no virus found eTrust-Vet 30.4.3397 02.14.2007 no virus found Ewido 4.0 02.14.2007 no virus found Fortinet 2.85.0.0 02.14.2007 no virus found F-Prot 4.2.1.29 02.14.2007 no virus found F-Secure 6.70.13030.0 02.14.2007 no virus found Ikarus T3.1.0.31 02.14.2007 no virus found Kaspersky 4.0.2.24 02.14.2007 no virus found McAfee 4963 02.14.2007 no virus found Microsoft 1.2204 02.14.2007 no virus found NOD32v2 2061 02.14.2007 no virus found Norman 5.80.02 02.14.2007 no virus found Panda 9.0.0.4 02.14.2007 no virus found Prevx1 V2 02.14.2007 no virus found Sophos 4.14.0 02.13.2007 no virus found Sunbelt 2.2.907.0 02.09.2007 no virus found Symantec 10 02.14.2007 no virus found TheHacker 6.1.6.057 02.14.2007 no virus found UNA 1.83 02.14.2007 no virus found VBA32 3.11.2 02.14.2007 no virus found VirusBuster 4.3.19:9 02.14.2007 no virus found Aditional Information File size: 180 bytes MD5: 1f767f0d3040a016bd2f2a44d54f7707 SHA1: efa769aeafe76aca5f141b3fba29357671a4f334 Complete scanning result of "i1.3", received in VirusTotal at 02.14.2007, 23:22:23 (CET). Antivirus Version Update Result AntiVir 7.3.1.37 02.14.2007 no virus found Authentium 4.93.8 02.14.2007 no virus found Avast 4.7.936.0 02.14.2007 no virus found AVG 386 02.14.2007 no virus found BitDefender 7.2 02.14.2007 no virus found CAT-QuickHeal 9.00 02.14.2007 no virus found ClamAV devel-20060426 02.14.2007 no virus found DrWeb 4.33 02.14.2007 no virus found eSafe 7.0.14.0 02.14.2007 no virus found eTrust-Vet 30.4.3397 02.14.2007 no virus found Ewido 4.0 02.14.2007 no virus found Fortinet 2.85.0.0 02.14.2007 no virus found F-Prot 4.2.1.29 02.14.2007 no virus found F-Secure 6.70.13030.0 02.14.2007 no virus found Ikarus T3.1.0.31 02.14.2007 no virus found Kaspersky 4.0.2.24 02.14.2007 no virus found McAfee 4963 02.14.2007 no virus found Microsoft 1.2204 02.14.2007 no virus found NOD32v2 2061 02.14.2007 no virus found Norman 5.80.02 02.14.2007 no virus found Panda 9.0.0.4 02.14.2007 no virus found Prevx1 V2 02.14.2007 no virus found Sophos 4.14.0 02.13.2007 no virus found Sunbelt 2.2.907.0 02.09.2007 no virus found Symantec 10 02.14.2007 no virus found TheHacker 6.1.6.057 02.14.2007 no virus found UNA 1.83 02.14.2007 no virus found VBA32 3.11.2 02.14.2007 no virus found VirusBuster 4.3.19:9 02.14.2007 no virus found Aditional Information File size: 880 bytes MD5: 23aa84e3f471dbd402957c7b0b616f0f SHA1: a8ff53d8d7aa1574e5ddefe4edcaff4387b30b32 Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI