This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Having Problems With Popup Ads When Opening Ie7

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am new to this forum and greatly appreciate any help that someone might be able to give.

I am running Windows XP with all updates, and IE7. I am having issues with anytime I open IE after a period of time I start receiving annoying ad popups. The popups do not occur unless I open IE (this issue also does not occur when I use Firefox). I have run McAfee virus scan, Spybot, and AdAware, and while they have found items that have been removed, the problem still persists.


I have included my HJT log below. Please forgive me if I have not included something that is needed to help you assist me in removing of this.


Logfile of HijackThis v1.99.1
Scan saved at 4:35:51 AM, on 06/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\WINDOWS\system32\WCEFLMS.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\WINDOWS\system32\igfxpers.exe
D:\HP\HP Software Update\HPWuSchd2.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
D:\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\r_server.exe
G:\ZoneAlarm\ZoneAlarm\ZoneAlarm\zapro.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
D:\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
G:\mirc\mirc.exe
C:\Firefox2\firefox.exe
E:\HiJackThis\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.44.216.72:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SpyBot\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {9b76f44c-66ba-448f-b9df-4c4ca43c6fac} - C:\WINDOWS\system32\c_8est.dll
O2 - BHO: (no name) - {DEBEB52F-CFA6-4647-971F-3EDB75B63AFA} - C:\WINDOWS\system32\tmp47.tmp.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - E:\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [WCEFLMS] WCEFLMS.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O5 "LPT1:" /M "Stylus C82"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Auto EPSON Stylus C82 Series on PAGECOLMARKETIN] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P47 "Auto EPSON Stylus C82 Series on PAGECOLMARKETIN" /O34 "\\PAGECOLMARKETIN\EPSON Stylus C82" /M "Stylus C82"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [\\PAGECOLMARKETIN\EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P41 "\\PAGECOLMARKETIN\EPSON Stylus C82 Series" /O5 "LPT1:" /M "Stylus C82"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe
O4 - HKLM\..\Run: [HP Software Update] D:\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Install.exe] C:\WINDOWS\svchost.exe
O4 - HKCU\..\Run: [TransTask] "C:\TweakXPPro\transtask.exe"
O4 - HKCU\..\Run: [Tweak-XP Pro] C:\TweakXPPro\autostart.exe
O4 - HKCU\..\Run: [PRIVMGR] F:\Anonymizer\Privacy Manager\privmgr.exe /min /autostart
O4 - HKCU\..\Run: [NBJ] "D:\Nero\Nero63120\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /M "Stylus C82" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = G:\ZoneAlarm\ZoneAlarm\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Download All by FlashGet - E:\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - E:\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} - http://survey.otxresearch.com/Preloader.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_5.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/0385fe2ae3f61be46202/…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1179439087425
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC6C7545-5563-465F-9E58-7FA73CF1506E}: NameServer = 68.87.85.98,67.166.9.242,71.237.116.215
O17 - HKLM\System\CCS\Services\Tcpip\..\{FDBF65E2-06D3-442D-9B20-0D5FC97C4421}: NameServer = 68.87.85.98,67.166.9.242
O20 - AppInit_DLLs: c:\windows\system32\vtsqrsp.dll
O20 - Winlogon Notify: c_8est - C:\WINDOWS\SYSTEM32\c_8est.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe


Thank you again for any assistance!
Hi tether,

I'm Gary R, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
If you can do these things, everything should go smoothly.
  • Please note you'll need to have Administrator priviledges to perform the fixes. (XP accounts are Administrator by default)
  • Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


There's a few things on your computer, and it'll take a few posts to get you clear. At this point it's not entirely clear what some of those infections may be and I'll need you to run some tests for me to establish what we'll need to do.

First

Go to Control Panel > Add/Remove Programs and uninstall the following.

Viewpoint Manager or anything similarly named.

Then
  • Download combofix.exe by sUBs
  • Alternate Download
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log for you. Post that log in your next reply please.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Now I'd like you to check some files for Viruses.
  • Go to VirusTotal or Jotti's, and scan the following files.

C:\WINDOWS\system32\WCEFLMS.exe
C:\WINDOWS\system32\r_server.exe
C:\WINDOWS\svchost.exe
F:\Anonymizer\Privacy Manager\privmgr.exe

  • NOTE: There is a legit svchost.exe but that is in the C:\Windows\System32 folder.
  • Click on the Browse button at the top of the screen.
  • Browse to the first file on the list.
  • Click OK.
  • Click Send, and the file will upload to VirusTotal / Jotti, where it will be scanned by several anti-virus programmes.
  • After a while, a window will open, with details of what the scans found.
  • Note details of any viruses found.
  • Repeat for all files on the list, and post me the details please, along with the Combofix log and a new HJT log please..
GaryR,

Thank you so much for your reply and your assistance with this!

1) I did remove Viewpoint Manager using Add/Remove Programs from Control Panel

2) ComboFix was run and here is the resulting Log:

"Mike" - 2007-06-07 4:23:44 Service Pack 2 NTFS
ComboFix 07-06-3B - Running from: "C:\Documents and Settings\Mike\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\kstgdb.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((( Files Created from 2007-05-07 to 2007-06-07 )))))))))))))))))))))))))))))))


2007-06-06 13:13 50,970 –a—— C:\DOCUME~1\Mike\APPLIC~1\tmp54.tmp.exe
2007-06-06 11:28 47,899 –a—— C:\WINDOWS\system32\mljji.exe
2007-06-06 11:18 d——– C:\VundoFix Backups
2007-06-05 10:51 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
2007-06-05 05:12 1,227 –a—— C:\WINDOWS\mozver.dat
2007-06-04 21:00 0 –a—— C:\WINDOWS\nsreg.dat
2007-06-04 20:56 d——– C:\Firefox2
2007-06-04 20:47 252,166 –a—— C:\DOCUME~1\Mike\APPLIC~1\tmpAB.tmp.exe
2007-06-04 20:47 2,560 –a—— C:\DOCUME~1\Mike\APPLIC~1\tmpAC.tmp.exe
2007-06-04 18:47 71,496 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-06-04 18:47 37,480 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-06-04 18:47 34,184 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2007-06-04 18:47 32,008 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2007-06-04 18:47 170,408 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2007-06-04 18:47 109,608 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2007-06-04 18:46 d——– C:\Program Files\McAfee.com
2007-06-04 18:46 d——– C:\Program Files\McAfee
2007-06-04 18:46 d——– C:\Program Files\Common Files\McAfee
2007-06-04 18:37 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-06-04 17:52 58,796 –a—— C:\WINDOWS\klvkx.exe
2007-06-04 17:52 12,010 ——— C:\WINDOWS\system32\vtsqrsp.dll
2007-06-01 14:19 d——– C:\DOCUME~1\Mike\APPLIC~1\SlySoft
2007-06-01 14:19 d——– C:\DOCUME~1\Mike\APPLIC~1\Elaborate Bytes
2007-05-31 15:44 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
2007-05-31 14:50 d——– C:\DOCUME~1\Mike\APPLIC~1\HP
2007-05-31 14:50 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
2007-05-31 14:48 d——– C:\Program Files\Hewlett-Packard
2007-05-31 14:47 d——– C:\Program Files\Common Files\HP
2007-05-31 14:46 48,640 –a—— C:\WINDOWS\system32\hpzll4pi.dll
2007-05-31 14:45 94,208 –a—— C:\WINDOWS\system32\HPZipt12.dll
2007-05-31 14:45 69,632 –a—— C:\WINDOWS\system32\HPZipm12.exe
2007-05-31 14:45 65,536 –a—— C:\WINDOWS\system32\HPZinw12.exe
2007-05-31 14:45 57,344 –a—— C:\WINDOWS\system32\HPZisn12.dll
2007-05-31 14:45 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-05-31 14:45 282,680 –a—— C:\WINDOWS\system32\HPZidr12.dll
2007-05-31 14:45 204,800 –a—— C:\WINDOWS\system32\HPZipr12.dll
2007-05-31 14:41 14,916 ——— C:\WINDOWS\hphmdl12.dat
2007-05-31 14:41 124,465 –a—— C:\WINDOWS\HPHins12.dat
2007-05-31 14:37 77,824 –a—— C:\WINDOWS\system32\hpzids01.dll
2007-05-31 14:27 56 –a—— C:\ut9x.bat
2007-05-31 14:27 54 –a—— C:\ut.bat
2007-05-31 14:18 d——– C:\Program Files\Hp
2007-05-31 14:17 d——– C:\Temp\FixEngine
2007-05-24 06:46 66,736 ——— C:\WINDOWS\system32\drivers\PnP680.sys
2007-05-23 14:10 d——– C:\DOCUME~1\Mike\APPLIC~1\ZoomBrowser EX
2007-05-23 14:04 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\ZoomBrowser
2007-05-23 14:03 d——– C:\Program Files\Common Files\Canon
2007-05-20 17:43 d——– C:\DOCUME~1\Mike\APPLIC~1\Google
2007-05-19 20:16 31,232 -r-hs—- C:\WINDOWS\system32\msfDX.dll
2007-05-19 16:21 d–hs—- C:\RECYCLER
2007-05-17 20:54 d——– C:\Program Files\COMPAQ
2007-05-17 15:49 88,064 ——— C:\WINDOWS\system32\Baspxp32.dll
2007-05-17 15:49 d——– C:\WINDOWS\system32\DRVSTORE
2007-05-17 15:49 d——– C:\Program Files\Broadcom
2007-05-17 15:38 150,528 –a—— C:\WINDOWS\system32\drivers\b57xp32.sys
2007-05-17 14:28 606,684 –a—— C:\WINDOWS\system32\drivers\ltmdmnt.sys
2007-05-17 14:06 d——– C:\AVG
2007-05-17 13:43 135,168 ——— C:\WINDOWS\system32\igfxres.dll
2007-05-17 13:38 978,944 ——— C:\WINDOWS\SynthCoreA.Dll
2007-05-17 13:38 720,896 –a—— C:\WINDOWS\system32\a3d.dll
2007-05-17 13:38 578,304 ——— C:\WINDOWS\system32\drivers\smwdm.sys
2007-05-17 13:38 49,152 ——— C:\WINDOWS\system32\S11thk32.dll
2007-05-17 13:38 49,152 ——— C:\WINDOWS\system32\DSndUp.exe
2007-05-17 13:38 45,056 ——— C:\WINDOWS\system32\SynthCore11Resources.dll
2007-05-17 13:38 45,056 ——— C:\WINDOWS\system32\CleanUp.exe
2007-05-17 13:38 44 ——— C:\WINDOWS\system32\msssc.dll
2007-05-17 13:38 40,820 ——— C:\WINDOWS\system32\Syncor11.dll
2007-05-17 13:38 380,928 ——— C:\WINDOWS\SynCor.exe
2007-05-17 13:38 30,208 ——— C:\WINDOWS\system32\wdmioctl.dll
2007-05-17 13:38 3,744 ——— C:\WINDOWS\system32\drivers\smsens.sys
2007-05-17 13:38 100,224 ——— C:\WINDOWS\system32\drivers\aeaudio.sys
2007-05-17 13:38 1,285,632 ——— C:\WINDOWS\system32\SMMedia.dll
2007-05-17 13:38 d——– C:\Program Files\Analog Devices
2007-05-17 13:35 d——– C:\Program Files\Intel
2007-05-17 13:34 d——– C:\SWSetup
2007-05-17 13:13 d——– C:\WINDOWS\Prefetch
2007-05-17 12:57 24,661 –a—— C:\WINDOWS\system32\spxcoins.dll
2007-05-17 12:57 13,312 –a—— C:\WINDOWS\system32\irclass.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-07 10:21:49 ——– d—–w C:\Program Files\Viewpoint
2007-06-03 02:05:04 ——– d—–w C:\Program Files\DivX
2007-05-31 21:41:13 ——– d—–w C:\Program Files\EPSON
2007-05-27 11:57:19 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\OfficeUpdate12
2007-05-23 20:06:27 ——– d—–w C:\Program Files\Canon
2007-05-23 20:06:09 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-05-20 23:43:55 ——– d—–w C:\Program Files\Google
2007-05-17 19:05:28 23,348 ——w C:\WINDOWS\system32\emptyregdb.dat
2007-04-25 10:45:28 ——– d—–w C:\Program Files\MSXML 6.0
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-03-23 12:07:56 1,683,280 ——w C:\WINDOWS\system32\XpsSvcs.dll
2007-03-23 12:07:54 583,504 ——w C:\WINDOWS\system32\XPSSHHDR.dll
2007-03-23 02:25:02 124,928 ——w C:\WINDOWS\system32\prntvpt.dll
2007-03-17 13:43:02 292,864 —-a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 —-a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 —-a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 —-a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 —-a-w C:\WINDOWS\system32\win32k.sys
2007-03-07 23:51:00 129,784 ——w C:\WINDOWS\system32\pxafs.dll
2005-05-13 23:12:00 217,073 –sh–r C:\WINDOWS\meta4.exe
2005-10-24 17:13:58 66,560 –sh–r C:\WINDOWS\MOTA113.exe
2005-07-14 18:31:20 27,648 –sh–r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 21:32:28 616,448 –sh–r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 04:37:42 45,568 –sh–r C:\WINDOWS\system32\cygz.dll
2006-05-03 09:06:54 163,328 –sh–r C:\WINDOWS\system32\flvDX.dll
2004-01-25 06:00:00 70,656 –sh–r C:\WINDOWS\system32\i420vfw.dll
2005-02-28 19:16:22 240,128 –sh–r C:\WINDOWS\system32\x.264.exe
2004-01-25 06:00:00 70,656 –sh–r C:\WINDOWS\system32\yv12vfw.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=D:\SpyBot\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{7DB2D5A0-7241-4E79-B68D-6309F01C5231}=c:\program files\mcafee\virusscan\scriptcl.dll [2006-12-22 16:02]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WCEFLMS"="WCEFLMS.exe" [2001-09-27 13:45 C:\WINDOWS\system32\WCEFLMS.EXE]
"AtiPTA"="atiptaxx.exe" [2001-09-27 01:39 C:\WINDOWS\system32\atiptaxx.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 01:50]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-01-31 15:31]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 15:22]
"DrvLsnr"="C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe" [2003-05-08 11:34]
"SetRefresh"="C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe" [2003-11-20 18:01]
"HP Software Update"="D:\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TransTask"="C:\TweakXPPro\transtask.exe" []
"Tweak-XP Pro"="C:\TweakXPPro\autostart.exe" []
"Pop-Up-Blocker"="" []
"TransparentIcons"="" []
"PRIVMGR"="F:\Anonymizer\Privacy Manager\privmgr.exe" []
"NBJ"="D:\Nero\Nero63120\Nero BackItUp\NBJ.exe" [2004-07-26 19:14]
"EPSON Stylus C82 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.exe" [2003-10-15 04:02]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 21:00]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeStartMenu"=0 (0x0)
"NoClose"=0 (0x0)
"NoLogOff"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\vtsqrsp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRIVANAL]
C:\TweakXP\Tweak-xp.exe -ex

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*


Contents of the 'Scheduled Tasks' folder
2007-06-05 00:46:56 C:\WINDOWS\tasks\McDefragTask.job
2007-06-05 00:46:54 C:\WINDOWS\tasks\McQcTask.job
2007-06-07 10:30:44 C:\WINDOWS\tasks\MP Scheduled Scan.job
2007-06-07 10:22:01 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-07 04:27:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
EPSON Stylus C82 Series = C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /M "Stylus C82" /EF "HKCU"???????$?????R?2????????????????h?w??>???????????????T???T??????????????h?w??T???T?????????8???????????-??w??T???T????????w??T???T?????)??|???????

scanning hidden files …

**************************************************************************

Completion time: 2007-06-07 4:31:55 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-06-07 04:31

— E O F —


3) I could not find C:\WINDOWS\svchost.exe, or F:\Anonymizer\Privacy Manager\privmgr.exe on my machine so I could not scan them at VirusTotal. I also did not scan C:\WINDOWS\system32\r_server.exe file as I know that file is for the program Remote Administrator V2.2 which I installed in order to have access to other machines on my home network. I did scan C:\WINDOWS\system32\WCEFLMS.exe and here is the result log:

Complete scanning result of "WCEFLMS.EXE", received in VirusTotal at 06.07.2007, 12:38:01 (CET).

Antivirus Version Update Result
AhnLab-V3 2007.5.31.2 06.07.2007 no virus found
AntiVir 7.4.0.32 06.06.2007 no virus found
Authentium 4.93.8 05.23.2007 no virus found
Avast 4.7.997.0 06.06.2007 no virus found
AVG 7.5.0.467 06.06.2007 no virus found
BitDefender 7.2 06.07.2007 no virus found
CAT-QuickHeal 9.00 06.06.2007 no virus found
ClamAV devel-20070416 06.07.2007 no virus found
DrWeb 4.33 06.07.2007 no virus found
eSafe 7.0.15.0 06.06.2007 no virus found
eTrust-Vet 30.7.3698 06.07.2007 no virus found
Ewido 4.0 06.07.2007 no virus found
FileAdvisor 1 06.07.2007 No threat detected
Fortinet 2.85.0.0 06.07.2007 no virus found
F-Prot 4.3.2.48 06.06.2007 no virus found
F-Secure 6.70.13030.0 06.07.2007 no virus found
Ikarus T3.1.1.8 06.07.2007 no virus found
Kaspersky 4.0.2.24 06.07.2007 no virus found
McAfee 5047 06.06.2007 no virus found
Microsoft 1.2503 06.07.2007 no virus found
NOD32v2 2314 06.06.2007 no virus found
Norman 5.80.02 06.06.2007 no virus found
Panda 9.0.0.4 06.07.2007 no virus found
Prevx1 V2 06.07.2007 no virus found
Sophos 4.18.0 06.01.2007 no virus found
Sunbelt 2.2.907.0 06.04.2007 no virus found
Symantec 10 06.07.2007 no virus found
TheHacker [removed] 06.06.2007 no virus found
VBA32 3.12.0 06.06.2007 no virus found
VirusBuster 4.3.23:9 06.06.2007 no virus found
Webwasher-Gateway 6.0.1 06.07.2007 no virus found

Aditional Information
File size: 13312 bytes
MD5: da964bc70c292dc3eb60140e3e7d3083
SHA1: e914563fa1e6a04aa38ddf28795a7afc3d604c21
Bit9 info: http://fileadvisor.bit9.com/services/extin…b60140e3e7d3083

And finally,
4) Here is the updated HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 4:54:14 AM, on 06/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\r_server.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\WCEFLMS.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
D:\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
D:\HP\Digital Imaging\bin\hpqtra08.exe
G:\ZoneAlarm\ZoneAlarm\ZoneAlarm\zapro.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
D:\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Firefox2\firefox.exe
C:\WINDOWS\explorer.exe
E:\HiJackThis\Hijackthis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.44.216.72:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SpyBot\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7bac5516-65c1-4786-beb8-a62b80b596df} - C:\WINDOWS\system32\CpuiXEC.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [WCEFLMS] WCEFLMS.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe
O4 - HKLM\..\Run: [HP Software Update] D:\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TransTask] "C:\TweakXPPro\transtask.exe"
O4 - HKCU\..\Run: [Tweak-XP Pro] C:\TweakXPPro\autostart.exe
O4 - HKCU\..\Run: [PRIVMGR] F:\Anonymizer\Privacy Manager\privmgr.exe /min /autostart
O4 - HKCU\..\Run: [NBJ] "D:\Nero\Nero63120\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /M "Stylus C82" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = G:\ZoneAlarm\ZoneAlarm\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Download All by FlashGet - E:\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - E:\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\CpuiXEC.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\CpuiXEC.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} - http://survey.otxresearch.com/Preloader.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_5.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/0385fe2ae3f61be46202/…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1179439087425
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC6C7545-5563-465F-9E58-7FA73CF1506E}: NameServer = 68.87.85.98,67.166.9.242,71.237.116.215
O17 - HKLM\System\CCS\Services\Tcpip\..\{FDBF65E2-06D3-442D-9B20-0D5FC97C4421}: NameServer = 68.87.85.98,67.166.9.242
O20 - AppInit_DLLs: c:\windows\system32\vtsqrsp.dll
O20 - Winlogon Notify: CpuiXEC - C:\WINDOWS\SYSTEM32\CpuiXEC.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe

Again, GaryR thank you so much for your time and effort with this!

tether (Mike)
Hi tether,

OK, looks like this one is putting up a fight. We'll try a different tool to attack it (there'll still be some work to do once the main infection is cleared).

Sorry, I forgot to give you some instructions in my first post before asking you to look for files.

Make sure that you can see hidden files and folders.
  • Click Start.
  • Click My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Click Yes to confirm.
  • Uncheck the Hide file extensions for known file types.
  • Uncheck Hide protected operating system files a pop up will appear, answer Yes
  • Click OK.
Now see if you can find.

C:\WINDOWS\svchost.exe
F:\Anonymizer\Privacy Manager\privmgr.exe


If found scan them at VirusTotal or Jotti's and let me know what they find (if anything). If they're still not present let me know.

We need to disable Spybot S&D Teatimer as it will interfere with things.

To disable Spybot S&D TeaTimer
  • Run Spybot-S&D
  • Go to the Mode menu, and make sure Advanced Mode is selected.
  • On the left hand side, choose Tools -> Resident
  • Uncheck Resident TeaTimer and OK any prompts.
  • Restart your computer.
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HijackThis log. Plus the VirusTotal/Jotti's results if applicable.
Note: It is possible that VundoFix will encounter a file it can't remove. In this case, VundoFix will run on reboot. Simply follow the above instructions starting from Click the Scan for Vundo button when VundoFix appears at reboot.

I notice you have entries for both Symantec and MacAfee on your computer, are you running two anti-virus programmes, or are there remnants from an old Norton/Symantec install still on your computer?

Let me know. It is not possible to run two AVs on the same computer without having conflicts (especially with Norton and MacAfee), if you are running two you must uninstall one at once. If one is just remnants, they'll still need removing but I can instruct you how to do it.
GaryR, Good Morning! After your last post here are the results: 1) Made all changes in the Folder Options per your instructions. However, I still cannot find either C:\WINDOWS\svchost.exe or F:\Anonymizer\Privacy Manager\privmgr.exe files. Before you initially responded to my first post, I did run SpyBot, AdAware, and McAfee AV in Safe Mode, so is it possible that they removed those files? I did run a scan at VirusTotal for r_server.exe as you requested and here is the scan results: Complete scanning result of "r_server.exe", received in VirusTotal at 06.07.2007, 15:56:37 (CET). Antivirus Version Update Result AhnLab-V3 2007.5.31.2 06.07.2007 no virus found AntiVir 7.4.0.32 06.07.2007 no virus found Authentium 4.93.8 05.23.2007 no virus found Avast 4.7.997.0 06.07.2007 no virus found AVG 7.5.0.467 06.06.2007 Potentially harmful program RemoteAdmin.EA BitDefender 7.2 06.07.2007 no virus found CAT-QuickHeal 9.00 06.07.2007 no virus found ClamAV devel-20070416 06.07.2007 no virus found DrWeb 4.33 06.07.2007 no virus found eSafe 7.0.15.0 06.06.2007 no virus found eTrust-Vet 30.7.3699 06.07.2007 no virus found Ewido 4.0 06.07.2007 Not-A-Virus.RemoteAdmin.Win32.RAdmin.22 FileAdvisor 1 06.07.2007 no virus found Fortinet 2.85.0.0 06.07.2007 RAT/RAdmin F-Prot 4.3.2.48 06.07.2007 no virus found F-Secure 6.70.13030.0 06.07.2007 no virus found Ikarus T3.1.1.8 06.07.2007 not-a-virus:RemoteAdmin.Win32.RAdmin.22 Kaspersky 4.0.2.24 06.07.2007 not-a-virus:RemoteAdmin.Win32.RAdmin.22 McAfee 5047 06.06.2007 no virus found Microsoft 1.2503 06.07.2007 RemoteAccess:Win32/RServer (threat-c) NOD32v2 2315 06.07.2007 Win32/RAdmin.22 Norman 5.80.02 06.07.2007 no virus found Panda 9.0.0.4 06.07.2007 no virus found Prevx1 V2 06.07.2007 no virus found Sophos 4.18.0 06.01.2007 no virus found Sunbelt 2.2.907.0 06.04.2007 no virus found Symantec 10 06.07.2007 Remacc.Radmin TheHacker 6.1.6.130 06.06.2007 Aplicacion/RAdmin.22 VBA32 3.12.0 06.06.2007 no virus found VirusBuster 4.3.23:9 06.06.2007 no virus found Webwasher-Gateway 6.0.1 06.07.2007 no virus found Aditional Information File size: 708608 bytes MD5: 7a67446b8c0d917d540af1088b3c8c17 SHA1: ecc46682ba236d234bfcb28ef3813308bf79b158 2) I disabled Resident Tea-Timer in SpyBot and re-booted. 3) I ran VundoFix and it did find one file, C:\WINDOWS\system32\vtsqrsp.dll, that seems to not want to be erased so maybe it is our culprit? After re-boots of VundoFix that file is still there. Here is the log results from VundoFix: VundoFix V6.4.2 Checking Java version… Java version is 1.4.2.1 Old versions of java are exploitable and should be removed. Java version is 1.4.2.6 Old versions of java are exploitable and should be removed. Java version is 1.5.0.2 Old versions of java are exploitable and should be removed. Java version is 1.5.0.4 Old versions of java are exploitable and should be removed. Java version is 1.5.0.6 Old versions of java are exploitable and should be removed. Java version is 1.5.0.9 Old versions of java are exploitable and should be removed. Java version is 1.5.0.10 Java version is 1.5.0.11 Scan started at 8:16:49 AM 06/07/2007 Listing files found while scanning…. C:\WINDOWS\system32\vtsqrsp.dll Beginning removal… Attempting to delete C:\WINDOWS\system32\vtsqrsp.dll C:\WINDOWS\system32\vtsqrsp.dll Could not be deleted. Performing Repairs to the registry. Done! Beginning removal… Attempting to delete C:\WINDOWS\system32\vtsqrsp.dll C:\WINDOWS\system32\vtsqrsp.dll Could not be deleted. Performing Repairs to the registry. Done! Beginning removal… I did not re-run scan from HiJackThis yet as you did not request it. 4) I currently run McAfee AntiVirus on this machine. I used to run Nortons AV but I un-installed it some time ago. Thanks again for your help!
Gary R,

I hope you don't mind, but I went a head and scanned C:\Windows\System32\vtsqrsp.dll at VirusTotal and here are the results:


Complete scanning result of "vtsqrsp.dll", received in VirusTotal at 06.07.2007, 17:12:20 (CET).

Antivirus Version Update Result
AhnLab-V3 2007.5.31.2 06.07.2007 no virus found
AntiVir 7.4.0.32 06.07.2007 TR/Crypt.XPACK.Gen
Authentium 4.93.8 05.23.2007 no virus found
Avast 4.7.997.0 06.07.2007 no virus found
AVG 7.5.0.467 06.07.2007 Generic4.SKM
BitDefender 7.2 06.07.2007 Trojan.Downloader.Agent.YDN
CAT-QuickHeal 9.00 06.07.2007 Trojan.Agent.bi
ClamAV devel-20070416 06.07.2007 no virus found
DrWeb 4.33 06.07.2007 no virus found
eSafe 7.0.15.0 06.06.2007 no virus found
eTrust-Vet 30.7.3699 06.07.2007 no virus found
Ewido 4.0 06.07.2007 no virus found
FileAdvisor 1 06.07.2007 No threat detected
Fortinet 2.85.0.0 06.07.2007 W32/Agent.BI!tr
F-Prot 4.3.2.48 06.07.2007 no virus found
F-Secure 6.70.13030.0 06.07.2007 Trojan.Win32.Agent.bi
Ikarus T3.1.1.8 06.07.2007 no virus found
Kaspersky 4.0.2.24 06.07.2007 Trojan.Win32.Agent.bi
McAfee 5047 06.06.2007 no virus found
Microsoft 1.2503 06.07.2007 no virus found
NOD32v2 2316 06.07.2007 no virus found
Norman 5.80.02 06.07.2007 no virus found
Panda 9.0.0.4 06.07.2007 Suspicious file
Prevx1 V2 06.07.2007 SpywareQuake
Sophos 4.18.0 06.01.2007 no virus found
Sunbelt 2.2.907.0 06.04.2007 VIPRE.Suspicious
Symantec 10 06.07.2007 no virus found
TheHacker [removed] 06.06.2007 no virus found
VBA32 3.12.0 06.06.2007 no virus found
VirusBuster 4.3.23:9 06.07.2007 no virus found
Webwasher-Gateway 6.0.1 06.07.2007 Trojan.Crypt.XPACK.Gen

Aditional Information
File size: 12010 bytes
MD5: 17ce50eed06fb7f91bbcbf8d02535d26
SHA1: 035f2fa39bd75f0abcd85f32c4b84181331bb9fd
Bit9 info: http://fileadvisor.bit9.com/services/extin…bbcbf8d02535d26
packers: RLPack
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PXC=e55098092642
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.


Looks bad I guess?
Gary R……I am so sorry, I missed that request. Here is the current HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 1:12:44 PM, on 06/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\r_server.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\WCEFLMS.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
D:\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
D:\HP\Digital Imaging\bin\hpqtra08.exe
G:\ZoneAlarm\ZoneAlarm\ZoneAlarm\zapro.exe
D:\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\ntvdm.exe
E:\HiJackThis\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.44.216.72:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SpyBot\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7bac5516-65c1-4786-beb8-a62b80b596df} - C:\WINDOWS\system32\CpuiXEC.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [WCEFLMS] WCEFLMS.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe
O4 - HKLM\..\Run: [HP Software Update] D:\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TransTask] "C:\TweakXPPro\transtask.exe"
O4 - HKCU\..\Run: [Tweak-XP Pro] C:\TweakXPPro\autostart.exe
O4 - HKCU\..\Run: [PRIVMGR] F:\Anonymizer\Privacy Manager\privmgr.exe /min /autostart
O4 - HKCU\..\Run: [NBJ] "D:\Nero\Nero63120\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /M "Stylus C82" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = G:\ZoneAlarm\ZoneAlarm\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Download All by FlashGet - E:\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - E:\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\CpuiXEC.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\CpuiXEC.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} - http://survey.otxresearch.com/Preloader.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_5.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/0385fe2ae3f61be46202/…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1179439087425
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC6C7545-5563-465F-9E58-7FA73CF1506E}: NameServer = 68.87.85.98,67.166.9.242,71.237.116.215
O17 - HKLM\System\CCS\Services\Tcpip\..\{FDBF65E2-06D3-442D-9B20-0D5FC97C4421}: NameServer = 68.87.85.98,67.166.9.242
O20 - AppInit_DLLs: c:\windows\system32\vtsqrsp.dll
O20 - Winlogon Notify: CpuiXEC - C:\WINDOWS\SYSTEM32\CpuiXEC.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe
OK, lets have another go with this.

Create a System Restore Point
  • Click Start > Run
  • Copy/Paste C:\Windows\System32\Restore\rstrui.exe into the Open: box.
  • Click OK.
  • This will open the System Restore window.
  • Click on Create a Restore Point then click Next.
  • Enter Restore from Reg Changes to the description box, then click Create.
  • A new Restore Point will be created, click Close to exit.
Ensure Spybot S&D Teatimer is disabled.

To disable Spybot S&D TeaTimer
  • Run Spybot-S&D
  • Go to the Mode menu, and make sure Advanced Mode is selected.
  • On the left hand side, choose Tools -> Resident
  • Uncheck Resident TeaTimer and OK any prompts.
  • Restart your computer.
THEN

We need to remove some services.
  • Click Start > Run type Notepad click OK.
  • This will open an empty Notepad file.
  • Copy/Paste the contents of the box below into Notepad.
@ echo off

sc stop "Automatic LiveUpdate Scheduler"
sc delete "Automatic LiveUpdate Scheduler"
sc stop LiveUpdate
sc delete LiveUpdate
sc stop SymWSC
sc delete SymWSC
  • Click Format and ensure Wordwrap is unchecked.
  • Save as RemNorton.bat
  • Save as file type All Files or it won't work.
  • Now double click on RemNorton.bat to run it.
Run a scan with HJT and when finished check the following items (if found).

O2 - BHO: (no name) - {7bac5516-65c1-4786-beb8-a62b80b596df} - C:\WINDOWS\system32\CpuiXEC.dll

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

O4 - HKCU\..\Run: [PRIVMGR] F:\Anonymizer\Privacy Manager\privmgr.exe /min /autostart

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\CpuiXEC.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\CpuiXEC.dll

O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} - http://survey.otxresearch.com/Preloader.dll

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/0385fe2ae3f61be46202/…ip/RdxIE601.cab

O20 - AppInit_DLLs: c:\windows\system32\vtsqrsp.dll

O20 - Winlogon Notify: CpuiXEC - C:\WINDOWS\SYSTEM32\CpuiXEC.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


Now close all open windows and click Fix Checked to remove them.

Download OTMoveIt by OldTimer to your Desktop.
  • Double click OTMoveIt.exe to launch it.
  • Copy/Paste the contents of the box below into the left hand pane of OTMoveIt.

C:\Program Files\Symantec
C:\Program Files\Common Files\Symantec Shared
C:\WINDOWS\system32\CpuiXEC.dll
F:\Anonymizer\Privacy Manager\privmgr.exe
c:\windows\system32\vtsqrsp.dll

  • Click the Move It button.
  • The list will be processed and the results will appear in the right hand pane.
  • If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
  • When finished click Exit to exit the programme.
  • A log C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log will be created (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
  • Post the log back here please, along with a new HJT log.
  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.
Now please do an online scan with Kaspersky Online Scanner

Note: You must be using Internet Explorer as your browser as it will be necessary to install an Active X component to your computer.

Important If you have previously used Kaspersky Online Scanner (before 8th Aug 2006), you will have to uninstall the old version using Add/Remove Programs in Control Panel before you can use the new version.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK.
  • Now under select a target to scan select My Computer.
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post, along with the OTMoveIt log and the new HJT log.
Please post each separately so they don't get cut off by the forum post size limiter.

Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.
Gary R

1) Ran Restore Point in Windows
2) made sure 'TeaTimer' was un-checked in SpyBot
3) Created and ran RemNorton.bat
4) Ran HJT and Fix Checked. Did receive the following error:

An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: c:\windows\system32\vtsqrsp.dll)
Error #5 - Invalid procedure call or argument

Please email me at [removed], reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 7.0.5730.11
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.


5) Ran OTMoveIt and here is the resulting log:

C:\Program Files\Symantec\LiveUpdate moved successfully.
C:\Program Files\Symantec moved successfully.
C:\Program Files\Common Files\Symantec Shared\VirusDefs moved successfully.
C:\Program Files\Common Files\Symantec Shared\SPManifests moved successfully.
C:\Program Files\Common Files\Symantec Shared\Security Center moved successfully.
C:\Program Files\Common Files\Symantec Shared\Registry Backup moved successfully.
C:\Program Files\Common Files\Symantec Shared\LiveReg moved successfully.
C:\Program Files\Common Files\Symantec Shared\Help moved successfully.
C:\Program Files\Common Files\Symantec Shared moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\CpuiXEC.dll
C:\WINDOWS\system32\CpuiXEC.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\CpuiXEC.dll scheduled to be moved on reboot.
File/Folder F:\Anonymizer\Privacy Manager\privmgr.exe not found.
DllUnregisterServer procedure not found in c:\windows\system32\vtsqrsp.dll
c:\windows\system32\vtsqrsp.dll NOT unregistered.
File move failed. c:\windows\system32\vtsqrsp.dll scheduled to be moved on reboot.

Created on 06/07/2007 14:50:19


6) Here is the resulting HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 2:57:57 PM, on 06/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\WINDOWS\system32\WCEFLMS.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
D:\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
D:\HP\Digital Imaging\bin\hpqtra08.exe
G:\ZoneAlarm\ZoneAlarm\ZoneAlarm\zapro.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\r_server.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
D:\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Firefox2\firefox.exe
E:\HiJackThis\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.44.216.72:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SpyBot\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O4 - HKLM\..\Run: [WCEFLMS] WCEFLMS.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe
O4 - HKLM\..\Run: [HP Software Update] D:\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TransTask] "C:\TweakXPPro\transtask.exe"
O4 - HKCU\..\Run: [Tweak-XP Pro] C:\TweakXPPro\autostart.exe
O4 - HKCU\..\Run: [NBJ] "D:\Nero\Nero63120\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /M "Stylus C82" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = G:\ZoneAlarm\ZoneAlarm\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Download All by FlashGet - E:\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - E:\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1179439087425
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC6C7545-5563-465F-9E58-7FA73CF1506E}: NameServer = 68.87.85.98,67.166.9.242,71.237.116.215
O17 - HKLM\System\CCS\Services\Tcpip\..\{FDBF65E2-06D3-442D-9B20-0D5FC97C4421}: NameServer = 68.87.85.98,67.166.9.242
O20 - AppInit_DLLs: c:\windows\system32\vtsqrsp.dll
O20 - Winlogon Notify: CpuiXEC - CpuiXEC.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe

I will next run Cleanmgr, and then the Kaspersky Online Scanner. I will include the log from the Kaspersky Scanner and another HJT log in my next post.


Thank you AGAIN!
Looking better, but one of the files is being stubborn. I'll wait for the Kaspersky log and see what that tells me. Probably be tomorrow before I get back to you.
Gary R, Here is the Kaspersky Scan log: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Thursday, June 07, 2007 5:32:42 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 7/06/2007 Kaspersky Anti-Virus database records: 341449 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ Scan Statistics: Total number of scanned objects: 113781 Number of viruses found: 30 Number of infected objects: 89 Number of suspicious objects: 0 Duration of the scan process: 02:02:09 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{D512892F-E880-4093-B19F-6B07BD51A991}.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR2.tmp Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12062006-084806.log Object is locked skipped C:\Documents and Settings\All Users\Documents\Remote_Admin_22.zip/RADMIN22.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped C:\Documents and Settings\All Users\Documents\Remote_Admin_22.zip/RADMIN22.EXE/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped C:\Documents and Settings\All Users\Documents\Remote_Admin_22.zip/RADMIN22.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped C:\Documents and Settings\All Users\Documents\Remote_Admin_22.zip/rviewer3.exe/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.30 skipped C:\Documents and Settings\All Users\Documents\Remote_Admin_22.zip/rviewer3.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.30 skipped C:\Documents and Settings\All Users\Documents\Remote_Admin_22.zip ZIP: infected - 5 skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\5dgd5jzb.default\cert8.db Object is locked skipped C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\5dgd5jzb.default\history.dat Object is locked skipped C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\5dgd5jzb.default\key3.db Object is locked skipped C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\5dgd5jzb.default\parent.lock Object is locked skipped C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\5dgd5jzb.default\search.sqlite Object is locked skipped C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\5dgd5jzb.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\Mike\Application Data\tmp54.tmp.exe Infected: Trojan.Win32.BHO.g skipped C:\Documents and Settings\Mike\Application Data\tmpAC.tmp.exe Infected: Trojan.Win32.Agent.anr skipped C:\Documents and Settings\Mike\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{BA4FE8CB-FB6F-46B9-9B73-37E2267345DB} Object is locked skipped C:\Documents and Settings\Mike\Local Settings\Application Data\Mozilla\Firefox\Profiles\5dgd5jzb.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Mike\Local Settings\Application Data\Mozilla\Firefox\Profiles\5dgd5jzb.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Mike\Local Settings\Application Data\Mozilla\Firefox\Profiles\5dgd5jzb.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Mike\Local Settings\Application Data\Mozilla\Firefox\Profiles\5dgd5jzb.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Mike\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Mike\Local Settings\History\History.IE5\MSHist012007060720070608\index.dat Object is locked skipped C:\Documents and Settings\Mike\Local Settings\Temp\hpodvd09.log Object is locked skipped C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Mike\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Mike\NTUSER.DAT.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP17\A0004318.exe Infected: Backdoor.Win32.Small.os skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP29\A0005082.exe Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP29\A0005083.exe Infected: Trojan.Win32.Agent.agv skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP29\A0005084.exe Infected: Trojan.Win32.Agent.anr skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP30\A0005100.exe Infected: Trojan.Win32.Agent.anr skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP30\A0005102.exe Infected: Trojan.Win32.Agent.agv skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP30\A0005104.exe Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP30\A0005114.exe Infected: Trojan.Win32.Agent.anr skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP30\A0005116.exe Infected: Trojan.Win32.Agent.agv skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP30\A0005118.exe Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP30\A0005138.exe Infected: Trojan.Win32.Agent.anr skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP30\A0005140.exe Infected: Trojan.Win32.Agent.agv skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP30\A0005142.exe Infected: Trojan.Win32.Agent.bi skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP30\A0005416.dll Infected: Trojan.Win32.Agent.bi skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP36\A0005890.exe Infected: Trojan.Win32.Agent.bi skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP36\A0005953.exe Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP36\A0006007.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP36\A0006007.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP36\A0006007.exe RarSFX: infected - 2 skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP38\A0006087.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ke skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP38\A0006088.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ke skipped C:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP41\change.log Object is locked skipped C:\VundoFix Backups\c_8est.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ke skipped C:\VundoFix Backups\dswnxx.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ke skipped C:\VundoFix Backups\vtsqrsp.dll.bad Infected: Trojan.Win32.Agent.bi skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Internet Logs\HOME.ldb Object is locked skipped C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINDOWS\klvkx.exe Infected: Trojan.Win32.Agent.bi skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{18F75E0A-F6EA-4E53-8205-575DEA5CAA7F}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped C:\WINDOWS\system32\r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\mcmsc_3cKleET25GmjSKZ Object is locked skipped C:\WINDOWS\Temp\mcmsc_fsSLtWnHEKGeFaM Object is locked skipped C:\WINDOWS\Temp\mcmsc_Mx8EaELUZX1je1v Object is locked skipped C:\WINDOWS\Temp\mcmsc_yfugaWsZNkxakKE Object is locked skipped C:\WINDOWS\Temp\ZLT4.tmp Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\_OTMoveIt\MovedFiles\WINDOWS\system32\vtsqrsp.dll Infected: Trojan.Win32.Agent.bi skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped D:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP41\change.log Object is locked skipped E:\FlashGet\fgf140.exe/WISE0018.BIN/cd_clint.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped E:\FlashGet\fgf140.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.Cydoor skipped E:\FlashGet\fgf140.exe WiseSFX: infected - 2 skipped E:\RemoteAdmin\RADMIN21.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped E:\RemoteAdmin\RADMIN21.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped E:\RemoteAdmin\RADMIN21.EXE/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped E:\RemoteAdmin\RADMIN21.EXE/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped E:\RemoteAdmin\RADMIN21.EXE Gentee: infected - 4 skipped E:\RemoteAdmin\RadMin22\raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped E:\RemoteAdmin\RadMin22\RADMIN22.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped E:\RemoteAdmin\RadMin22\RADMIN22.EXE/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped E:\RemoteAdmin\RadMin22\RADMIN22.EXE Gentee: infected - 2 skipped E:\RemoteAdmin\RadMin22\remote_administrator_22.rar/Remote Administrator 22/RADMIN22.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped E:\RemoteAdmin\RadMin22\remote_administrator_22.rar/Remote Administrator 22/RADMIN22.EXE/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped E:\RemoteAdmin\RadMin22\remote_administrator_22.rar/Remote Administrator 22/RADMIN22.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped E:\RemoteAdmin\RadMin22\remote_administrator_22.rar/Remote Administrator 22/rviewer3.exe/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.30 skipped E:\RemoteAdmin\RadMin22\remote_administrator_22.rar/Remote Administrator 22/rviewer3.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.30 skipped E:\RemoteAdmin\RadMin22\remote_administrator_22.rar RAR: infected - 5 skipped E:\RemoteAdmin\RadMin22\rviewer3.exe/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.30 skipped E:\RemoteAdmin\RadMin22\rviewer3.exe CreateInstall: infected - 1 skipped E:\RemoteAdmin\RadMin22\r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped E:\RemoteAdmin\radmin22.zip/RADMIN22.EXE/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped E:\RemoteAdmin\radmin22.zip/RADMIN22.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped E:\RemoteAdmin\radmin22.zip/RADMIN22.EXE/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped E:\RemoteAdmin\radmin22.zip/RADMIN22.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped E:\RemoteAdmin\radmin22.zip ZIP: infected - 4 skipped E:\RemoteAdmin\Remote Adminstrator V2.1 .zip/Remote Adminstrator V2.1 /RADMIN21.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped E:\RemoteAdmin\Remote Adminstrator V2.1 .zip/Remote Adminstrator V2.1 /RADMIN21.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped E:\RemoteAdmin\Remote Adminstrator V2.1 .zip/Remote Adminstrator V2.1 /RADMIN21.EXE/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped E:\RemoteAdmin\Remote Adminstrator V2.1 .zip/Remote Adminstrator V2.1 /RADMIN21.EXE/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped E:\RemoteAdmin\Remote Adminstrator V2.1 .zip/Remote Adminstrator V2.1 /RADMIN21.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped E:\RemoteAdmin\Remote Adminstrator V2.1 .zip ZIP: infected - 5 skipped E:\RemoteAdmin\Remote%20Adminstrator%20V2.1.zip/Remote Adminstrator V2.1 /RADMIN21.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped E:\RemoteAdmin\Remote%20Adminstrator%20V2.1.zip/Remote Adminstrator V2.1 /RADMIN21.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped E:\RemoteAdmin\Remote%20Adminstrator%20V2.1.zip/Remote Adminstrator V2.1 /RADMIN21.EXE/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped E:\RemoteAdmin\Remote%20Adminstrator%20V2.1.zip/Remote Adminstrator V2.1 /RADMIN21.EXE/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped E:\RemoteAdmin\Remote%20Adminstrator%20V2.1.zip/Remote Adminstrator V2.1 /RADMIN21.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped E:\RemoteAdmin\Remote%20Adminstrator%20V2.1.zip ZIP: infected - 5 skipped E:\RemoteAdmin\rviewer3.exe/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.30 skipped E:\RemoteAdmin\rviewer3.exe CreateInstall: infected - 1 skipped E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped E:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP41\change.log Object is locked skipped F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped F:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP41\change.log Object is locked skipped G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped G:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP41\change.log Object is locked skipped G:\WinBNC\bnc.exe Infected: not-a-virus:Server-Proxy.Win32.IrcProxy.264 skipped H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped H:\System Volume Information\_restore{1D9780D0-D719-4596-AB53-4E7769928ED6}\RP41\change.log Object is locked skipped Scan process completed. Sure doesn't seem to like my Remote Admin program does it. Next post will be the current HJT log.
Here is the latest HJT log:


Logfile of HijackThis v1.99.1
Scan saved at 6:28:03 PM, on 06/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\WINDOWS\system32\WCEFLMS.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
D:\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
D:\HP\Digital Imaging\bin\hpqtra08.exe
G:\ZoneAlarm\ZoneAlarm\ZoneAlarm\zapro.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\r_server.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
D:\HP\Digital Imaging\bin\hpqSTE08.exe
G:\mirc\mirc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
E:\HiJackThis\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.44.216.72:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SpyBot\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O4 - HKLM\..\Run: [WCEFLMS] WCEFLMS.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe
O4 - HKLM\..\Run: [HP Software Update] D:\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TransTask] "C:\TweakXPPro\transtask.exe"
O4 - HKCU\..\Run: [Tweak-XP Pro] C:\TweakXPPro\autostart.exe
O4 - HKCU\..\Run: [NBJ] "D:\Nero\Nero63120\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /M "Stylus C82" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = G:\ZoneAlarm\ZoneAlarm\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Download All by FlashGet - E:\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - E:\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1179439087425
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC6C7545-5563-465F-9E58-7FA73CF1506E}: NameServer = 68.87.85.98,67.166.9.242,71.237.116.215
O17 - HKLM\System\CCS\Services\Tcpip\..\{FDBF65E2-06D3-442D-9B20-0D5FC97C4421}: NameServer = 68.87.85.98,67.166.9.242
O20 - AppInit_DLLs: c:\windows\system32\vtsqrsp.dll
O20 - Winlogon Notify: CpuiXEC - CpuiXEC.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe



Gary R, btw the popups with IE open have now stopped so I hope we are making some progress. Thanks again so much for all of your help!
OK, looking better, but still a few things to do.

Run a scan with HJT and when finished check the following items (if found).

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)

O20 - AppInit_DLLs: c:\windows\system32\vtsqrsp.dll

O20 - Winlogon Notify: CpuiXEC - CpuiXEC.dll (file missing)


Now close all open windows and click Fix Checked to remove them.
  • Double click OTMoveIt.exe to launch it.
  • Copy/Paste the contents of the box below into the left hand pane of OTMoveIt.

C:\Documents and Settings\Mike\Application Data\tmp54.tmp.exe
C:\Documents and Settings\Mike\Application Data\tmpAC.tmp.exe
C:\WINDOWS\klvkx.exe
c:\windows\system32\vtsqrsp.dll
E:\FlashGet
C:\VundoFix Backups

  • Click the Move It button.
  • The list will be processed and the results will appear in the right hand pane.
  • If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
  • When finished click Exit to exit the programme.
  • A log C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log will be created (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
  • Post the log back here please, along with a new HJT log.
I can't find anything definitive on the following file G:\WinBNC\bnc.exe if you know the programme, and know it to be OK then leave it alone. If not add G:\WinBNC to the list of things to be removed by OTMoveIt.


Your remote admin programme is being flagged because of the nature of the functions within it. Provided you installed it yourself and know it comes from a clean source, we'll treat Kaspersky's findings as false positives.

Your System Restore Points are also infected, but provided you don't do a System Restore they can't re-infect you. We'll clear them out when we've got the rest of your computer clean. I do it this way just in case we have any unexpected problems, better an infected restore point than no restore point.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI