This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Self-help Troubles

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

That info brought out some hidden items we can address now. It is actually a good sign you are getting those com9.few alerts - it shows us the how the infection was hidden and definitely tells us the file is malicious. We will remove some of the stealth infection now, after which you will need to connect this system to net access to run a scan.

Could you translate for me the following hilighted items please:
Dokumente und Einstellungen\anto
Gemeinsame Dateien



Go to Start - Run, type services.msc (and OK).

On the list locate and double-click on the following item.

RemoteRegistry

Under Service Status, click Stop.

Then using the dropdown box, change the Startup type to Disabled.

Apply/OK and exit.

——————————————-

Again Copy all the text contained in the code box below by highlighting it and right clicking and selecting "Copy"

Drivers to unload:
SrvMyt

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs

Files to delete:
C:\Programme\Gemeinsame Dateien\System\TRm.exe

Now, start The Avenger program by clicking on its icon on your desktop. Look under "Script file to execute" and click on "Input Script Manually". Next click on the Magnifying Glass icon and a blank dialogue box will open called "View/Edit script". Position your mouse inside the box, rightclick and choose Paste. All the text above in the code box should now appear there. Click Done and click on the Green Light to begin execution of the script. Answer "Yes" twice when prompted.

The Avenger will restart your computer. (if the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)

When you have rebooted, a black command window briefly opens on your desktop, this is normal. A logfile will be created that records all actions that The Avenger performed. This log file is saved to C:\avenger.txt. The deleted files will be backed up and saved to C:\avenger\backup.zip.


=================================================

Once your computer has rebooted, download ComboFix.exe from here to your desktop, and click the downloaded file to run the repair.

When the command window opens, select 1 (and Enter). Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

————————————————

Then connect to the internet and disable your antivirus program (be sure to enable it after the scan completes) and go here and run an online scan with BitDefender (you will need to use Internet Explorer for this scan). When the ActiveX Control has loaded, click on "Click here to scan" and grab a coffee.

When BitDefender completes the scan, select the "Detected Problems" tab. Click on "Click here to export scan". Save the file as an HTML to your Desktop. Then click on the saved file and allow it to open with your browser. Go to Edit - Select All. Then copy/paste that log back here, along with the BitDefender log, the avenger.txt log, a HijackThis (with Word Wrap off, bitte) and a Silent Runners log please.
hi Jintan, thanks for staying with me and sorry for the delay, your last message opened up a second page, which i didn't realise immediately! :blink:

ok, here's the translation you requested:
Dokumente und Einstellungen\anto = Documents and Settings\anto (personal data)
Gemeinsame Dateien = Shared Data

that's all for todays german-lesson ;)

first of all, i want to mention that i ran into some problems this time, which i had probably caused myself: to speed things up a bit before doing the onlinescan (last time i tried one it took several hours) i emptied the personal data folder, cleaned the registry with ccleaner and defragged the drive. i have no idea if this was to blame for the problems that arose but i thought you might want to know…
after that i followed your instructions from above:

1. i ran services.msc
stopping the remote registry did not work, the error message was "mistake 1053: The service did't respond in time" (my translation)
setting startup-type to disabled worked though and after a reboot remote registry resulted "disabled".

2. ran Avenger with the Script you provided
it rebooted twice and gave me an error log.

3. i decided to proceed anyway to see what would happen, and combofix.exe spat a bunch of error messages at me, the same as i described in my last post, ("The application or DLL C\:Windows\System32\com9.few is not a valid Windows-file. Please check with your windows-install-cd"), but for the following apps:
dumphive.cfexe, nircmd.cfexe, setpath.cfexe, mtee.cfexe, swreg.cfexe, regt.cfexe,
find.exe, findstr.exe, cattrib.exe
each of which i had to click away dozens of times
AND avg resident warned me about a hidden .bat extention of C:\Cobofix.txt.bat!
the combofix logfile-creation seemed to have gone in tilt, after more than one hour i decided to abort.

4. nonetheless i did the bitdefender online scan which revealed and deletet one trojan (i've posted the report)

5. after that i gave it another try with avenger and this time it worked fine (log posted)

6. combofix worked fine after that as well (log posted)

7. i reran bitdefender, just to be sure, no results there (posted the second log anyway)

8. ran hijackthis (log posted)

9. ran silentrunners (log posted)

phew, a long read for you!!

____________________________________________
here are the logs:

step 2. avenger error log:

//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Fatal error: could not create new script file.
Error code: 1813
Error logged to errorlog.txt. Aborting now!

__________________________________________________
step 4. first bitdefender log:


BitDefender Online Scanner







Scan report generated at: Tue, Jun 26, 2007 - 09:07:34









Scan path: C:\;E:\;















Statistics

Time


00:32:08

Files


142750

Folders


4129

Boot Sectors


2

Archives


1266

Packed Files


7198







Results

Identified Viruses


1

Infected Files


1

Suspect Files


0

Warnings


0

Disinfected


0

Deleted Files


1







Engines Info

Virus Definitions


571425

Engine build


AVCORE v1.0 (build 2410) (i386) (Jun 12 2007 21:08:27)

Scan plugins


14

Archive plugins


38

Unpack plugins


6

E-mail plugins


6

System plugins


1







Scan Settings

First Action


Disinfect

Second Action


Delete

Heuristics


Yes

Enable Warnings


Yes

Scanned Extensions


*;

Exclude Extensions




Scan Emails


Yes

Scan Archives


Yes

Scan Packed


Yes

Scan Files


Yes

Scan Boot


Yes








Scanned File


Status

C:\WINDOWS\Downloaded Program Files\start.INF


Infected with: Trojan.Clicker.Agent.AC

C:\WINDOWS\Downloaded Program Files\start.INF


Disinfection failed

C:\WINDOWS\Downloaded Program Files\start.INF


Deleted

________________________________________________
step 5. second avenger attempt:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\vhcxqdun

*******************

Script file located at: \??\C:\Program Files\qoinukio.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Driver SrvMyt unloaded successfully.
File C:\Programme\Gemeinsame Dateien\System\TRm.exe deleted successfully.
Registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs replaced with dummy successfully.

Completed script processing.

*******************

Finished! Terminate.

_________________________________
step 6. second combofix attempt:

ComboFix 07-06-13.3 - C:\Dokumente und Einstellungen\anto\Desktop\ComboFix.exe
"anto" - 2007-06-26 9:29:06 - Service Pack 2 NTFS


((((((((((((((((((((((((( Files Created from 2007-05-26 to 2007-06-26 )))))))))))))))))))))))))))))))


2007-06-26 08:34 d——– C:\WINDOWS\BDOSCAN8
2007-06-25 23:01 d——– C:\DOKUME~1\anto\ricerche di mercato
2007-06-18 09:26 d——– C:\gmer
2007-06-18 09:10 d——– C:\getservice
2007-06-16 15:41 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-06-13 14:52 d——– C:\Programme\ht
2007-06-13 13:46 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-13 12:04 75,512 –a—— C:\WINDOWS\zllsputility.exe
2007-06-13 12:03 1,087,216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-06-13 12:03 d——– C:\WINDOWS\system32\ZoneLabs
2007-06-13 11:42 5,632 –a—— C:\WINDOWS\system32\C22EE0C9.exe
2007-06-13 11:40 5,632 –a—— C:\WINDOWS\system32\A7F4841F.exe
2007-06-13 11:12 d——– C:\RkUnhooker
2007-06-13 09:45 d——– C:\pulire
2007-06-12 10:05 d——– C:\program files
2007-06-12 09:43 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-06-12 09:42 d——– C:\DOKUME~1\anto\.housecall6.6
2007-06-11 16:27 d——– C:\DOKUME~1\anto\ANWEND~1\Comodo
2007-06-11 16:26 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Comodo
2007-06-11 16:20 d——– C:\Programme\Comodo
2007-06-11 16:06 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2007-06-11 16:06 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2007-06-11 16:06 154,112 –a—— C:\WINDOWS\system32\irftp.exe
2007-05-29 11:14 d——– C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-29 11:13 d——– C:\Programme\ClamWin
2007-05-29 11:13 d——– C:\DOKUME~1\ALLUSE~1\.clamwin


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-25 15:31:48 ——– d—–w C:\Programme\JKDefrag
2007-06-25 11:36:29 48,486 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-06-25 11:36:29 316,888 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-13 10:07:48 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-06-12 08:37:18 ——– d—–w C:\Programme\Spybot
2007-06-11 11:48:27 ——– d—–w C:\Programme\Startup Optimizer
2007-06-11 10:40:11 ——– d—–w C:\Programme\SyncBack
2007-05-29 15:33:50 ——– d—–w C:\Programme\CCleaner
2007-05-29 09:14:44 ——– d—–w C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-16 15:11:44 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-06 18:43:15 ——– d—–w C:\Programme\Windows Media Connect 2
2007-04-25 14:22:27 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:13:24 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-23 21:12]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Programme\Spybot\SDHelper.dll [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-15 12:03]
"ZoneAlarm Client"="C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Programme\Grisoft\AVGAntiSpyware7.5\shellexecutehook.dll" [2007-05-30 14:29]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2kadiras]
2kadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9xadiras]
9xadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
"C:\Programme\ClamWin\bin\ClamTray.exe" –logon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
pctspk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xovx2.exe]
C:\WINDOWS\Temp\xovx2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZCfgSvc.exe]
C:\WINDOWS\System32\ZCfgSvc.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"hfoyf"="C:\DOKUME~1\anto\LOKALE~1\Temp\694288.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3a5fda0-0df4-11dc-8c7f-00904bb1fd80}]
AutoRun\command- explorer.exe /n,/e,\


Contents of the 'Scheduled Tasks' folder
2007-01-15 18:05:04 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-26 09:32:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]


Completion time: 2007-06-26 9:33:27
C:\ComboFix-quarantined-files.txt … 2007-06-26 09:33
C:\ComboFix2.txt … 2007-06-16 15:55

— E O F —

__________________________________________________________
step 7. second bitdefender log, no new infections found:



BitDefender Online Scanner







Scan report generated at: Tue, Jun 26, 2007 - 10:08:29









Scan path: C:\;E:\;















Statistics

Time


00:32:21

Files


142666

Folders


4121

Boot Sectors


2

Archives


1264

Packed Files


7198







Results

Identified Viruses


0

Infected Files


0

Suspect Files


0

Warnings


0

Disinfected


0

Deleted Files


0







Engines Info

Virus Definitions


571425

Engine build


AVCORE v1.0 (build 2410) (i386) (Jun 12 2007 21:08:27)

Scan plugins


14

Archive plugins


38

Unpack plugins


6

E-mail plugins


6

System plugins


1







Scan Settings

First Action


Disinfect

Second Action


Delete

Heuristics


Yes

Enable Warnings


Yes

Scanned Extensions


*;

Exclude Extensions




Scan Emails


Yes

Scan Archives


Yes

Scan Packed


Yes

Scan Files


Yes

Scan Boot


Yes








Scanned File


Status

No virus found.

______________________________________________________
step 8. hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 10:13:42, on 26.06.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Grisoft\AVGAntiSpyware7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programme\ht\msnoob.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sev84.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.libero.it
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot\SDHelper.dll
O2 - BHO: (no name) - {8F6E6D6A-3C22-E2FE-7CC2-8FC37D944F90} - (no file)
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.libero.it
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1113512489581
O16 - DPF: {FBFF6F10-ABCD-9544-832F-A1F75A0501AE} - http://www.ricerchiamo.net/cart/x/gsa_0082.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programme\Grisoft\AVGAntiSpyware7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Programme\Intel\NCS\Sync\NetSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

_____________________________________________________________________
step 9. silentrunnerslog

"Silent Runners.vbs", revision R50, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
———————————

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"AVG7_CC" = "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
"ZoneAlarm Client" = ""C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"" ["Zone Labs, LLC"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM…CLSID} = "AcroIEHlprObj Class"
\InProcServer32\(Default) = "C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Programme\Spybot\SDHelper.dll" ["Safer Networking Limited"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "CPL-Erweiterung für Anzeigeverschiebung"
-> {HKLM…CLSID} = "CPL-Erweiterung für Anzeigeverschiebung"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Erweiterung für HyperTerminal-Icons"
-> {HKLM…CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{8e9d6600-f84a-11ce-8daa-00aa004a5691}" = "Shell extensions for NetWare"
-> {HKLM…CLSID} = "NetWare Objects"
\InProcServer32\(Default) = "nwprovau.dll" [MS]
"{e3f2bac0-099f-11cf-8daa-00aa004a5691}" = "Shell extensions for NetWare"
-> {HKLM…CLSID} = "NetWare UNC Folder Menu"
\InProcServer32\(Default) = "nwprovau.dll" [MS]
"{52c68510-09a0-11cf-8daa-00aa004a5691}" = "Shell extensions for NetWare"
-> {HKLM…CLSID} = "NetWare Hood Verbs"
\InProcServer32\(Default) = "nwprovau.dll" [MS]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {HKLM…CLSID} = "Microsoft Office Outlook"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
-> {HKLM…CLSID} = "Estensione dell'icona del file di Outlook"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Programme\Microsoft Office\OFFICE11\msohev.dll" [MS]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{D9872D13-7651-4471-9EEE-F0A00218BEBB}" = "Multiscan"
-> {HKLM…CLSID} = "ZLAVShExt Class"
\InProcServer32\(Default) = "C:\Programme\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
-> {HKLM…CLSID} = "CShellExecuteHookImpl Object"
\InProcServer32\(Default) = "C:\Programme\Grisoft\AVGAntiSpyware7.5\shellexecutehook.dll" ["GRISOFT s.r.o."]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\
"AppInit_DLLs" = (value not set)

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<> igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]

HKLM\Software\Classes\PROTOCOLS\Filter\
<> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM…CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "C:\Programme\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM…CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Programme\Grisoft\AVGAntiSpyware7.5\context.dll" ["GRISOFT s.r.o."]
ClamWin\(Default) = "{65713842-C410-4f44-8383-BFE01A398C90}"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Programme\ClamWin\bin\ExpShell.dll" ["alch"]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
ZLAVShExt\(Default) = "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"
-> {HKLM…CLSID} = "ZLAVShExt Class"
\InProcServer32\(Default) = "C:\Programme\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM…CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Programme\Grisoft\AVGAntiSpyware7.5\context.dll" ["GRISOFT s.r.o."]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
ClamWin\(Default) = "{65713842-C410-4f44-8383-BFE01A398C90}"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Programme\ClamWin\bin\ExpShell.dll" ["alch"]
NetWareUNCMenu\(Default) = "{e3f2bac0-099f-11cf-8daa-00aa004a5691}"
-> {HKLM…CLSID} = "NetWare UNC Folder Menu"
\InProcServer32\(Default) = "nwprovau.dll" [MS]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
ZLAVShExt\(Default) = "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"
-> {HKLM…CLSID} = "ZLAVShExt Class"
\InProcServer32\(Default) = "C:\Programme\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]


Default executables:
——————–

<> HKLM\Software\Classes\scrfile\shell\open\command\(Default) = ""%1" %*" [file not found]


Group Policies {GPedit.msc branch and setting}:
———————————————–

Note: detected settings may not have any effect.

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
—————————–

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp"


Enabled Scheduled Tasks:
————————

"AppleSoftwareUpdate" -> launches: "C:\Programme\Apple Software Update\SoftwareUpdate.exe -Task" [file not found]


Winsock2 Service Provider DLLs:
——————————-

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\System32\nwprovau.dll" [MS]
000000000005\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 27
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
————————————

Explorer Bars

HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Ricerche"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{85D1F590-48F4-11D9-9669-0800200C9A66}\
"MenuText" = "Uninstall BitDefender Online Scanner v8"
"Exec" = "%windir%\bdoscandel.exe" [null data]

{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
"ButtonText" = "Ricerche"

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Programme\Messenger\msmsgs.exe" [MS]


Miscellaneous IE Hijack Points
——————————

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=http://www.libero.it

Missing lines (compared with English-language version):
[Strings]: 1 line


Running Services (Display Name, Service Name, Path {Service DLL}):
——————————————————————

AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Programme\Grisoft\AVGAntiSpyware7.5\guard.exe" ["GRISOFT s.r.o."]
AVG E-mail Scanner, AVGEMS, "C:\PROGRA~1\Grisoft\AVG7\avgemc.exe" ["GRISOFT, s.r.o."]
AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe" ["GRISOFT, s.r.o."]
AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe" ["GRISOFT, s.r.o."]
Bluetooth Support Service, BthServ, "C:\WINDOWS\system32\svchost.exe -k bthsvcs" {"C:\WINDOWS\System32\bthserv.dll" [MS]}
RegSrvc, RegSrvc, "C:\WINDOWS\System32\RegSrvc.exe" ["Intel Corporation"]
Spectrum24 Event Monitor, S24EventMonitor, "C:\WINDOWS\System32\S24EvMon.exe" ["Intel Corporation "]
TrueVector Internet Monitor, vsmon, "C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service" ["Zone Labs, LLC"]
WLTRYSVC, WLTRYSVC, "C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe" [null data]


Print Monitors:
—————

HKLM\System\CurrentControlSet\Control\Print\Monitors\
Adobe PDF Port\Driver = "C:\WINDOWS\System32\AdobePDF.dll" ["Adobe Systems Incorporated."]
hpzsnt10\Driver = "hpzsnt10.dll" ["HP"]
Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]


———-
<>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 41 seconds.
———- (total run time: 94 seconds)
Good work coming back and getting the repairs on track there, and the logs show more of what has been blocking efforts up until now. Let's make additional repairs and check for what has yet to be seen.

There is recent activity related to the use of infrared net access there, which we do not normally see in logs. If you do not use infrared for your communications, please locate the following file and rename it by adding old to the name.

C:\WINDOWS\system32\irftp.exe (irftp.exe becomes irftp.exe.old)



Backup Your Registry with ERUNT

Please use the following link and scroll down to ERUNT and download it.
http://aumha.org/freeware/freeware.php
For version with the Installer:
Use the setup program to install ERUNT on your computer
For the zipped version:
Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe


Launch Notepad (Start>All Programs>Accessories), and copy/paste all the Quoted REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: * files
Click: Save

REGEDIT4

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3a5fda0-0df4-11dc-8c7f-00904bb1fd80}]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xovx2.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"hfoyf"=-


Save this as fix.reg Choose to save as *all files and place it on your desktop. Then Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.
(In case you are unsure how to create a reg file, take a look here with screenshots.)



Next close Internet Explorer and all running programs and run a scan in HijackThis. Place a check next to all of the following lines, then select “Fix Checked” and close HijackThis.

O2 - BHO: (no name) - {8F6E6D6A-3C22-E2FE-7CC2-8FC37D944F90} - (no file)
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file)


———————————————————————–

Then reboot, and go Here and download ATF cleaner. Click on the downloaded file to run it, and select "Select All", then click Empty Selected (and close ATF).

If you have them, also click on Firefox/Opera at the top and repeat the steps (and close ATF). Firefox/Opera will need to be closed first for the cleaning to be effective.


Then go here and run the Kaspersky online scan, and post back the log it creates (it requires IE).

To use the scan, once the download has completed click Scan Settings, then make sure the "extended option" is checked (leave all others as they are) and click OK. Then click My Computer to begin the scan. Save the Report as a text file and post that back here.


Run new ComboFix and HijackThis scans, and post those logs back here along with the Kaspersky log please.
hi Jintan, things went smoothly today!

1. as infrared is not being used, i renamed C:\WINDOWS\system32\irftp.exe to …irftp.exe.old

2. backed up my registry with ERUNT

3. created fixme.reg and merged it with the registry

4. ran HT , fixed the reg-entries you posted and rebootet

5. cleaned house with ATF-cleaner

6. did the kaspersky online scan

7.ran combofix and HT again (btw: combofix runs fine since the measures from post 16, also there are no more warnings on startup)

_____________________________________
here are the logs from steps 6. and 7.:


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, June 27, 2007 1:14:44 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 27/06/2007
Kaspersky Anti-Virus database records: 354110
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
E:\

Scan Statistics:
Total number of scanned objects: 41452
Number of viruses found: 0
Number of infected objects: 0 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:48:10

Infected Object Name / Virus Name / Last Action
C:\Avenger\com9.few Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\avg7\Log\emc.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Dokumente und Einstellungen\anto\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\anto\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\CSR.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\Diet.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\IAmIG.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\IjD.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\jcB.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\Mrv.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\mVIwNs.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\Rcn.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\TBa.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\TMw.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\tNI.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\vvHzJ.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\wJN.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\xFNKG.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\xwTACI.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\ZEc.exe Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\ANTO.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\nortonchecker.exe Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\aukvgjig.dat Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\com9.few Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\SeagateFlash.exe Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT0526f.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT07f67.TMP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
__________________________________________________________

ComboFix 07-06-13.3 - C:\Dokumente und Einstellungen\anto\Desktop\ComboFix.exe
"anto" - 2007-06-27 13:16:53 - Service Pack 2 NTFS


((((((((((((((((((((((((( Files Created from 2007-05-27 to 2007-06-27 )))))))))))))))))))))))))))))))


2007-06-27 09:59 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-06-27 09:59 d——– C:\WINDOWS\LastGood
2007-06-27 09:36 d——– C:\Programme\regbackup
2007-06-26 08:34 d——– C:\WINDOWS\BDOSCAN8
2007-06-25 23:01 d——– C:\DOKUME~1\anto\ricerche di mercato
2007-06-18 09:26 d——– C:\gmer
2007-06-18 09:10 d——– C:\getservice
2007-06-16 15:41 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-06-13 14:52 d——– C:\Programme\ht
2007-06-13 13:46 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-13 12:04 75,512 –a—— C:\WINDOWS\zllsputility.exe
2007-06-13 12:03 1,087,216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-06-13 12:03 d——– C:\WINDOWS\system32\ZoneLabs
2007-06-13 11:42 5,632 –a—— C:\WINDOWS\system32\C22EE0C9.exe
2007-06-13 11:40 5,632 –a—— C:\WINDOWS\system32\A7F4841F.exe
2007-06-13 11:12 d——– C:\RkUnhooker
2007-06-13 09:45 d——– C:\pulire
2007-06-12 10:05 d——– C:\program files
2007-06-12 09:43 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-06-12 09:42 d——– C:\DOKUME~1\anto\.housecall6.6
2007-06-11 16:27 d——– C:\DOKUME~1\anto\ANWEND~1\Comodo
2007-06-11 16:26 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Comodo
2007-06-11 16:20 d——– C:\Programme\Comodo
2007-06-11 16:06 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2007-06-11 16:06 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2007-06-11 16:06 154,112 –a—— C:\WINDOWS\system32\irftp.exe
2007-05-29 11:14 d——– C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-29 11:13 d——– C:\Programme\ClamWin
2007-05-29 11:13 d——– C:\DOKUME~1\ALLUSE~1\.clamwin


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-25 15:31:48 ——– d—–w C:\Programme\JKDefrag
2007-06-25 11:36:29 48,486 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-06-25 11:36:29 316,888 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-13 10:07:48 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-06-12 08:37:18 ——– d—–w C:\Programme\Spybot
2007-06-11 11:48:27 ——– d—–w C:\Programme\Startup Optimizer
2007-06-11 10:40:11 ——– d—–w C:\Programme\SyncBack
2007-05-29 15:33:50 ——– d—–w C:\Programme\CCleaner
2007-05-29 09:14:44 ——– d—–w C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-16 15:11:44 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-06 18:43:15 ——– d—–w C:\Programme\Windows Media Connect 2
2007-04-25 14:22:27 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:13:24 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Programme\Spybot\SDHelper.dll [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-15 12:03]
"ZoneAlarm Client"="C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Programme\Grisoft\AVGAntiSpyware7.5\shellexecutehook.dll" [2007-05-30 14:29]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2kadiras]
2kadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9xadiras]
9xadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
"C:\Programme\ClamWin\bin\ClamTray.exe" –logon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
pctspk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZCfgSvc.exe]
C:\WINDOWS\System32\ZCfgSvc.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3a5fda0-0df4-11dc-8c7f-00904bb1fd80}]
AutoRun\command- explorer.exe /n,/e,\


Contents of the 'Scheduled Tasks' folder
2007-01-15 18:05:04 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-27 13:19:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]


Completion time: 2007-06-27 13:21:06
C:\ComboFix-quarantined-files.txt … 2007-06-27 13:20
C:\ComboFix2.txt … 2007-06-26 09:33
C:\ComboFix3.txt … 2007-06-16 15:55

— E O F —
_______________________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 13:22:39, on 27.06.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Grisoft\AVGAntiSpyware7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\explorer.exe
c:\programme\ht\msnoob.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sev84.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.libero.it
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot\SDHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.libero.it
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1113512489581
O16 - DPF: {FBFF6F10-ABCD-9544-832F-A1F75A0501AE} - http://www.ricerchiamo.net/cart/x/gsa_0082.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programme\Grisoft\AVGAntiSpyware7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Programme\Intel\NCS\Sync\NetSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Good news things are now working better. There still appears to be a component of this infection that is resistant to removal, so let's address that now.


Delete the current copy you have of ComboFix.exe and download a fresh copy from here to your desktop.


Please open Notepad (Start > Run > in the Open field type: notepad)
Click: OK

Copy/ paste the entire contents of the textbox below to Notepad:

File::
C:\WINDOWS\system32\com9.few
C:\WINDOWS\system32\aukvgjig.dat
C:\Programme\Gemeinsame Dateien\System\CSR.exe 
C:\Programme\Gemeinsame Dateien\System\Diet.exe 
C:\Programme\Gemeinsame Dateien\System\IAmIG.exe 
C:\Programme\Gemeinsame Dateien\System\IjD.exe 
C:\Programme\Gemeinsame Dateien\System\jcB.exe 
C:\Programme\Gemeinsame Dateien\System\Mrv.exe 
C:\Programme\Gemeinsame Dateien\System\mVIwNs.exe 
C:\Programme\Gemeinsame Dateien\System\Rcn.exe 
C:\Programme\Gemeinsame Dateien\System\TBa.exe 
C:\Programme\Gemeinsame Dateien\System\TMw.exe 
C:\Programme\Gemeinsame Dateien\System\tNI.exe 
C:\Programme\Gemeinsame Dateien\System\vvHzJ.exe 
C:\Programme\Gemeinsame Dateien\System\wJN.exe 
C:\Programme\Gemeinsame Dateien\System\xFNKG.exe 
C:\Programme\Gemeinsame Dateien\System\xwTACI.exe 
C:\Programme\Gemeinsame Dateien\System\ZEc.exe 

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2kadiras]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9xadiras]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3a5fda0-0df4-11dc-8c7f-00904bb1fd80}]

Save as ComboFix-Do.txt
Change the "Save as type" to "All Files"
Save it to the Desktop.

[external image: Posted Image]

Referring to the screen shot above, drag ComboFix-Do.txt into ComboFix.exe
ComboFix now runs a scan on your system, and may reboot when it finishes. This is normal.

CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

When finished, a log is produced: C:\ComboFix.txt

Please provide the contents of the C:\ComboFix.txt in your next reply.
hi jintan, glad that things are going well…
here is the fresh combofix-log:


"anto" - 2007-06-28 9:33:13 - ComboFix 07-06-27.7 - Service Pack 2 NTFS
Command switches used :: C:\Dokumente und Einstellungen\anto\Desktop\Combifix-Do.txt


((((((((((((((((((((((((( Files Created from 2007-05-28 to 2007-06-28 )))))))))))))))))))))))))))))))


2007-06-27 09:59 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-06-27 09:36 d——– C:\Programme\regbackup
2007-06-26 08:34 d——– C:\WINDOWS\BDOSCAN8
2007-06-25 23:01 d——– C:\DOKUME~1\anto\ricerche di mercato
2007-06-18 09:26 d——– C:\gmer
2007-06-18 09:10 d——– C:\getservice
2007-06-16 15:41 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-06-13 14:52 d——– C:\Programme\ht
2007-06-13 13:46 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-13 12:04 75,512 –a—— C:\WINDOWS\zllsputility.exe
2007-06-13 12:03 1,087,216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-06-13 12:03 d——– C:\WINDOWS\system32\ZoneLabs
2007-06-13 11:42 5,632 –a—— C:\WINDOWS\system32\C22EE0C9.exe
2007-06-13 11:40 5,632 –a—— C:\WINDOWS\system32\A7F4841F.exe
2007-06-13 11:12 d——– C:\RkUnhooker
2007-06-13 09:45 d——– C:\pulire
2007-06-12 10:05 d——– C:\program files
2007-06-12 09:43 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-06-12 09:42 d——– C:\DOKUME~1\anto\.housecall6.6
2007-06-11 16:27 d——– C:\DOKUME~1\anto\ANWEND~1\Comodo
2007-06-11 16:26 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Comodo
2007-06-11 16:20 d——– C:\Programme\Comodo
2007-06-11 16:06 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2007-06-11 16:06 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2007-06-11 16:06 154,112 –a—— C:\WINDOWS\system32\irftp.exe
2007-05-29 11:14 d——– C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-29 11:13 d——– C:\Programme\ClamWin
2007-05-29 11:13 d——– C:\DOKUME~1\ALLUSE~1\.clamwin


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-25 15:31:48 ——– d—–w C:\Programme\JKDefrag
2007-06-25 11:36:29 48,486 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-06-25 11:36:29 316,888 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-13 10:07:48 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-06-12 08:37:18 ——– d—–w C:\Programme\Spybot
2007-06-11 11:48:27 ——– d—–w C:\Programme\Startup Optimizer
2007-06-11 10:40:11 ——– d—–w C:\Programme\SyncBack
2007-05-29 15:33:50 ——– d—–w C:\Programme\CCleaner
2007-05-29 09:14:44 ——– d—–w C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-16 15:11:44 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-06 18:43:15 ——– d—–w C:\Programme\Windows Media Connect 2
2007-04-25 14:22:27 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:13:24 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Programme\Spybot\SDHelper.dll [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-15 12:03]
"ZoneAlarm Client"="C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Programme\Grisoft\AVGAntiSpyware7.5\shellexecutehook.dll" [2007-05-30 14:29]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2kadiras]
2kadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9xadiras]
9xadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
"C:\Programme\ClamWin\bin\ClamTray.exe" –logon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
pctspk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZCfgSvc.exe]
C:\WINDOWS\System32\ZCfgSvc.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


Contents of the 'Scheduled Tasks' folder
2007-01-15 18:05:04 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-28 09:35:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

cmd.exe [8064]


scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]


Completion time: 2007-06-28 9:37:17
C:\ComboFix-quarantined-files.txt … 2007-06-28 09:36
C:\ComboFix2.txt … 2007-06-27 13:21
C:\ComboFix3.txt … 2007-06-26 09:33

— E O F —
Some change showing - if you would, please locate and post back the contents of the C:\ComboFix-quarantined-files.txt files as well here.
here u are!

2006-05-31 16:02	  1090	–a——	C:\Qoobox\Quarantine\C\INSTALL.LOG.vir
2007-06-16 15:46	  1060	–a——	C:\Qoobox\Quarantine\Registry_backups\LEGACY_NWSAPAGENT.reg.cf
2007-06-16 15:46	  3630	–a——	C:\Qoobox\Quarantine\Registry_backups\services_NwSapAgent.reg.cf
2007-06-16 15:46	  6644	–a——	C:\Qoobox\Quarantine\Registry_backups\services_nm.reg.cf


Auflistung der Ordnerpfade
Volumenummer: 9415-BDDF
C:\QOOBOX
\—Quarantine
	+—C
	|	   INSTALL.LOG.vir
	|	   
	\—Registry_backups
			LEGACY_NWSAPAGENT.reg.cf
			services_nm.reg.cf
			services_NwSapAgent.reg.cf
Let's follow up more on that now. Some files showing in these logs are suspect, but the latest log results do not clearly show if all the removal steps we have done have all been successful.


Please go to http://virusscan.jotti.org , click on Browse, and upload the following file(s) for analysis. You may not be able to locate some of these - if so, be sure to take note and update me in your next reply:

c:\windows\system32\2kadiras.exe
c:\windows\system32\9xadiras.exe
C:\WINDOWS\system32\com9.few
C:\WINDOWS\system32\aukvgjig.dat
C:\Programme\Gemeinsame Dateien\System\CSR.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.


If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html

http://www.virustotal.com/en/indexf.html
hi jintan!
i was only able to scan one of the files with jotti:

1:
c:\windows\system32\2kadiras.exe
resulted:
File: 2kadiras.EXE
Status: OK
MD5: a10235274acf16a13758e873a9bb85cf
Packers detected: -
Bit9 reports: File not found

2.
C:\Programme\Gemeinsame Dateien\System\CSR.exe
resulted in following error message:
The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file

i tried kaspersky and virustotal on CSR.exe as well, just to be sure, the result was the same.

3.
i did not find the following files:
c:\windows\system32\9xadiras.exe
C:\WINDOWS\system32\com9.few
C:\WINDOWS\system32\aukvgjig.dat
here is the new kaspersky-log: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Friday, June 29, 2007 2:00:48 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 29/06/2007 Kaspersky Anti-Virus database records: 355194 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ E:\ Scan Statistics: Total number of scanned objects: 41708 Number of viruses found: 0 Number of infected objects: 0 Number of suspicious objects: 0 Duration of the scan process: 00:48:04 Infected Object Name / Virus Name / Last Action C:\Avenger\com9.few Object is locked skipped C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\avg7\Log\emc.log Object is locked skipped C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log Object is locked skipped C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped C:\Dokumente und Einstellungen\anto\Cookies\index.dat Object is locked skipped C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped C:\Dokumente und Einstellungen\anto\NTUSER.DAT Object is locked skipped C:\Dokumente und Einstellungen\anto\ntuser.dat.LOG Object is locked skipped C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Programme\Gemeinsame Dateien\System\CSR.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\Diet.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\IAmIG.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\IjD.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\jcB.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\Mrv.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\mVIwNs.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\Rcn.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\TBa.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\TMw.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\tNI.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\vvHzJ.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\wJN.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\xFNKG.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\xwTACI.exe Object is locked skipped C:\Programme\Gemeinsame Dateien\System\ZEc.exe Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Internet Logs\ANTO.ldb Object is locked skipped C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped C:\WINDOWS\nortonchecker.exe Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\aukvgjig.dat Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\com9.few Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\SeagateFlash.exe Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\ZLT0788a.TMP Object is locked skipped C:\WINDOWS\Temp\ZLT0788d.TMP Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
Some of the same files still show here. I would like you do do a few additional steps that in ways repeat each other in order to make advances on the removal here. Although not all of these steps might work exactly as prepared here, if you have problems with one just move to the next and update me in your next reply. I also would like to again check some files if that works out.


Go Here and download and install Unlocker.


Then We need to make sure all hidden files are showing so please:
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.


Navigate to C:\Windows\explorer.exe and When found, rightclick it and choose "Unlocker". If this file is still hooked, a window listing of lockers will appear. Click Unlock All.

Next navigate to the following hilighted files/folders (shown in Bold).

C:\Avenger\com9.few
C:\WINDOWS\system32\aukvgjig.dat
C:\WINDOWS\nortonchecker.exe
C:\Programme\Gemeinsame Dateien\System\CSR.exe


When found, rightclick each and choose "Unlocker". If this file is still hooked, a window listing of lockers will appear. Click Unlock All.


If successful, again go here and follow the instructions to upload the the file(s).

You DO NOT need to be a member to upload, anybody can upload the files.



Next navigate to the following, and follow the same procedure to "Unlock All".

C:\Windows\System32\cmd.exe
C:\Windows\System32\notepad.exe




Open Notepad (Start - Programs - Accessories) and copy the following text into a new file:

cd C:\Windows\System32
cacls com9.few /e /g Owner:f
attrib -s -h -r com9.few
del com9.few
cacls aukvgjig.dat /e /g Owner:f
attrib -s -h -r aukvgjig.dat
del aukvgjig.dat
exit

Save the file to the desktop as ausgang.bat and make sure the "Save as type" field says "All files".

Then double-click on ausgang.bat. A window should open and close fairly quickly — this is normal.



Then rename Avenger.exe to worker.exe, and click that file to run Avenger.

Copy all the text contained in the code box below by highlighting it and right clicking and selecting "Copy"

Files to delete:
C:\Avenger\com9.few
C:\WINDOWS\nortonchecker.exe
C:\WINDOWS\system32\aukvgjig.dat
C:\WINDOWS\system32\com9.few	
C:\Programme\Gemeinsame Dateien\System\CSR.exe	
C:\Programme\Gemeinsame Dateien\System\Diet.exe	
C:\Programme\Gemeinsame Dateien\System\IAmIG.exe	
C:\Programme\Gemeinsame Dateien\System\IjD.exe	
C:\Programme\Gemeinsame Dateien\System\jcB.exe	
C:\Programme\Gemeinsame Dateien\System\Mrv.exe	
C:\Programme\Gemeinsame Dateien\System\mVIwNs.exe	
C:\Programme\Gemeinsame Dateien\System\Rcn.exe	
C:\Programme\Gemeinsame Dateien\System\TBa.exe	
C:\Programme\Gemeinsame Dateien\System\TMw.exe	
C:\Programme\Gemeinsame Dateien\System\tNI.exe	
C:\Programme\Gemeinsame Dateien\System\vvHzJ.exe	
C:\Programme\Gemeinsame Dateien\System\wJN.exe	
C:\Programme\Gemeinsame Dateien\System\xFNKG.exe	
C:\Programme\Gemeinsame Dateien\System\xwTACI.exe	
C:\Programme\Gemeinsame Dateien\System\ZEc.exe

Now, start The Avenger program by clicking on its icon on your desktop. Look under "Script file to execute" and click on "Input Script Manually". Next click on the Magnifying Glass icon and a blank dialogue box will open called "View/Edit script". Position your mouse inside the box, rightclick and choose Paste. All the text above in the code box should now appear there. Click Done and click on the Green Light to begin execution of the script. Answer "Yes" twice when prompted.

The Avenger will restart your computer. (if the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)

When you have rebooted, a black command window briefly opens on your desktop, this is normal. A logfile will be created that records all actions that The Avenger performed. This log file is saved to C:\avenger.txt. The deleted files will be backed up and saved to C:\avenger\backup.zip.


=================================================

Once your computer has rebooted, run a new Kaspersky scan, and post that log back here, along with the C:\avenger.txt log please.


Also locate C:\avenger\backup.zip, and again go here and follow the instructions to upload the the file(s).
hi jintan, couple of problems here:

1. installed unlocker and unhid protected files in explorer

unlocker produced an error message about debug privileges at first which i resolved with the help of the faqs
tried again, neither
C:\Windows\explorer.exe
nor
C:\Avenger\com9.few
C:\WINDOWS\system32\aukvgjig.dat
C:\WINDOWS\nortonchecker.exe
C:\Programme\Gemeinsame Dateien\System\CSR.exe

seemed not to be hooked, unlocker gave the output "No locking handle found…"
for all of the files, so i proceeded with "no action" and went on to the next step

2. uploading of the files above to security-central failed though

3. unlocker
C:\Windows\System32\cmd.exe
C:\Windows\System32\notepad.exe
resulted in "no locking handle found…" as well…

4. made the ausgang.bat and ran it

5. renamed avenger and tried to run, at first there was following error message:
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Fatal error: could not create new script file.
Error code: 1813
Error logged to errorlog.txt. Aborting now!

but at a second try it seemed to work and rebootet
after logging in the cli popped up and informed me about missing files (com9.few and the like that had been deleted by avenger)
then notepad opened with the message: "file avenger.txt not found, create it?"

there i probably screwed it by typing "no", as no avenger-log was created!

6. uploaded the avenger backup.zip to security central

7. ran kaspersky, here's the log:

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, June 29, 2007 4:58:46 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 29/06/2007
Kaspersky Anti-Virus database records: 355388
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
E:\

Scan Statistics:
Total number of scanned objects: 41726
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 00:48:48

Infected Object Name / Virus Name / Last Action
C:\Avenger\com9.few Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\avg7\Log\emc.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Dokumente und Einstellungen\anto\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\MSHist012007062920070630\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\anto\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\CSR.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\Diet.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\IAmIG.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\IjD.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\jcB.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\Mrv.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\mVIwNs.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\Rcn.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\TBa.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\TMw.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\tNI.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\vvHzJ.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\wJN.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\xFNKG.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\xwTACI.exe Object is locked skipped
C:\Programme\Gemeinsame Dateien\System\ZEc.exe Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\ANTO.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\nortonchecker.exe Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\aukvgjig.dat Object is locked skipped
C:\WINDOWS\system32\com9.few Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\SeagateFlash.exe Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT031db.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT031de.TMP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI