Hi, I've been doing scans on my computer with AVG Anti-spyware. It generally dectects one or two after the scan, but if I quarantine or delete the trojan I get a RUNDLL error every time I start up or reboot. I used system restore to restore it to a earlier time, but the virus scan shows the trojan is still there.
Thanks, Tom.
Here is my HiJackThis log
Logfile of HijackThis v1.99.1
Scan saved at 1:25:10 AM, on 3/17/2007
Platform: Windows XP SP2, v.2149 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2149)
I am currently looking over your log. As I am an Undergraduate, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.
First, there are a few very important security program that you are In need of. These programs are essential to prevent you from getting reinfected:
* Use an Anti Virus Software - It is very important that your computer has an anti-virus software running on your machine. Please download and install one antivirus program from the following list, download the latest signatures, and do a full system scan.
o AVG Anti-Virus
o Avast Home Edition
* Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check http://www.bleepingcomputer.com/tutorials/tutorial60.html]This webpage out. 2 free ones available for personal use:
Without these programs, you will be quickly reinfected, and we would just be wasting our time trying to clean your computer.
_________________
Download "FindAWF"
Save to desktop and run. Output is to awf.txt
If a DOS window does not stay open throughout the search (approx a minute) you need to change how the program runs. Heres how:
1. Locate the file
2. Right-click and select Properties
3. Select Compatibility and select Run this program in compatibility mode for: Windows 98/Windows ME and click OK.
4. The tool should now work.
Please include new HJT log, awf txt
in your next post
Thanks dan
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
278528 Feb 23 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
163840 May 15 2003 "C:\Program Files\Microsoft IntelliPoint\bak\point32.exe"
155648 Mar 5 2006 "C:\Program Files\QuickTime\bak\qttask.exe"
155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
504080 Apr 6 2004 "C:\Program Files\CA\eTrust Antivirus\bak\realmon.exe"
131072 Dec 20 2004 "C:\Program Files\NVIDIA Corporation\NvMixer\bak\NVMixerTray.exe"
end of report
————————————————————————————————————————
Here is the new Hijackthis post
Logfile of HijackThis v1.99.1
Scan saved at 5:46:10 PM, on 3/17/2007
Platform: Windows XP SP2, v.2149 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2149)
If you get any warnings about the script; let it run.
Once scan is done it will tell you.
Log is called "startup programs + time/date/computername.txt" is created in c:\
_____________
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.
Open the extracted SDFix folder and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
post me the silent runners log and the Report.txt from
Thanks dan
"Silent Runners.vbs", revision R50, http://www.silentrunners.org/
Operating System: Windows XP
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
———————————
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = ""C:\PROGRA~1\COMMON~1\Ahead\Lib\NMBGMO~1.EXE"" [file not found]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{00534B55-3155-CA4F-B41D-0E922121D03C}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Shell Event Object Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\cscentfy.dll" [MS]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Adobe PDF Reader Link Helper"
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
-> {HKLM…CLSID} = "SSVHelper Class"
\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll" ["Sun Microsystems, Inc."]
{D38439EC-4A7F-42b4-90C2-D810D7778FDD}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\tmp8D.tmp.dll" [file not found]
{f01ac5b4-d989-4db8-af1c-1dda0c18d6a3}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\gpkuse.dll" [null data]
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}
Active Desktop and Wallpaper:
—————————–
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Tom\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"
Startup items in "Tom" & "All Users" startup folders:
—————————————————–
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]
"Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS]
"University of Colorado at Boulder VPN Client" -> shortcut to: "C:\Program Files\CU VPN\vpngui.exe "-user_logon"" ["Cisco Systems, Inc."]
———-
<>: Suspicious data at a malware launch point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 32 seconds.
———- (total run time: 68 seconds)
——————————————————————————————————————
Here's the Report.txt
SDFix: Version 1.73
Run by [removed]
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
MsaSvc
Path:
C:\WINDOWS\system32\msasvc.exe
MsaSvc Deleted
Restoring Windows Registry Entries
Restoring Default Hosts File
Rebooting…
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
Logfile of HijackThis v1.99.1
Scan saved at 1:51:45 PM, on 3/18/2007
Platform: Windows XP SP2, v.2149 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2149)
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
Please include new HJT log, and vundofix.tx
in your next post
Thanks dan
Logfile of HijackThis v1.99.1
Scan saved at 7:58:36 PM, on 3/18/2007
Platform: Windows XP SP2, v.2149 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2149)
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath,browse and find the file click open which will place it in the field.
C:\WINDOWS\SYSTEM32\gpkuse.dll
Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.
If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html
Double-click VundoFix.exe to run it again.
Right Click inside the listbox (white box) and click add more files
Copy&Paste the entries below into the open boxes
C:\WINDOWS\SYSTEM32\gpkuse.dll
Click Add Files and Click Close Window
Click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot,allow the computer to reboot and VundoFix to load.
Just add the very same files as before and Click Remove Vundo.
Please include new HJT log, vundofix txt
in your next post
Thanks dan
Hi dan12
Here are the results from the jotti scan
can taken on 19 Mar 2007 21:25:40 (GMT)
AntiVir
Found TR/Dldr.ConHook.Gen
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found MemScan:Trojan.BHO.AK
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found Trojan.Win32.Agent.agv
Fortinet
Found nothing
Kaspersky Anti-Virus
Found Trojan.Win32.Agent.agv
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
VirusBuster
Found Packed/Upack
VBA32
Found nothing
———————————————————-
here are the statistics
Last file scanned at least one scanner reported something about: c93af3180e.zip (MD5: e5c64d81e69c536904603fe733fb7169, size: 141875 bytes), detected by:
Scanner Malware name
AntiVir X
ArcaVir X
Avast Win32:Flooder-Y
AVG Antivirus X
BitDefender X
ClamAV X
Dr.Web X
F-Prot Antivirus X
F-Secure Anti-Virus X
Fortinet X
Kaspersky Anti-Virus X
NOD32 X
Norman Virus Control X
Panda Antivirus X
VirusBuster X
VBA32 X
Attempting to delete C:\WINDOWS\SYSTEM32\gpkuse.dll
C:\WINDOWS\SYSTEM32\gpkuse.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal…
Attempting to delete C:\WINDOWS\SYSTEM32\gpkuse.dll
C:\WINDOWS\SYSTEM32\gpkuse.dll Has been deleted!
Performing Repairs to the registry.
Done!
——————————————————————-
Here is the new Hijackthis log
Logfile of HijackThis v1.99.1
Scan saved at 3:39:23 PM, on 3/19/2007
Platform: Windows XP SP2, v.2149 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2149)
if exist "C:\Program Files\iTunes\iTunesHelper.exe" del /q "C:\Program Files\iTunesHelper.exe"
copy /y "C:\Program Files\iTunes\bak\iTunesHelper.exe" "C:\Program Files\iTunes\iTunesHelper.exe"
if exist "C:\Program Files\Microsoft IntelliPoint\point32.exe" del /q "C:\Program Files\Microsoft IntelliPoint\point32.exe"
copy /y "C:\Program Files\Microsoft IntelliPoint\bak\point32.exe" "C:\Program Files\Microsoft IntelliPoint\point32.exe"
if exist "C:\Program Files\QuickTime\qttask.exe" del /q "C:\Program Files\QuickTime\qttask.exe"
copy /y "C:\Program Files\QuickTime\bak\qttask.exe" "C:\Program Files\QuickTime\qttask.exe"
if exist "C:\WINDOWS\system32\NeroCheck.exe" del /q "C:\WINDOWS\system32\NeroCheck.exe"
copy /y "C:\WINDOWS\system32\bak\NeroCheck.exe" "C:\WINDOWS\system32\NeroCheck.exe"
if exist "C:\Program Files\CA\eTrust Antivirus\realmon.exe" del /q "C:\Program Files\CA\eTrust Antivirus\realmon.exe"
copy /y "C:\Program Files\CA\eTrust Antivirus\bak\realmon.exe" "C:\Program Files\CA\eTrust Antivirus\realmon.exe" <<<<<<<<<< This is not on system anyway
if exist "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" del /q "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
copy /y "C:\Program Files\NVIDIA Corporation\NvMixer\bak\NVMixerTray.exe" "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
Save this as fixme.bat , choose to save it as *all files and place it on your desktop. We will use this shortly
__________
Download ATF Cleaner by Atribune and save it to your Desktop. Do not use yet!
Ewido is now known as ( AVG Anti-Spyware.)
Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
Install AVG Anti-Spyware by double clicking the installer.
Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
On the main screen under Your Computer's security.
Click on Change state next to Resident shield. It should now change to inactive.
Click on Change state next to Automatic updates. It should now change to inactive.
Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
Wait until you see the Update succesfull message.
Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido. AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update. Dont use yet!
____________________
We need to reveal system folders
Close all programs so that you are at your desktop.
Double-click on the My Computer icon.
Select the Tools menu and click Folder Options
After the new window appears select the View tab.
Place a checkmark in the checkbox labeled Display the contents of system folders
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders
Remove the checkmark from the checkbox labeled Hide file extensions for known file types
Remove the checkmark from the checkbox labeled Hide protected operating system files
Press the Apply and then the ok button and shut down my computer
Now your computer is configured to show all hidden files.
For you and the tools to be able to see appropriate files we need to Show Hidden Files
Re-boot into safe mode
Next, please reboot your computer in Safe Mode by doing the following:
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
Instead of Windows loading as normal, a menu should appear use arrow up to highlight
Select the first option, to run Windows in Safe Mode hit enter.
For additional help in booting into Safe Mode, see the following site:HERE
___________
Doubleclick fixme.bat from where you saved it earlier, (on the desktop) the screen may go off and on this is normal.
Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)
O2 - BHO: (no name) - {f01ac5b4-d989-4db8-af1c-1dda0c18d6a3} - C:\WINDOWS\system32\gpkuse.dll (file missing)
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\fcbbyv.dll",setvm
O20 - AppInit_DLLs:
WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit
Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:
C:\WINDOWS\system32\gpkuse.dll <===This file if there
C:\WINDOWS\fcbbyv.dll <=====This file
Run ATF cleaner
Double click ATF-Cleaner.exe to run the program.
Check the following boxes:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch
Recycle Bin
Java Cache
The rest are optional - if you want to remove the lot, check Select All.
Now click Empty Selected.
When you get the Done Cleaning message, click OK.
If you use Firefox browser.
Click Firefox at the top and choose: Select All
If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button.
If you use Opera browser.
Click Opera at the top and choose: Select All
If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button.
Run AVG Anti-Spyware
Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Click on Scanner on the toolbar.
Click on the Settings tab.
Under How to act?
Click on Recommended Action and choose Quarantine from the popup menu.
Under How to scan?
All checkboxes should be ticked.
Under Possibly unwanted software:
All checkboxes should be ticked.
Under Reports:
Select Automatically generate report after every scan and uncheck Only if threats were found.
Under What to scan?
Select Scan every file.
Click on the Scan tab.
Click on Complete System Scan to start the scan process.
Let the program scan the machine.
When the scan has finished, follow the instructions below. IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
Make sure that Set all elements to: shows Quarantine(1), if not click on the link and choose Quarantine from the popup menu. (2)
At the bottom of the window click on the Apply all Actions button. (3)
[external image: Posted Image]
When done, click the Save Scan Report button. (4)
Click the Save Report as button.
Save the report to your Desktop.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________
please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK
Now under select a target to scan select My Computer
The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
Please include new HJT log, AVG Anti-Spyware log and kaspersky log
in your next post
Thanks dan
Logfile of HijackThis v1.99.1
Scan saved at 1:45:23 AM, on 3/21/2007
Platform: Windows XP SP2, v.2149 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2149)
:mozilla.36:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.37:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.38:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.39:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.40:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.13:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.54:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.55:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.56:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.15:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.16:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.17:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.18:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.58:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.23:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.33:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.34:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.35:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\3o5z70rr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{F7AAB29E-2EBD-4896-B141-D15987C3D262}\RP173\A0033898.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
::Report end
———————————————————————————————-
Here is the Kaspersky log
KASPERSKY ONLINE SCANNER REPORT
Wednesday, March 21, 2007 1:37:59 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2, v.2149 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 21/03/2007
Kaspersky Anti-Virus database records: 283749
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 37020
Number of viruses found 6
Number of infected objects 14 / 0
Number of suspicious objects 0
Duration of the scan process 01:30:23
Infected Object Name Virus Name Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Tom\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Tom\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Tom\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Tom\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Tom\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Tom\ntuser.dat Object is locked skipped
C:\Documents and Settings\Tom\ntuser.dat.LOG Object is locked skipped
C:\Downloads\New Folder\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Downloads\New Folder\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Downloads\New Folder\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log.idx Object is locked skipped
C:\SDFix\backups\backups.zip/backups/tmp8C.tmp.exe Infected: Trojan-Downloader.Win32.Agent.bjk skipped
C:\SDFix\backups\backups.zip ZIP: infected - 1 skipped
C:\System Volume Information\_restore{F7AAB29E-2EBD-4896-B141-D15987C3D262}\RP131\A0030392.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\System Volume Information\_restore{F7AAB29E-2EBD-4896-B141-D15987C3D262}\RP131\A0030392.exe/data0003 Infected: not-a-virus:AdWare.Win32.PurityScan.bu skipped
C:\System Volume Information\_restore{F7AAB29E-2EBD-4896-B141-D15987C3D262}\RP131\A0030392.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{F7AAB29E-2EBD-4896-B141-D15987C3D262}\RP173\A0033800.exe Infected: Trojan-Downloader.Win32.Agent.bjk skipped
C:\System Volume Information\_restore{F7AAB29E-2EBD-4896-B141-D15987C3D262}\RP173\A0033864.dll Infected: Trojan.Win32.Agent.agv skipped
C:\System Volume Information\_restore{F7AAB29E-2EBD-4896-B141-D15987C3D262}\RP174\change.log Object is locked skipped
C:\VundoFix Backups\gpkuse.dll.bad Infected: Trojan.Win32.Agent.agv skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd5965.sys Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\websvr\htdocs\remview.php Infected: not-a-virus:RemoteAdmin.PHP.RemView.a skipped
C:\WINDOWS\websvr.part2.rar/websvr/htdocs/remview.php Infected: not-a-virus:RemoteAdmin.PHP.RemView.a skipped
C:\WINDOWS\websvr.part2.rar RAR: infected - 1 skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Your doing well, were getting there, little bit to do.
I need you to upload a file for me for it to be checked over.
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath,browse and find the file click open which will place it in the field.
C:\WINDOWS\system32\cscentfy.dll
Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.
If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html
Hi dan12,
here are the results
Scan taken on 21 Mar 2007 23:29:06 (GMT)
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI