This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Help

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hope you can help. Norton AV detected a trojan.adclicker virus on my machine and was not able to delete it. Since then I am getting all sorts of web pages popping up on my screen when I launch Explorer. Also have received messages in Outlook that ask if I want to allow a program to access my email address book file. Finally the virus has kicked me out of your website a number of times making me think that it might be smart enough to stop me from getting assistance. Of course that might be my paranoia at work Here is my HJ log file. Please assist if you can.

Thanks,

Logfile of HijackThis v1.99.1
Scan saved at 4:37:59 PM, on 4/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\System32\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ISS\DesktopProtection\blackd.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\updater.exe
C:\WINDOWS\system32\micro1\b9.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\PROGRA~1\COMMON~1\wkzm\wkzmm.exe
D:\Profiles\cmni58\MYDOCU~1\FNTS~1\wuauboot.exe
C:\Program Files\Common Files\??crosoft.NET\t?skmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Audible\Bin\adhelper.exe
C:\PROGRA~1\COMMON~1\wkzm\wkzma.exe
C:\Program Files\Dell\Bluetooth Software\BTTray.exe
C:\Program Files\ISS\DesktopProtection\blackice.exe
C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
C:\PROGRA~1\Dell\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Microsoft Office 2003\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office 2003\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
D:\Profiles\cmni58\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://compass.mot.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Motorola
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.mot.com:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.mot.com;*.gi.com;
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\System32\ZCfgSvc.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [CSCAdvantage] "C:\Program Files\Help Desk\CSCAdv.exe" /s
O4 - HKLM\..\Run: [CSCLogonInfo] C:\WINDOWS\UsrLogon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Blocker] "C:\Program Files\Internet Explorer\Iereg.exe"
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\updater.exe 61A847B5BBF72810329B385473F001F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [bantool] C:\WINDOWS\system32\micro1\b9.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [hB7FRSjtV] dpsgest.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [wkzm] C:\PROGRA~1\COMMON~1\wkzm\wkzmm.exe
O4 - HKCU\..\Run: [Utat] "D:\Profiles\cmni58\MYDOCU~1\FNTS~1\wuauboot.exe" -vt yazb
O4 - HKCU\..\Run: [Bsnwsgne] "C:\Program Files\Common Files\??crosoft.NET\t?skmgr.exe"
O4 - Startup: Livelink Explorer Synchronizer.lnk = C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\adhelper.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O4 - Global Startup: SysTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {01516EAA-CC39-4477-9500-87CB12F72AFD} (Livelink Explorer Activator) - http://compass.mot.com/support/webexp/llexpld.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9A04E3F0-3BB2-11D2-91E2-00C04FAEC46B} (NMClient Class) - http://meet-amer.mot.com/ConferencingBin/xcliacc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\Software\..\Telephony: DomainName = ds.mot.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.mot.com,ds.mot.com,sps.mot.com,mot.com
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\DesktopProtection\blackd.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Motorola MVP\Extranet_serv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\DesktopProtection\RapApp.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\WINDOWS\System32\WLKeeper.exe
Hi and welcome to the forums. :) I'm Markka and I will be helping you with your malware issues. I'll check your HijackThis log. Right now I'm MRU Undergrad, everything that I post to you must be checked by teachers of Malware Removal University. Please be patient. :)
Hello :)


1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log


Post:
- A fresh HijackThis log
- Contents of C:\combofix
- Logfile of SDFix (contents of Report.txt)
I really appreciate your help. Here are the logs.

"cmni58" - 07-04-19 21:45:25 Service Pack 2
ComboFix 07-04-19.2V - Running from: C:\Program Files\Mozilla Firefox\


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\Program Files\Common Files\CROSOF~1.NET
C:\qoobox\purity\C\Program Files\Common Files\CROSOF~1.NET\t?skmgr.exe


((((((((((((((((((((((((((((((( Files Created from 2007-03-19 to 2007-04-19 ))))))))))))))))))))))))))))))))))


2007-04-18 16:27 28,672 –a—— C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-04-18 14:47 3,833 –a—— C:\WINDOWS\hGFdeYYm64pUIdwQ.exe
2007-04-18 11:16 60,928 –a—— C:\WINDOWS\system32\aunj.dll
2007-04-18 11:16 2 –a—— C:\WINDOWS\system32\wtsicomsv.exe
2007-04-18 11:01 d——– C:\WINDOWS\wkzm
2007-04-18 11:01 d——– C:\Program Files\Common Files\wkzm
2007-04-18 10:46 d–hs—- C:\WINDOWS\TW90b3JvbGEgUEM
2007-04-18 10:04 8,464 –a—— C:\WINDOWS\system32\sporder.dll
2007-04-18 10:04 72,320 –a—— C:\WINDOWS\system32\drivers\core.sys
2007-04-18 10:04 105,434 –a—— C:\WINDOWS\VTTC.exe
2007-04-18 10:04 d——– C:\WINDOWS\system32\micro1
2007-04-18 10:04 d——– C:\Temp\tn3
2007-04-18 10:04 d——– C:\Temp\tn3
2007-03-21 11:33 d——– C:\Program Files\RSA Security


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-18 15:21 ——– d——– C:\Program Files\motorola mvp
2007-04-18 15:21 ——– d——– C:\Program Files\motorola mvp
2007-04-18 12:41 9129 –a—— C:\Program Files\hijackthis.log
2007-04-18 12:41 9129 –a—— C:\Program Files\hijackthis.log
2007-04-13 08:27 ——– d——– C:\Program Files\lx_cats
2007-04-13 08:27 ——– d——– C:\Program Files\lx_cats
2007-03-21 11:33 ——– d–h—– C:\Program Files\installshield installation information
2007-03-21 11:33 ——– d–h—– C:\Program Files\installshield installation information
2007-03-15 12:23 497496 –a—— C:\WINDOWS\system32\xceedzip.dll
2007-03-15 12:19 526184 –a—— C:\WINDOWS\system32\xceedcry.dll
2007-03-15 10:08 101438 –a—— C:\WINDOWS\b122.exe
2007-03-12 11:01 ——– d——– C:\Program Files\patches
2007-03-12 11:01 ——– d——– C:\Program Files\patches
2007-03-12 11:01 ——– d——– C:\Program Files\msecache
2007-03-12 11:01 ——– d——– C:\Program Files\msecache
2007-03-10 18:10 ——– d——– C:\Program Files\gimp-2.0
2007-03-10 18:10 ——– d——– C:\Program Files\gimp-2.0
2007-03-10 17:42 37027 –a—— C:\WINDOWS\atmoun.exe
2007-03-10 17:42 ——– d——– C:\Program Files\viewpoint
2007-03-10 17:42 ——– d——– C:\Program Files\viewpoint
2007-02-22 15:20 224 –a—— C:\WINDOWS\system32\tbhi.dat
2007-02-19 07:01 252356 –a—— C:\WINDOWS\b128.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
{48F0BED1-D50D-4FD9-92EF-52E1AC2BA3F9} C:\Program Files\Internet Explorer\hoke.dll
{4F91D51C-39FE-6976-A34E-1CE348EEFACE} C:\WINDOWS\system32\aunj.dll
{53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
{AE7CD045-E861-484f-8273-0445EE161910} C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
{DDA0B37B-A085-424D-199E-E6B2F780F5C0} C:\Program Files\Windows Media Player\lavuma.dll
{F757FBBF-10E5-4DDA-BBEA-2357E54BEA2B} C:\Program Files\Open Text\Livelink Explorer\LLBHO3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
"Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"ZCfgSvc.exe"="C:\\WINDOWS\\System32\\ZCfgSvc.exe"
"PRONoMgr.exe"="C:\\Program Files\\Intel\\NCS\\PROSet\\PRONoMgr.exe"
"CSCAdvantage"="\"C:\\Program Files\\Help Desk\\CSCAdv.exe\" /s"
"CSCLogonInfo"="C:\\WINDOWS\\UsrLogon.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Blocker"="\"C:\\Program Files\\Internet Explorer\\Iereg.exe\""
"LXCFCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\LXCFtime.dll,_RunDLLEntry@16"
"bantool"="C:\\WINDOWS\\system32\\micro1\\b9.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"hB7FRSjtV"="dpsgest.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Communicator"="\"C:\\Program Files\\Microsoft Office Communicator\\Communicator.exe\" /background"
"Bsnwsgne"="\"C:\\Program Files\\Common Files\\??crosoft.NET\\t?skmgr.exe\""

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Communicator"="\"C:\\Program Files\\Microsoft Office Communicator\\Communicator.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"=dword:00000000
"NoToolbarCustomize"=dword:00000000
"NoBandCustomize"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Btn_Back"=dword:00000000
"Btn_Forward"=dword:00000000
"Btn_Stop"=dword:00000000
"Btn_Refresh"=dword:00000000
"Btn_Home"=dword:00000000
"Btn_Search"=dword:00000000
"Btn_History"=dword:00000000
"Btn_Favorites"=dword:00000000
"Btn_Media"=dword:00000000
"Btn_Folders"=dword:00000000
"Btn_Fullscreen"=dword:00000000
"Btn_Tools"=dword:00000000
"Btn_MailNews"=dword:00000000
"Btn_Size"=dword:00000000
"Btn_Print"=dword:00000000
"Btn_Edit"=dword:00000000
"Btn_Discussions"=dword:00000000
"Btn_Cut"=dword:00000000
"Btn_Copy"=dword:00000000
"Btn_Paste"=dword:00000000
"Btn_Encoding"=dword:00000000
"Btn_PrintPreview"=dword:00000000
"NoActiveDesktopChanges"=dword:00000000
"NoFavoritesMenu"=dword:00000000
"NoSetActiveDesktop"=dword:00000000
"NoWindowsUpdate"=dword:00000000
"NoChangeStartMenu"=dword:00000000
"NoRecentDocsMenu"=dword:00000000
"NoRecentDocsHistory"=dword:00000000
"ClearRecentDocsOnExit"=dword:00000000
"NoLogoff"=dword:00000000
"NoClose"=dword:00000000
"NoSetFolders"=dword:00000000
"NoSetTaskbar"=dword:00000000
"NoTrayContextMenu"=dword:00000000
"NoFileMenu"=dword:00000000
"NoViewContextMenu"=dword:00000000
"EnforceShellExtensionSecurity"=dword:00000000
"LinkResolveIgnoreLinkInfo"=dword:00000000
"NoNetConnectDisconnect"=dword:00000000
"NoDeletePrinter"=dword:00000000
"NoAddPrinter"=dword:00000000
"NoPrinterTabs"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoWindowsUpdate"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\run]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0nwprovau\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
HTTPFilter REG_MULTI_SZ HTTPFilter\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\
WudfServiceGroup REG_MULTI_SZ WUDFSvc\



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\WiMAX Back-up.job

********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-19 21:48:31
C:\ComboFix-quarantined-files.txt … 07-04-19 21:48
C:\ComboFix2.txt … 07-04-19 21:10
C:\ComboFix3.txt … 07-04-19 14:48


2007/01/16-16:47:22.711 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/16-16:47:38.023 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/16-16:48:01.459 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/18-08:40:11.063 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/18-08:40:45.342 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/18-14:56:34.906 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/18-14:56:57.909 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/18-15:53:30.028 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/18-15:53:42.271 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/18-17:31:52.536 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/18-17:32:04.072 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/19-08:34:15.915 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/19-08:34:31.718 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/19-08:42:00.642 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/19-08:42:16.154 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/19-16:40:03.922 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/19-16:40:24.743 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/20-17:17:19.872 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/20-17:17:33.322 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/21-11:22:29.901 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/22-16:15:18.247 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/22-16:15:42.333 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/23-16:38:13.068 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/23-16:38:40.149 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/23-17:19:14.703 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/23-17:19:27.342 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/23-17:23:01.206 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/23-17:23:16.859 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/24-13:58:51.019 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/24-13:59:10.827 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/24-22:46:06.189 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/24-22:46:20.549 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/25-16:48:55.212 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/25-16:49:13.199 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/26-12:58:28.481 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/26-12:58:40.022 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/26-13:24:50.831 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/26-13:25:15.667 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/26-14:09:51.404 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/26-14:10:02.890 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/26-16:47:56.490 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/26-16:48:10.338 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/29-16:10:43.996 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/29-16:11:11.716 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/30-09:34:52.458 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/01/30-09:35:09.292 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/07-16:56:15.088 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/07-16:56:30.602 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/07-19:27:28.580 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/07-19:27:41.967 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/09-16:51:45.167 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/09-16:52:07.248 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/10-19:05:09.575 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/10-19:05:24.887 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/13-13:42:34.672 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/13-13:42:49.926 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/15-07:45:42.874 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/15-07:45:59.108 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/15-17:24:15.874 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/15-17:24:31.556 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/16-17:24:01.258 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/16-17:24:20.106 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/17-09:13:40.381 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/17-09:13:55.953 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/19-17:34:11.559 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/19-17:34:25.779 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/20-18:28:18.710 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/20-18:28:35.587 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/21-15:49:47.214 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/21-15:50:48.557 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/22-17:13:28.640 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/22-17:13:48.169 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/22-17:46:53.139 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/22-17:47:08.722 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/22-23:39:22.120 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/22-23:39:36.401 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/26-17:15:38.886 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/26-17:15:57.953 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/27-17:30:47.010 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/27-17:32:07.582 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/28-17:06:55.644 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/02/28-17:07:41.890 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/01-17:52:45.822 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/01-17:53:08.694 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/02-16:03:57.753 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/02-16:04:15.389 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/03-10:22:53.448 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/03-10:23:08.229 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/05-16:08:59.722 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/05-16:09:26.742 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/08-15:56:15.092 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/08-15:56:30.075 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/09-16:35:43.304 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/09-16:35:58.338 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/11-08:24:52.895 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/11-08:25:07.256 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/12-09:25:20.829 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/12-09:25:36.932 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/12-11:03:23.057 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/12-11:03:42.345 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/12-11:04:08.603 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/12-16:13:32.986 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/12-16:13:47.317 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/18-07:51:06.135 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/18-07:51:24.010 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/19-17:05:18.382 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/19-17:05:32.623 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/19-21:39:02.271 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/19-21:39:18.114 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/19-21:39:32.614 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-09:17:49.299 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-09:18:00.805 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-09:21:10.676 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-09:21:21.902 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-10:27:56.220 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-10:34:38.114 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-10:34:49.410 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-10:41:30.171 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-10:41:40.576 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-10:44:56.670 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-10:45:07.375 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-10:53:03.473 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:03:05.081 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:03:16.858 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:07:12.077 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:07:22.842 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:17:57.609 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:18:09.987 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:29:29.331 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:29:46.065 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:34:14.412 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:34:30.054 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:39:40.342 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-11:39:54.883 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-17:05:44.751 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/21-17:06:03.858 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/22-09:26:56.327 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/22-09:27:19.010 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/22-16:58:13.201 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/22-16:58:37.085 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/22-17:09:09.361 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/22-17:09:28.168 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/23-17:09:13.941 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/23-17:10:00.228 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/26-08:19:09.888 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/26-08:19:23.488 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/26-09:16:20.111 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/26-09:16:36.114 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/26-17:20:35.986 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/26-17:21:10.015 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/28-14:20:05.737 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/28-14:20:25.715 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/30-16:50:08.492 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/30-16:50:53.056 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/31-12:36:23.426 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/03/31-12:36:56.273 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/08-14:10:41.667 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/08-14:10:57.811 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/09-02:59:19.561 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/09-02:59:36.035 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/09-21:50:36.268 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/09-21:50:51.310 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/09-22:53:06.287 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/09-22:53:21.409 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/10-17:22:27.448 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/10-17:23:00.846 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/11-17:04:04.911 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/11-17:04:36.947 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/12-17:20:35.224 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/12-17:21:04.166 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/13-16:35:52.211 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/13-16:36:15.034 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/15-08:25:10.293 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/15-08:25:24.072 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/16-17:33:54.989 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/16-17:34:13.596 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/18-10:25:27.134 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/18-10:26:04.949 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/18-11:58:01.126 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/18-11:58:34.714 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/18-12:46:17.017 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/18-12:46:46.489 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/18-17:02:29.736 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/18-17:03:06.399 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/19-09:43:41.297 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/19-09:44:09.537 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/19-14:55:28.692 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/19-14:55:56.532 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/19-21:27:19.624 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/19-21:28:17.898 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/19-21:51:58.686 ComClient LcsGetClientIdRunnable() exception=2147943453
2007/04/19-21:52:15.550 ComClient LcsGetClientIdRunnable() exception=2147943453


Logfile of HijackThis v1.99.1
Scan saved at 10:21:06 PM, on 4/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\System32\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ISS\DesktopProtection\blackd.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\micro1\b9.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Audible\Bin\adhelper.exe
C:\Program Files\Dell\Bluetooth Software\BTTray.exe
C:\Program Files\ISS\DesktopProtection\blackice.exe
C:\PROGRA~1\Dell\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Profiles\cmni58\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.mot.com:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.mot.com;*.gi.com;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {48F0BED1-D50D-4FD9-92EF-52E1AC2BA3F9} - C:\Program Files\Internet Explorer\hoke.dll
O2 - BHO: (no name) - {4F91D51C-39FE-6976-A34E-1CE348EEFACE} - C:\WINDOWS\system32\aunj.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: 0 - {DDA0B37B-A085-424D-199E-E6B2F780F5C0} - C:\Program Files\Windows Media Player\lavuma.dll
O2 - BHO: LLIEHlprObj Class - {F757FBBF-10E5-4DDA-BBEA-2357E54BEA2B} - C:\Program Files\Open Text\Livelink Explorer\LLBHO3.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\System32\ZCfgSvc.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [CSCAdvantage] "C:\Program Files\Help Desk\CSCAdv.exe" /s
O4 - HKLM\..\Run: [CSCLogonInfo] C:\WINDOWS\UsrLogon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Blocker] "C:\Program Files\Internet Explorer\Iereg.exe"
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [bantool] C:\WINDOWS\system32\micro1\b9.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [hB7FRSjtV] dpsgest.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - HKCU\..\Run: [Bsnwsgne] "C:\Program Files\Common Files\??crosoft.NET\t?skmgr.exe"
O4 - Startup: Livelink Explorer Synchronizer.lnk = C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\adhelper.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O4 - Global Startup: SysTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9A04E3F0-3BB2-11D2-91E2-00C04FAEC46B} (NMClient Class) - http://meet-amer.mot.com/ConferencingBin/xcliacc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\Software\..\Telephony: DomainName = ds.mot.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{E05DF853-5AFA-4B6A-8858-A2CE921A27D4}: NameServer = 129.188.1.1,129.188.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.mot.com,ds.mot.com,sps.mot.com,mot.com
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\DesktopProtection\blackd.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Motorola MVP\Extranet_serv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\DesktopProtection\RapApp.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\WINDOWS\System32\WLKeeper.exe


Hope you can help
Hello :)


First we'll need to backup registry:

Start -> Run -> regedit -> ok. Then File -> Export. Give it a name and press Save.

Save text below as fix.reg on Notepad (save it as all files (*.*)) on Desktop

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{48F0BED1-D50D-4FD9-92EF-52E1AC2BA3F9}"=-
"{4F91D51C-39FE-6976-A34E-1CE348EEFACE}"=-
"{DDA0B37B-A085-424D-199E-E6B2F780F5C0}"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"CSCLogonInfo"=-
"bantool"=-
"Blocker"="-

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"hB7FRSjtV"=-
"Bsnwsgne"=-

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoWindowsUpdate"=-

It should look like this -> [external image: Posted Image]

Doubleclick fix.reg, press Yes and ok.

(In case you are unsure how to create a reg file, take a look here with screenshots.)


Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.



Open HijackThis, Click Do a system scan only, checkmark these. Then close all others windows except HijackThis and press fix checked.

O2 - BHO: (no name) - {48F0BED1-D50D-4FD9-92EF-52E1AC2BA3F9} - C:\Program Files\Internet Explorer\hoke.dll
O2 - BHO: (no name) - {4F91D51C-39FE-6976-A34E-1CE348EEFACE} - C:\WINDOWS\system32\aunj.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - (no file)
O2 - BHO: 0 - {DDA0B37B-A085-424D-199E-E6B2F780F5C0} - C:\Program Files\Windows Media Player\lavuma.dll
O4 - HKLM\..\Run: [CSCLogonInfo] C:\WINDOWS\UsrLogon.exe
O4 - HKLM\..\Run: [Blocker] "C:\Program Files\Internet Explorer\Iereg.exe"
O4 - HKLM\..\Run: [bantool] C:\WINDOWS\system32\micro1\b9.exe
O4 - HKCU\..\Run: [hB7FRSjtV] dpsgest.exe
O4 - HKCU\..\Run: [Bsnwsgne] "C:\Program Files\Common Files\??crosoft.NET\t?skmgr.exe"




Make your hidden files visible:
  • Click start
  • Click my computer
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.

Please download ATF-cleaner and save it to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

    If you use Firefox browser:

  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser:

  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.


Please then reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.

Delete these files: (if found)
C:\Program Files\Internet Explorer\hoke.dll
C:\WINDOWS\system32\aunj.dll
C:\Program Files\Windows Media Player\lavuma.dll
C:\WINDOWS\UsrLogon.exe
C:\Program Files\Internet Explorer\Iereg.exe
C:\WINDOWS\hGFdeYYm64pUIdwQ.exe
C:\WINDOWS\system32\wtsicomsv.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b128.exe
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\VTTC.exe


Use the Windows "search" tool
Start->Search
-> All files and folders
Click More advanced options

Checkmark these options:
"Search system folders"
"Search hidden files and folders"
"Search subfolders"


->Search for this and delete if found: dpsgest.exe

Delete these folders: (if found)
C:\WINDOWS\system32\micro1
C:\Program Files\Common Files\wkzm
C:\WINDOWS\wkzm
C:\WINDOWS\TW90b3JvbGEgUEM
C:\Temp\tn3

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.


Please Download F-Secure's Blacklight and save it to your desktop.

Doubleclick fsbl.exe, accept the agreement, click Scan, then click Next

You'll see a list what have been found. A log will appear to your desktop, it is named fsbl.xxxxxxx.log (xxxxxxx will be random numbers).

DON'T choose Rename if something was found!


Go to Jotti's Malware Scan.*Click on the "Browse"-button
*Find this file: C:\WINDOWS\system32\drivers\CO_Mon.sys
*Click on the "Submit"-button
*Copy/paste the results of Jotti's into a notepad.

Post:
- A fresh HijackThis log
- AVG's log
- Logfile of Blacklight
- The results of Jotti's
Here's everything. Thanks for your help.

Logfile of HijackThis v1.99.1
Scan saved at 12:30:14 PM, on 4/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\System32\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ISS\DesktopProtection\blackd.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Audible\Bin\adhelper.exe
C:\Program Files\Dell\Bluetooth Software\BTTray.exe
C:\Program Files\ISS\DesktopProtection\blackice.exe
C:\PROGRA~1\Dell\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
C:\Program Files\Intel\NCS\Sync\NetSvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Profiles\cmni58\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.mot.com:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.mot.com;*.gi.com;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: LLIEHlprObj Class - {F757FBBF-10E5-4DDA-BBEA-2357E54BEA2B} - C:\Program Files\Open Text\Livelink Explorer\LLBHO3.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\System32\ZCfgSvc.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [CSCAdvantage] "C:\Program Files\Help Desk\CSCAdv.exe" /s
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - Startup: Livelink Explorer Synchronizer.lnk = C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\adhelper.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O4 - Global Startup: SysTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9A04E3F0-3BB2-11D2-91E2-00C04FAEC46B} (NMClient Class) - http://meet-amer.mot.com/ConferencingBin/xcliacc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\Software\..\Telephony: DomainName = ds.mot.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{E05DF853-5AFA-4B6A-8858-A2CE921A27D4}: NameServer = 129.188.1.1,129.188.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.mot.com,ds.mot.com,sps.mot.com,mot.com
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\DesktopProtection\blackd.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Motorola MVP\Extranet_serv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\DesktopProtection\RapApp.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\WINDOWS\System32\WLKeeper.exe

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 11:52:21 AM 4/22/2007

+ Scan result:



C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc13\asappsrv.dll -> Adware.CommAd : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc13\command.exe -> Adware.CommAd : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc15\f1.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\QooBox\purity\C\Program Files\Common Files\CROSOF~1.NET\tаskmgr.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
D:\Profiles\cmni58\Desktop\backups\backup-20070422-100316-642.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc8.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\DeluxeCommunications\Dxc.exe.vir -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\DeluxeCommunications\DxcBho.dll.vir -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\DeluxeCommunications\DxcCore.dll.vir -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\DXCLIB~1.DLL.vir -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc15\f4.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc11\wkzmd\wkzmc.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc1.dll -> Adware.TTC : Cleaned with backup (quarantined).
D:\Profiles\cmni58\Desktop\backups\backup-20070422-100316-538.dll -> Adware.TTC : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\iiffdbx.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\urqqqnm.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\yaywuro.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WinStatX.Installer -> Adware.WinTaskAd : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WinStatX.Installer\CLSID -> Adware.WinTaskAd : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc9.exe -> Downloader.PurityScan.eh : Cleaned with backup (quarantined).
C:\WINDOWS\b104.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc11\wkzmd\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\WINDOWS\b103.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc15\fin5.exe -> Dropper.Agent.bfr : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc5.sys -> Rootkit.Agent.eq : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc15\b9.exe -> Trojan.Bantool : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc13\nq6XvaLSv3H0oHg.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc4.exe -> Trojan.Small : Cleaned with backup (quarantined).


::Report end

BackLight Log File

04/22/07 12:13:35 [Info]: BlackLight Engine 1.0.61 initialized
04/22/07 12:13:35 [Info]: OS: 5.1 build 2600 (Service Pack 2)
04/22/07 12:13:35 [Note]: 7019 4
04/22/07 12:13:35 [Note]: 7005 0
04/22/07 12:13:42 [Note]: 7006 0
04/22/07 12:13:42 [Note]: 7011 1692
04/22/07 12:13:42 [Note]: 7026 0
04/22/07 12:13:42 [Note]: 7026 0
04/22/07 12:13:46 [Note]: FSRAW library version 1.7.1021
04/22/07 12:22:25 [Note]: 7007 0

Jotti's Results

Scan taken on 22 Apr 2007 16:22:37 (GMT)
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothin
Hello :)


Kaspersky online scanner works only with IE!

Please run an online scanner with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:

    o Scan using the following Anti-Virus database:

    + Extended (If available otherwise Standard)

    o Scan Options:

    + Scan Archives
    + Scan Mail Bases

  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.




Post:
- A fresh HijackThis log
- The report of the Kaspersky
Logfile of HijackThis v1.99.1
Scan saved at 9:40:00 PM, on 4/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\System32\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ISS\DesktopProtection\blackd.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Audible\Bin\adhelper.exe
C:\Program Files\Dell\Bluetooth Software\BTTray.exe
C:\Program Files\ISS\DesktopProtection\blackice.exe
C:\PROGRA~1\Dell\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
C:\Program Files\Intel\NCS\Sync\NetSvc.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\WINDOWS\system32\lxcfcoms.exe
C:\Program Files\Microsoft Office 2003\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office 2003\OFFICE11\WINWORD.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPC32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Profiles\cmni58\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.mot.com:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.mot.com;*.gi.com;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: LLIEHlprObj Class - {F757FBBF-10E5-4DDA-BBEA-2357E54BEA2B} - C:\Program Files\Open Text\Livelink Explorer\LLBHO3.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\System32\ZCfgSvc.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [CSCAdvantage] "C:\Program Files\Help Desk\CSCAdv.exe" /s
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - Startup: Livelink Explorer Synchronizer.lnk = C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\adhelper.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O4 - Global Startup: SysTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9A04E3F0-3BB2-11D2-91E2-00C04FAEC46B} (NMClient Class) - http://meet-amer.mot.com/ConferencingBin/xcliacc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\Software\..\Telephony: DomainName = ds.mot.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.mot.com,ds.mot.com,sps.mot.com,mot.com
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\DesktopProtection\blackd.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Motorola MVP\Extranet_serv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\DesktopProtection\RapApp.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\WINDOWS\System32\WLKeeper.exe

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, April 23, 2007 9:39:04 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 24/04/2007
Kaspersky Anti-Virus database records: 301215
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
Z:\

Scan Statistics:
Total number of scanned objects: 50803
Number of viruses found: 11
Number of infected objects: 24
Number of suspicious objects: 0
Duration of the scan process: 02:32:06

Infected Object Name / Virus Name / Last Action
C:\Ntutils\pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.e skipped
C:\Program Files\Audible\Bin\ADMDebug.log Object is locked skipped
C:\Program Files\ISS\DesktopProtection\blackice-service.log Object is locked skipped
C:\Program Files\Microsoft Office 2003\OFFICE11\1033\EMAIL.DOT Object is locked skipped
C:\Program Files\Microsoft Office 2003\OFFICE11\STARTUP\PDFMaker.dot Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bkd.exe.vir/InpB/DxcBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bkd.exe.vir/InpB/DxcCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bkd.exe.vir/InpB/Dxc.exe Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bkd.exe.vir/InpB/DxcRepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bkd.exe.vir/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bkd.exe.vir CAB: infected - 5 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bund1\ClientBundle1.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bund1\ClientBundle1.exe.vir/data0003 Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bund1\ClientBundle1.exe.vir/data0004 Infected: not-a-virus:AdWare.Win32.SurfSide.ax skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bund1\ClientBundle1.exe.vir/data0005 Infected: Trojan-Dropper.Win32.Agent.bfr skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bund1\ClientBundle1.exe.vir NSIS: infected - 4 skipped
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc10.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\RECYCLER\S-1-5-21-2052111302-287218729-725345543-771466\Dc10.exe NSIS: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\CCM\Cache\N0002A.2.System\Source\PSKILL.EXE Infected: not-a-virus:NetTool.Win32.PsKill skipped
C:\WINDOWS\system32\CCM\Cache\N0004E.1.System\Office2003.EXE/WISE0007.BIN Infected: not-a-virus:RiskTool.Win32.PsKill.e skipped
C:\WINDOWS\system32\CCM\Cache\N0004E.1.System\Office2003.EXE WiseSFX: infected - 1 skipped
C:\WINDOWS\system32\CCM\Cache\N0004E.1.System\Utils\pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.e skipped
C:\WINDOWS\system32\CCM\Logs\CAS.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\CcmExec.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\CertificateMaintenance.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\ClientIDManagerStartup.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\ContentTransferManager.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\DataTransferService.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\execmgr.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\FileSystemFile.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\InventoryAgent.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\LocationServices.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\mtrmgr.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PatchInstall.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PatchUIMonitor.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PolicyAgent.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PolicyAgentProvider.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PolicyEvaluator.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\Scheduler.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\SrcUpdateMgr.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\StatusAgent.log Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\00003A.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\00003A.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\000027.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\000027.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\00001O.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\00001O.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\000019.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\000019.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\00006W.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\00006W.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\00004C.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\00004C.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\000018.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\000018.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000D.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000D.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\0000MR.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\0000MR.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\00007D.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\00007D.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\0000GD.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\0000GD.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\00003W.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\00003W.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_fl08edm02_mp_locationmanager\000007.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_fl08edm02_mp_locationmanager\000007.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_il27edm01_mp_locationmanager\000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_il27edm01_mp_locationmanager\000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\000009.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\000009.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000B.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000B.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_relayendpoint\000009.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_relayendpoint\000009.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_sinvendpoint\000009.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_sinvendpoint\000009.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\000056.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\000056.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\00005E.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\00005E.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\0000F6.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\0000F6.que Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\csc\000001 Object is locked skipped
D:\Data\outlook.ost Object is locked skipped
D:\eMail\archive.pst Object is locked skipped
D:\Profiles\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
D:\Profiles\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
D:\Profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
D:\Profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
D:\Profiles\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineDB80000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
D:\Profiles\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineDB80001.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
D:\Profiles\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineDB80002.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
D:\Profiles\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineDB80003.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
D:\Profiles\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineDB80004.VBN Infected: Trojan-Downloader.Win32.Agent.bls skipped
D:\Profiles\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineDB80005.VBN Infected: Trojan-Downloader.Win32.Agent.bls skipped
D:\Profiles\cmni58\Application Data\Microsoft\Outlook\NewProf.NK2 Object is locked skipped
D:\Profiles\cmni58\Application Data\Microsoft\Outlook\NewProf.srs Object is locked skipped
D:\Profiles\cmni58\Application Data\Microsoft\Word\~WRA0004.wbk Object is locked skipped
D:\Profiles\cmni58\Application Data\Microsoft\Word\~WRL3387.tmp Object is locked skipped
D:\Profiles\cmni58\Cookies\index.dat Object is locked skipped
D:\Profiles\cmni58\Local Settings\Application Data\ApplicationHistory\OUTLOOK.EXE.44b47de0.ini.inuse Object is locked skipped
D:\Profiles\cmni58\Local Settings\Application Data\ApplicationHistory\WINWORD.EXE.9fa088d9.ini.inuse Object is locked skipped
D:\Profiles\cmni58\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Profiles\cmni58\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Profiles\cmni58\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Profiles\cmni58\Local Settings\History\History.IE5\MSHist012007042320070424\index.dat Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\ExchangePerflog_8484fa3133bdf2396d6853f0.dat Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\Perflib_Perfdata_69c.dat Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\~DF4458.tmp Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\~DF4462.tmp Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\~DF472A.tmp Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\~DF6046.tmp Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\~DF904F.tmp Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\~DFCA08.tmp Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\~WRD2119.doc Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\~WRF0005.tmp Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temp\~WRS2365.tmp Object is locked skipped
D:\Profiles\cmni58\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Profiles\cmni58\My Documents\Jim O'Kane personal folder.pst Object is locked skipped
D:\Profiles\cmni58\ntuser.dat Object is locked skipped
D:\Profiles\cmni58\NTUser.Dat.LOG Object is locked skipped
D:\Profiles\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Profiles\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Profiles\LocalService\ntuser.dat Object is locked skipped
D:\Profiles\LocalService\NTUser.Dat.LOG Object is locked skipped
D:\Profiles\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Profiles\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Profiles\NetworkService\ntuser.dat Object is locked skipped
D:\Profiles\NetworkService\NTUser.Dat.LOG Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.


Again…. Thanks
Hello :)

Disable system restore:
  • Right click on my computer icon
  • Choose properties
  • Click on system restore tab
  • Select Turn off System Restore
  • Click apply and click OK
  • Reboot!
Enable system restore:
  • Right click on my computer icon
  • Choose properties
  • Click on system restore tab
  • un-check Turn off System Restore
  • Click apply and click OK
  • Reboot!

Please post a fresh HijackThis log once again.
here's the fresh log

Thanks,

Logfile of HijackThis v1.99.1
Scan saved at 2:34:57 PM, on 4/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\System32\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ISS\DesktopProtection\blackd.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Audible\Bin\adhelper.exe
C:\Program Files\Dell\Bluetooth Software\BTTray.exe
C:\Program Files\ISS\DesktopProtection\blackice.exe
C:\PROGRA~1\Dell\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
D:\Profiles\cmni58\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.mot.com:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.mot.com;*.gi.com;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: LLIEHlprObj Class - {F757FBBF-10E5-4DDA-BBEA-2357E54BEA2B} - C:\Program Files\Open Text\Livelink Explorer\LLBHO3.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\System32\ZCfgSvc.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [CSCAdvantage] "C:\Program Files\Help Desk\CSCAdv.exe" /s
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - Startup: Livelink Explorer Synchronizer.lnk = C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\adhelper.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O4 - Global Startup: SysTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9A04E3F0-3BB2-11D2-91E2-00C04FAEC46B} (NMClient Class) - http://meet-amer.mot.com/ConferencingBin/xcliacc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\Software\..\Telephony: DomainName = ds.mot.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.mot.com,ds.mot.com,sps.mot.com,mot.com
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\DesktopProtection\blackd.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Motorola MVP\Extranet_serv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\DesktopProtection\RapApp.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\WINDOWS\System32\WLKeeper.exe
Hello :)

Your HijackThis log is clean! How is your computer running now?

Here are some tricks how to stay clean:
  • Clean speech:
  • Use Mozilla firefox or Opera as your browser!
    Mozilla firefox or Opera are better than Internet Explorer.
    Download Mozilla firefox from here!
    Download Opera from here!
  • Install Hosts-file!
    Hosts-file blocks bad web addresses. Remember to update hosts-file regularly.
    Download Hosts-file from here!
  • Install Winpatrol!
    Winpatrol monitors your system and blocks hijacks.
    Download Winpatrol from here!
  • Install AVG Anti-Spyware!
    AVG anti-spyware detecs and removes malware and cleans your register too. Run a scan with Ad-aware regularly and update it before the scan.
    Download AVG anti-spyware from here!
  • Install Ccleaner!
    CCleaner cleans your temporary files and also cleans your register. Run CCleaner regularly.
    Download CCleaner from here!
  • Install Ad-Aware!
    Ad-aware detecs and removes malware and cleans your register too. Run a scan with Ad-aware regularly and update it before the scan.
    Download Ad-aware from here!
  • Install SpywareBlaster!
    Spywareblaster blocks bad activeX-components. Update it regularly.
    Download Spywareblaster from here!
  • System restore!
    Clean and create new system restore point regularly.
    How do I clean my system restore and create new system restore point?
    Here are instructions!
  • Keep all programs updated!
    Remember to keep all programs up-to-date, also Windows. So please visit here regularly and install all critical updates.
Yes, my computer seems to be much happier now. A few questions. The files that I deleted are in my recycle bin. Should I empty the bin? I'm guessing yes but it never hurts to ask. Also when I open some emails (i think those that have not used Microsoft Word as the email editor) I get a message that a program is attempting to access my email addresses and asks me to decide whether or not to allow this. I always check No. Any idea what is going on? Many Many thanks for your assistance. This is a fantastic forum and you all are always very helpful. Jim
Hello :)

The files that I deleted are in my recycle bin. Should I empty the bin?

Yes, empty your recycle bin.


I'm guessing yes but it never hurts to ask. Also when I open some emails (i think those that have not used Microsoft Word as the email editor) I get a message that a program is attempting to access my email addresses and asks me to decide whether or not to allow this. I always check No. Any idea what is going on?

I'd say if they're opening e-mails, the message is probably normal.


And you're welcome ;)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI