This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Smitfraud + More Problems!

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

renamed HJT incase!!! please help!
——————————————————————————


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:46:28 PM, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\svhost.exe
C:\WINDOWS\retadpu77.exe
C:\WINDOWS\ragtljaA.exe
C:\WINDOWS\CURITY~1\regsvr32.exe
C:\Program Files\WinPop\winpop.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Ryan\My Documents\??mantec\r?ndll.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Documents and Settings\Ryan\Application Data\Microsoft\Windows\qwphjtg.exe
C:\Documents and Settings\Ryan\Application Data\WinTouch\WinTouch.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [poolsv] "C:\WINDOWS\poolsv.exe"
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu77.exe 61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [ragtljaA] C:\WINDOWS\ragtljaA.exe
O4 - HKLM\..\Run: [{ZN}] C:\WINDOWS\xcnse0578.exe SKY009
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\foxnmvdg.dll",forkonce
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Wsdu] "C:\WINDOWS\CURITY~1\regsvr32.exe" -vt yazb
O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.7.8\webbuying.exe
O4 - HKCU\..\Run: [Fzrull] "C:\Documents and Settings\Ryan\My Documents\??mantec\r?ndll.exe"
O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe
O4 - HKCU\..\Run: [WinTouch] C:\Documents and Settings\Ryan\Application Data\WinTouch\WinTouch.exe
O4 - HKCU\..\Run: [SfKg6w] C:\Documents and Settings\Ryan\Application Data\Microsoft\Windows\qwphjtg.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\xcnse0578.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1178338978029
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1178341677451
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 4119 bytes


HELP PLEASE~!!! thanks in advance
Hello qqq and welcome to the TomCoyote Forums

My name is Trevuren and I will be helping you with your problem.


1. Some trojans have a way of masking their presence from the HijackThis program when they recognize the name. I think that this is the case here because there are no 02 or 020 entries visible in your log.

Please locate the following file: C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
Next, right click on the file and from the popup menu that appears, choose the RENAME option and rename the file Killer.exe.

From now on, when I ask you to start HijackThis, just click on the Killer.exe file.


2. Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt



3. A. Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.



B. Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall


C. Reports/Logs to post:
  • Report.txt from SDFix
  • VundoFix.txt
  • ComboFix.txt
  • HijackThis log
hi Trevuren! Thanks for your help so far!
Here are the logs:

SDfix


SDFix: Version 1.91

Run by [removed] on Sun 07/15/2007 at 07:34 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
core

ImagePath:
system32\drivers\core.sys

core - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\b122.exe - Deleted
C:\WINDOWS\b128.exe - Deleted
C:\WINDOWS\b136.exe - Deleted
C:\WINDOWS\b138.exe - Deleted
C:\WINDOWS\poolsv.exe - Deleted
C:\WINDOWS\retadpu1000106.exe - Deleted
C:\WINDOWS\retadpu77.exe - Deleted
C:\WINDOWS\svhost.exe - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\drivers\core.sys - Deleted
C:\WINDOWS\tcb.pmw - Deleted
C:\WINDOWS\wr.txt - Deleted


Folder C:\Program Files\InetGet2 - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HTTP-Tunnel\\HTTP-TunnelClient.exe"="C:\\Program Files\\HTTP-Tunnel\\HTTP-TunnelClient.exe:*:Enabled:HTTP-Tunnel Client"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\World of Warcraft\\Launcher.exe"="C:\\World of Warcraft\\Launcher.exe:*:Enabled:World of Warcraft"
"C:\\World of Warcraft\\WoW.exe"="C:\\World of Warcraft\\WoW.exe:*:Enabled:WoW"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.4\\cnc3game.dat"="C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.4\\cnc3game.dat:*:Enabled:Command & Conquer 3 Tiberium Wars"
"C:\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe"="C:\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.5\\cnc3game.dat"="C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.5\\cnc3game.dat:*:Enabled:Command & Conquer 3 Tiberium Wars"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"="C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\Xfire\\xfire.exe"="C:\\Program Files\\Xfire\\xfire.exe:*:Enabled:Xfire"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:
—————

Backups Folder: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

C:\WINDOWS\system32\gebyx.dll
C:\Documents and Settings\Ryan\My Documents\??mantec\r?ndll.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Windows Media Player\mplayer2.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\ragtljaA.exe
C:\WINDOWS\??curity\regsvr32.exe

Finished

VundoFix


VundoFix V6.5.4

Checking Java version…

Java version is 1.4.2.4
Old versions of java are exploitable and should be removed.

Scan started at 7:40:31 PM 7/15/2007

Listing files found while scanning….

C:\windows\system32\efcyyvt.dll
C:\WINDOWS\system32\fhhkj.bak2
C:\WINDOWS\system32\fhhkj.ini
C:\WINDOWS\system32\foxnmvdg.dll
C:\WINDOWS\system32\gdvmnxof.ini
C:\windows\system32\gebyx.dll
C:\windows\system32\ijjnjvbm.ini
C:\WINDOWS\system32\jkhhf.dll
C:\windows\system32\mbvjnjji.dll
C:\windows\system32\xybeg.ini

Beginning removal…

Attempting to delete C:\windows\system32\efcyyvt.dll
C:\windows\system32\efcyyvt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fhhkj.bak2
C:\WINDOWS\system32\fhhkj.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\fhhkj.ini
C:\WINDOWS\system32\fhhkj.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\foxnmvdg.dll
C:\WINDOWS\system32\foxnmvdg.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\gdvmnxof.ini
C:\WINDOWS\system32\gdvmnxof.ini Has been deleted!

Attempting to delete C:\windows\system32\gebyx.dll
C:\windows\system32\gebyx.dll Has been deleted!

Attempting to delete C:\windows\system32\ijjnjvbm.ini
C:\windows\system32\ijjnjvbm.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\jkhhf.dll Has been deleted!

Attempting to delete C:\windows\system32\mbvjnjji.dll
C:\windows\system32\mbvjnjji.dll Has been deleted!

Attempting to delete C:\windows\system32\xybeg.ini
C:\windows\system32\xybeg.ini Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\foxnmvdg.dll
C:\WINDOWS\system32\foxnmvdg.dll Has been deleted!

Performing Repairs to the registry.
Done!

ComboFix

"Ryan" - 2007-07-15 19:46:42 - ComboFix 07-07-14.6 - Service Pack 2 NTFS


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\ckihpljs.dll
C:\WINDOWS\system32\elcxjxhe.dll
C:\WINDOWS\system32\awtuuvs.dll
C:\WINDOWS\system32\awtuuvs.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Ryan\APPLIC~1\WinTouch\wintouch.cfg
C:\DOCUME~1\Ryan\APPLIC~1\WinTouch\WinTouch.exe
C:\DOCUME~1\Ryan\APPLIC~1\WinTouch\WTUninstaller.exe
C:\DOCUME~1\Ryan\MYDOCU~1.\mantec~1
C:\DOCUME~1\Ryan\MYDOCU~1.\mantec~1\r?ndll.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\Messenger\rybimo.dll
C:\Program Files\Messenger\rybimo799.dll
C:\Program Files\Online Services\rybimo432.dll
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\poolsv
C:\Program Files\poolsv\k11u72.exe
C:\Program Files\poolsv\svhost.exe
C:\Program Files\poolsv\WinAntiSpyware2007FreeInstall.exe
C:\Program Files\poolsv\wr-1-0000077.exe
C:\Program Files\poolsv\YazzleBundle-1549.exe
C:\Program Files\svhost
C:\Program Files\svhost\wr-1-0000077.exe
C:\Program Files\WindowsUpdate\nipy83122.dll
C:\Program Files\winpop
C:\Program Files\winpop\UnInstall.exe
C:\Program Files\winpop\winpop.exe
C:\temp\tn3
C:\WINDOWS\curity~1
C:\WINDOWS\curity~1\regsvr32.exe
C:\WINDOWS\dls0523pmw.exe
C:\WINDOWS\rau001978.exe
C:\WINDOWS\system32\B0
C:\WINDOWS\system32\B0\mwspasrt83122.exe
C:\WINDOWS\system32\B1
C:\WINDOWS\system32\B1\wr730.exe
C:\WINDOWS\system32\B2
C:\WINDOWS\system32\B2\sten2.exe
C:\WINDOWS\system32\B3
C:\WINDOWS\system32\B4
C:\WINDOWS\system32\B5
C:\WINDOWS\system32\B5\z53.exe
C:\WINDOWS\system32\rcnchhmq.exe
C:\WINDOWS\system32\ussiuorn.exe
C:\WINDOWS\system32\wnstssv.exe
C:\WINDOWS\system32\yehyduvk.exe
C:\WINDOWS\system32\yfowc.dll
C:\WINDOWS\tk58.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_NET_AGENT
——-\Net Agent


((((((((((((((((((((((((( Files Created from 2007-06-16 to 2007-07-16 )))))))))))))))))))))))))))))))


2007-07-15 19:46 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-15 19:40 d——– C:\VundoFix Backups
2007-07-15 19:34 d——– C:\WINDOWS\ERUNT
2007-07-15 17:31 d——– C:\info
2007-07-15 17:23 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-07-15 17:21 d——– C:\WINDOWS\TAV15.1
2007-07-15 16:02 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-15 15:54 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-15 15:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-12 16:48 d——– C:\WINDOWS\pss
2007-07-12 16:33 d——– C:\Program Files\Trend Micro
2007-07-12 16:00 d——– C:\DOCUME~1\Ryan\.housecall6.6
2007-07-12 15:52 d——– C:\WINDOWS\system32\appmgmt
2007-07-12 15:42 49,152 –a—— C:\WINDOWS\xcnse0578.exe
2007-07-12 15:39 d——– C:\Program Files\MSXML 4.0
2007-07-12 15:22 916,352 -r-hs—- C:\WINDOWS\ragtljaA.exe
2007-07-12 15:22 54,784 –a—— C:\WINDOWS\ragtlja.exe
2007-07-12 15:22 49,152 –a—— C:\WINDOWS\TISKY009.exe
2007-07-12 15:22 172,032 –a—— C:\WINDOWS\system32\vnesyfj.dll
2007-07-12 15:22 d——– C:\WINDOWS\system32\driver
2007-07-12 15:22 d——– C:\Tempc2
2007-07-12 15:21 d——– C:\WINDOWS\system32\b10FdUe
2007-07-12 15:21 d——– C:\Temp\brr
2007-07-12 15:21 d——– C:\Temp
2007-07-11 17:05 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Drivers Headquarters
2007-07-11 17:01 176,128 –a—— C:\WINDOWS\system32\nvuide.exe
2007-07-11 17:01 101,120 –a—— C:\WINDOWS\system32\drivers\nvtcp.sys
2007-07-11 17:01 d——– C:\Program Files\Silicon Image
2007-07-11 16:59 33,280 –a—— C:\WINDOWS\system32\nvconrmins.dll
2007-07-11 16:59 33,280 –a—— C:\WINDOWS\system32\NVCOI.DLL
2007-07-11 16:59 289,792 –a—— C:\WINDOWS\system32\idecoins.dll
2007-07-11 16:40 d——– C:\Program Files\Marvell
2007-07-11 16:30 d——– C:\DOCUME~1\Ryan\APPLIC~1\VersionTracker Pro
2007-06-30 23:35 d—s—- C:\Program Files\Xfire
2007-06-30 23:35 d——– C:\DOCUME~1\Ryan\APPLIC~1\Xfire
2007-06-24 18:31 d——– C:\DOCUME~1\Ryan\APPLIC~1\acccore
2007-06-24 18:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-06-24 18:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-06-23 03:18 d——– C:\DOCUME~1\Ryan\APPLIC~1\Yahoo!
2007-06-22 03:10 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-06-22 03:00 d——– C:\Program Files\uTorrent
2007-06-22 03:00 d——– C:\DOCUME~1\Ryan\APPLIC~1\uTorrent
2007-06-20 16:00 d——– C:\Program Files\Western Digital Technologies
2007-06-19 16:38 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-06-19 16:38 d——– C:\Program Files\Yahoo!
2007-06-19 16:38 d——– C:\Program Files\Common Files\Scanner
2007-06-19 16:38 d——– C:\DOCUME~1\Ryan\APPLIC~1\Logitech
2007-06-19 16:38 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\LogiShrd
2007-06-19 16:37 69,632 –a—— C:\WINDOWS\system32\KemXML.dll
2007-06-19 16:37 56,080 –a—— C:\WINDOWS\KHALMNPR.Exe
2007-06-19 16:37 36,112 –a—— C:\WINDOWS\system32\drivers\LMouFilt.Sys
2007-06-19 16:37 34,832 –a—— C:\WINDOWS\system32\drivers\LHidFilt.Sys
2007-06-19 16:37 28,688 –a—— C:\WINDOWS\system32\drivers\LUsbFilt.sys
2007-06-19 16:37 163,840 –a—— C:\WINDOWS\system32\kemutb.dll
2007-06-19 16:37 135,168 –a—— C:\WINDOWS\system32\KemUtil.dll
2007-06-19 16:37 110,592 –a—— C:\WINDOWS\system32\KemWnd.dll
2007-06-19 16:37 1,419,024 –a—— C:\WINDOWS\system32\WdfCoInstaller01005.dll
2007-06-19 16:36 d——– C:\Program Files\Logitech
2007-06-19 16:36 d——– C:\Program Files\Common Files\Logitech
2007-06-19 16:36 d——– C:\DOCUME~1\Ryan\APPLIC~1\InstallShield
2007-06-19 16:36 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
2007-06-19 13:22 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-06-18 00:22 d——– C:\ProgramData


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-16 02:47:56 ——– d–h–w C:\Program Files\WindowsUpdate
2007-07-16 02:47:56 ——– d—–w C:\Program Files\Online Services
2007-07-16 02:47:56 ——– d—–w C:\Program Files\Messenger
2007-07-15 07:39:22 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-07-15 07:38:33 103,736 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-07-12 23:46:30 ——– d—–w C:\Program Files\AIM6
2007-07-12 22:55:22 ——– d—–w C:\Program Files\Replay Music 2
2007-07-12 22:54:13 ——– d—–w C:\Program Files\Google
2007-07-12 22:53:41 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-07-12 22:53:39 ——– d—–w C:\Program Files\Electronic Arts
2007-07-12 22:52:57 ——– d—–w C:\Program Files\Steam
2007-07-12 22:52:28 ——– d—–w C:\Program Files\Azureus
2007-07-01 08:18:42 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Azureus
2007-06-22 10:10:12 2,414 —-a-w C:\WINDOWS\mozver.dat
2007-06-19 23:38:00 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-06-19 23:37:56 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2007-06-19 23:37:48 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-06-14 23:35:01 ——– d—–w C:\Program Files\Viewpoint
2007-06-14 23:34:47 ——– d—–w C:\Program Files\Common Files\AOL
2007-06-14 23:33:53 335 —-a-w C:\WINDOWS\nsreg.dat
2007-06-14 23:21:17 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Google
2007-06-13 02:25:35 63,040 —-a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-06-12 22:17:17 384 —-a-w C:\WINDOWS\system32\DVCStateBkp-{00000005-00000000-00000006-00001102-00000004-20021102}.dat
2007-06-12 22:17:17 384 —-a-w C:\WINDOWS\system32\DVCState-{00000005-00000000-00000006-00001102-00000004-20021102}.dat
2007-06-12 21:41:18 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\DMCache
2007-06-12 21:28:28 ——– d—–w C:\Program Files\Common Files\InstallShield
2007-05-28 04:24:38 ——– d—–w C:\Program Files\MSN Messenger
2007-05-24 05:01:36 ——– d—–w C:\Program Files\Replay Music
2007-05-24 05:01:35 737,280 —-a-w C:\WINDOWS\iun6002.exe
2007-05-21 08:36:17 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\dvdcss
2007-05-21 04:06:01 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-05-21 02:46:03 108,144 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-05-19 19:02:05 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Help
2007-05-16 19:50:33 ——– d—–w C:\Program Files\HTTP-Tunnel
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-14 03:03:36 451,072 —-a-w C:\WINDOWS\Radeon Omega Drivers v3.8.330 Uninstall.exe
2007-05-12 03:50:29 98,304 —-a-w C:\WINDOWS\system32CmdLineExt.dll
2007-05-06 03:09:34 184 —-a-w C:\WINDOWS\system32\e000001.dat
2007-05-06 02:25:03 664 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-05 03:50:53 0 –sha-r C:\MSDOS.SYS
2007-05-05 03:50:53 0 –sha-r C:\IO.SYS
2007-05-05 03:50:53 0 —-a-w C:\CONFIG.SYS
2007-05-05 03:50:53 0 —-a-w C:\AUTOEXEC.BAT
2007-05-05 03:48:38 21,640 —-a-w C:\WINDOWS\system32\emptyregdb.dat
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-18 15:59:40 98,600 —-a-w C:\WINDOWS\system32\COMMONFX.DLL
2007-04-17 05:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 05:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 05:44:20 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 05:44:18 208,248 —-a-w C:\WINDOWS\system32\muweb.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6BC50FD2-7903-46E3-8C47-A73A3199C7F6}]
C:\WINDOWS\system32\jkhhf.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c3c7a106-84e0-4963-bd31-ab15abe15072}]
2007-07-12 15:22 172032 –a—— C:\WINDOWS\system32\vnesyfj.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="atiptaxx.exe" [2006-02-21 17:05 C:\WINDOWS\system32\atiptaxx.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" []
"Wsdu"="C:\WINDOWS\CURITY~1\regsvr32.exe" []
"Fzrull"="C:\Documents and Settings\Ryan\My Documents\??mantec\r?ndll.exe" []
"SfKg6w"="C:\Documents and Settings\Ryan\Application Data\Microsoft\Windows\qwphjtg.exe" [2007-07-15 16:07]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
CTHELPER.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\Autorun.exe


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-15 19:49:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-15 19:49:46 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-15 19:49

— E O F —

Renamed HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:54:51 PM, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\killer.exe.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6BC50FD2-7903-46E3-8C47-A73A3199C7F6} - C:\WINDOWS\system32\jkhhf.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {c3c7a106-84e0-4963-bd31-ab15abe15072} - C:\WINDOWS\system32\vnesyfj.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Wsdu] "C:\WINDOWS\CURITY~1\regsvr32.exe" -vt yazb
O4 - HKCU\..\Run: [Fzrull] "C:\Documents and Settings\Ryan\My Documents\??mantec\r?ndll.exe"
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1178338978029
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1178341677451
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 3332 bytes




Thanks again!
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://forums.tomcoyote.org/Smitfraud_More_Problems_t81259.html

Collect::
C:\WINDOWS\xcnse0578.exe
C:\WINDOWS\ragtljaA.exe
C:\WINDOWS\ragtlja.exe
C:\WINDOWS\TISKY009.exe
C:\WINDOWS\system32\vnesyfj.dll
C:\WINDOWS\system32\b10FdUe

File::
C:\WINDOWS\xcnse0578.exe
C:\WINDOWS\ragtljaA.exe
C:\WINDOWS\ragtlja.exe
C:\WINDOWS\TISKY009.exe
C:\WINDOWS\system32\vnesyfj.dll
C:\WINDOWS\system32\b10FdUe

Folder::
C:\VundoFix Backups
C:\Tempc2
C:\Temp

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6BC50FD2-7903-46E3-8C47-A73A3199C7F6}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c3c7a106-84e0-4963-bd31-ab15abe15072}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wsdu"=-
"Fzrull"=-
"SfKg6w"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. Additonally, ComboFix will generate a zipped file on your desktop called Submit [Date Time].zip
Please submit this file to:

http://www.bleepingcomputer.com/submit-malware.php?channel=4


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
"Ryan" - 2007-07-15 20:52:29 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\Ryan\Desktop\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Temp
C:\Tempc2\tmpRC.log
C:\Temp\brr\tmpZTF.log
C:\VundoFix Backups
C:\VundoFix Backups\efcyyvt.dll.bad
C:\VundoFix Backups\fhhkj.bak2.bad
C:\VundoFix Backups\fhhkj.ini.bad
C:\VundoFix Backups\foxnmvdg.dll.bad
C:\VundoFix Backups\gdvmnxof.ini.bad
C:\VundoFix Backups\gebyx.dll.bad
C:\VundoFix Backups\ijjnjvbm.ini.bad
C:\VundoFix Backups\jkhhf.dll.bad
C:\VundoFix Backups\mbvjnjji.dll.bad
C:\VundoFix Backups\xybeg.ini.bad
C:\WINDOWS\ragtlja.exe
C:\WINDOWS\ragtljaA.exe
C:\WINDOWS\system32\b10FdUe
C:\WINDOWS\system32\vnesyfj.dll
C:\WINDOWS\TISKY009.exe
C:\WINDOWS\xcnse0578.exe


((((((((((((((((((((((((( Files Created from 2007-06-16 to 2007-07-16 )))))))))))))))))))))))))))))))


2007-07-15 19:46 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-15 19:34 d——– C:\WINDOWS\ERUNT
2007-07-15 17:31 d——– C:\info
2007-07-15 17:23 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-07-15 17:21 d——– C:\WINDOWS\TAV15.1
2007-07-15 16:02 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-15 15:54 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-15 15:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-12 16:48 d——– C:\WINDOWS\pss
2007-07-12 16:33 d——– C:\Program Files\Trend Micro
2007-07-12 16:00 d——– C:\DOCUME~1\Ryan\.housecall6.6
2007-07-12 15:52 d——– C:\WINDOWS\system32\appmgmt
2007-07-12 15:39 d——– C:\Program Files\MSXML 4.0
2007-07-12 15:22 d——– C:\WINDOWS\system32\driver
2007-07-11 17:05 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Drivers Headquarters
2007-07-11 17:01 176,128 –a—— C:\WINDOWS\system32\nvuide.exe
2007-07-11 17:01 101,120 –a—— C:\WINDOWS\system32\drivers\nvtcp.sys
2007-07-11 17:01 d——– C:\Program Files\Silicon Image
2007-07-11 16:59 33,280 –a—— C:\WINDOWS\system32\nvconrmins.dll
2007-07-11 16:59 33,280 –a—— C:\WINDOWS\system32\NVCOI.DLL
2007-07-11 16:59 289,792 –a—— C:\WINDOWS\system32\idecoins.dll
2007-07-11 16:40 d——– C:\Program Files\Marvell
2007-07-11 16:30 d——– C:\DOCUME~1\Ryan\APPLIC~1\VersionTracker Pro
2007-06-30 23:35 d—s—- C:\Program Files\Xfire
2007-06-30 23:35 d——– C:\DOCUME~1\Ryan\APPLIC~1\Xfire
2007-06-24 18:31 d——– C:\DOCUME~1\Ryan\APPLIC~1\acccore
2007-06-24 18:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-06-24 18:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-06-23 03:18 d——– C:\DOCUME~1\Ryan\APPLIC~1\Yahoo!
2007-06-22 03:10 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-06-22 03:00 d——– C:\Program Files\uTorrent
2007-06-22 03:00 d——– C:\DOCUME~1\Ryan\APPLIC~1\uTorrent
2007-06-20 16:00 d——– C:\Program Files\Western Digital Technologies
2007-06-19 16:38 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-06-19 16:38 d——– C:\Program Files\Yahoo!
2007-06-19 16:38 d——– C:\Program Files\Common Files\Scanner
2007-06-19 16:38 d——– C:\DOCUME~1\Ryan\APPLIC~1\Logitech
2007-06-19 16:38 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\LogiShrd
2007-06-19 16:37 69,632 –a—— C:\WINDOWS\system32\KemXML.dll
2007-06-19 16:37 56,080 –a—— C:\WINDOWS\KHALMNPR.Exe
2007-06-19 16:37 36,112 –a—— C:\WINDOWS\system32\drivers\LMouFilt.Sys
2007-06-19 16:37 34,832 –a—— C:\WINDOWS\system32\drivers\LHidFilt.Sys
2007-06-19 16:37 28,688 –a—— C:\WINDOWS\system32\drivers\LUsbFilt.sys
2007-06-19 16:37 163,840 –a—— C:\WINDOWS\system32\kemutb.dll
2007-06-19 16:37 135,168 –a—— C:\WINDOWS\system32\KemUtil.dll
2007-06-19 16:37 110,592 –a—— C:\WINDOWS\system32\KemWnd.dll
2007-06-19 16:37 1,419,024 –a—— C:\WINDOWS\system32\WdfCoInstaller01005.dll
2007-06-19 16:36 d——– C:\Program Files\Logitech
2007-06-19 16:36 d——– C:\Program Files\Common Files\Logitech
2007-06-19 16:36 d——– C:\DOCUME~1\Ryan\APPLIC~1\InstallShield
2007-06-19 16:36 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
2007-06-19 13:22 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-06-18 00:22 d——– C:\ProgramData


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-16 03:22:42 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-07-16 03:22:35 103,736 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-07-16 02:47:56 ——– d–h–w C:\Program Files\WindowsUpdate
2007-07-16 02:47:56 ——– d—–w C:\Program Files\Online Services
2007-07-16 02:47:56 ——– d—–w C:\Program Files\Messenger
2007-07-12 23:46:30 ——– d—–w C:\Program Files\AIM6
2007-07-12 22:55:22 ——– d—–w C:\Program Files\Replay Music 2
2007-07-12 22:54:13 ——– d—–w C:\Program Files\Google
2007-07-12 22:53:41 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-07-12 22:53:39 ——– d—–w C:\Program Files\Electronic Arts
2007-07-12 22:52:57 ——– d—–w C:\Program Files\Steam
2007-07-12 22:52:28 ——– d—–w C:\Program Files\Azureus
2007-07-01 08:18:42 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Azureus
2007-06-22 10:10:12 2,414 —-a-w C:\WINDOWS\mozver.dat
2007-06-19 23:38:00 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-06-19 23:37:56 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2007-06-19 23:37:48 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-06-14 23:35:01 ——– d—–w C:\Program Files\Viewpoint
2007-06-14 23:34:47 ——– d—–w C:\Program Files\Common Files\AOL
2007-06-14 23:33:53 335 —-a-w C:\WINDOWS\nsreg.dat
2007-06-14 23:21:17 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Google
2007-06-13 02:25:35 63,040 —-a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-06-12 22:17:17 384 —-a-w C:\WINDOWS\system32\DVCStateBkp-{00000005-00000000-00000006-00001102-00000004-20021102}.dat
2007-06-12 22:17:17 384 —-a-w C:\WINDOWS\system32\DVCState-{00000005-00000000-00000006-00001102-00000004-20021102}.dat
2007-06-12 21:41:18 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\DMCache
2007-06-12 21:28:28 ——– d—–w C:\Program Files\Common Files\InstallShield
2007-05-28 04:24:38 ——– d—–w C:\Program Files\MSN Messenger
2007-05-24 05:01:36 ——– d—–w C:\Program Files\Replay Music
2007-05-24 05:01:35 737,280 —-a-w C:\WINDOWS\iun6002.exe
2007-05-21 08:36:17 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\dvdcss
2007-05-21 04:06:01 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-05-21 02:46:03 108,144 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-05-19 19:02:05 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Help
2007-05-16 19:50:33 ——– d—–w C:\Program Files\HTTP-Tunnel
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-14 03:03:36 451,072 —-a-w C:\WINDOWS\Radeon Omega Drivers v3.8.330 Uninstall.exe
2007-05-12 03:50:29 98,304 —-a-w C:\WINDOWS\system32CmdLineExt.dll
2007-05-06 03:09:34 184 —-a-w C:\WINDOWS\system32\e000001.dat
2007-05-06 02:25:03 664 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-05 03:50:53 0 –sha-r C:\MSDOS.SYS
2007-05-05 03:50:53 0 –sha-r C:\IO.SYS
2007-05-05 03:50:53 0 —-a-w C:\CONFIG.SYS
2007-05-05 03:50:53 0 —-a-w C:\AUTOEXEC.BAT
2007-05-05 03:48:38 21,640 —-a-w C:\WINDOWS\system32\emptyregdb.dat
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-18 15:59:40 98,600 —-a-w C:\WINDOWS\system32\COMMONFX.DLL
2007-04-17 05:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 05:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 05:44:20 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 05:44:18 208,248 —-a-w C:\WINDOWS\system32\muweb.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="atiptaxx.exe" [2006-02-21 17:05 C:\WINDOWS\system32\atiptaxx.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
CTHELPER.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

*Newly Created Service* - CATCHME
*Newly Created Service* - PNKBSTRB
*Newly Created Service* - PNKBSTRK

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-15 20:53:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-15 20:53:59
C:\ComboFix-quarantined-files.txt … 2007-07-15 20:53
C:\ComboFix2.txt … 2007-07-15 19:49

— E O F —




HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:55:48 PM, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\killer.exe.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1178338978029
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1178341677451
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 2639 bytes



THanks!
Your logs are looking good. Now we should do a thorough check of all your system to make sure that no malware is still lurking.


Please do an online scan with Kaspersky Online Virus Scanner (Use Internet Explorer as your Browser)

Note: If you have used this particular scanner before, you MAY HAVE YO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component

Next Click on Free Virus Scanner, then Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Standard
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information into your next post.
Regards

Trevuren
Just finished the scan, here are the results: Apparently there is still some stuff left ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Sunday, July 15, 2007 10:54:35 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 15/07/2007 Kaspersky Anti-Virus database records: 362384 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ H:\ Scan Statistics: Total number of scanned objects: 66995 Number of viruses found: 25 Number of infected objects: 116 Number of suspicious objects: 2 Duration of the scan process: 00:30:42 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant1.zip/v1.7.8/wbuninst.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant1.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\MBSJ63U7\TISKY009[1].exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\cert8.db Object is locked skipped C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\formhistory.dat Object is locked skipped C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\history.dat Object is locked skipped C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\key3.db Object is locked skipped C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\parent.lock Object is locked skipped C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\search.sqlite Object is locked skipped C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\Ryan\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Ryan\Desktop\Submit [2007-07-15 20.52.09.53].zip/xcnse0578.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\Documents and Settings\Ryan\Desktop\Submit [2007-07-15 20.52.09.53].zip/ragtlja.exe Infected: Trojan-Dropper.Win32.Agent.mu skipped C:\Documents and Settings\Ryan\Desktop\Submit [2007-07-15 20.52.09.53].zip/TISKY009.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\Documents and Settings\Ryan\Desktop\Submit [2007-07-15 20.52.09.53].zip/vnesyfj.dll Infected: not-a-virus:AdWare.Win32.Agent.dk skipped C:\Documents and Settings\Ryan\Desktop\Submit [2007-07-15 20.52.09.53].zip ZIP: infected - 4 skipped C:\Documents and Settings\Ryan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Ryan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Ryan\Local Settings\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Ryan\Local Settings\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Ryan\Local Settings\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Ryan\Local Settings\Application Data\Mozilla\Firefox\Profiles\1meuv3pa.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Ryan\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Ryan\Local Settings\Temp\~DFF1C9.tmp Object is locked skipped C:\Documents and Settings\Ryan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Ryan\ntuser.dat Object is locked skipped C:\Documents and Settings\Ryan\ntuser.dat.LOG Object is locked skipped C:\QooBox\Quarantine\C\DOCUME~1\Ryan\MYDOCU~1\MANTEC~1\rυndll.exe.vir Infected: not-a-virus:AdWare.Win32.PurityScan.fn skipped C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1122OinAdmin.exe.vir Infected: Trojan-Downloader.Win32.PurityScan.eh skipped C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1549OinAdmin.exe.vir Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\QooBox\Quarantine\C\Program Files\Messenger\rybimo.dll.vir Infected: Trojan.Win32.BHO.ab skipped C:\QooBox\Quarantine\C\Program Files\Messenger\rybimo799.dll.vir Infected: Trojan.Win32.BHO.ab skipped C:\QooBox\Quarantine\C\Program Files\Online Services\rybimo432.dll.vir Infected: Trojan.Win32.BHO.ab skipped C:\QooBox\Quarantine\C\Program Files\poolsv\k11u72.exe.vir/data0005 Infected: Trojan-Downloader.Win32.VB.awj skipped C:\QooBox\Quarantine\C\Program Files\poolsv\k11u72.exe.vir NSIS: infected - 1 skipped C:\QooBox\Quarantine\C\Program Files\poolsv\svhost.exe.vir Infected: Trojan.Win32.StartPage.ahg skipped C:\QooBox\Quarantine\C\Program Files\poolsv\WinAntiSpyware2007FreeInstall.exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped C:\QooBox\Quarantine\C\Program Files\poolsv\wr-1-0000077.exe.vir Infected: Trojan-Downloader.Win32.Small.eqn skipped C:\QooBox\Quarantine\C\Program Files\poolsv\YazzleBundle-1549.exe.vir/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\QooBox\Quarantine\C\Program Files\poolsv\YazzleBundle-1549.exe.vir NSIS: infected - 1 skipped C:\QooBox\Quarantine\C\Program Files\WindowsUpdate\nipy83122.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.c skipped C:\QooBox\Quarantine\C\Program Files\WinPop\UnInstall.exe.vir Infected: Trojan.Win32.Small.oa skipped C:\QooBox\Quarantine\C\Program Files\WinPop\winpop.exe.vir Infected: not-a-virus:AdWare.Win32.Rond.a skipped C:\QooBox\Quarantine\C\VundoFix Backups\efcyyvt.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped C:\QooBox\Quarantine\C\VundoFix Backups\gebyx.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\QooBox\Quarantine\C\WINDOWS\dls0523pmw.exe.vir Infected: Trojan-Downloader.Win32.Zlob.bqw skipped C:\QooBox\Quarantine\C\WINDOWS\system32\awtuuvs.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped C:\QooBox\Quarantine\C\WINDOWS\system32\B0\mwspasrt83122.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.c skipped C:\QooBox\Quarantine\C\WINDOWS\system32\B0\mwspasrt83122.exe.vir NSIS: infected - 1 skipped C:\QooBox\Quarantine\C\WINDOWS\system32\B1\wr730.exe.vir Infected: Trojan-Downloader.Win32.Small.eqn skipped C:\QooBox\Quarantine\C\WINDOWS\system32\b10FdUe.vir\b10FdUe1099.exe Infected: Trojan-Downloader.Win32.VB.awj skipped C:\QooBox\Quarantine\C\WINDOWS\system32\B2\sten2.exe.vir Infected: Trojan-Dropper.Win32.Agent.bfr skipped C:\QooBox\Quarantine\C\WINDOWS\system32\B5\z53.exe.vir Infected: Trojan-Dropper.Win32.Agent.mu skipped C:\QooBox\Quarantine\C\WINDOWS\system32\yfowc.dll.vir Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped C:\QooBox\Quarantine\C\WINDOWS\tk58.exe.vir Infected: Trojan.Win32.BHO.ab skipped C:\SDFix\backups\backups.zip/backups/b122.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.Rond.b skipped C:\SDFix\backups\backups.zip/backups/b122.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\SDFix\backups\backups.zip/backups/b122.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\SDFix\backups\backups.zip/backups/b122.exe Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\SDFix\backups\backups.zip/backups/b128.exe/stream/data0002/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped C:\SDFix\backups\backups.zip/backups/b128.exe/stream/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped C:\SDFix\backups\backups.zip/backups/b128.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\SDFix\backups\backups.zip/backups/b128.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\SDFix\backups\backups.zip/backups/b128.exe Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\SDFix\backups\backups.zip/backups/b136.exe/stream/data0002 Infected: Trojan-Dropper.Win32.Agent.bfr skipped C:\SDFix\backups\backups.zip/backups/b136.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\SDFix\backups\backups.zip/backups/b136.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\SDFix\backups\backups.zip/backups/b136.exe Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\SDFix\backups\backups.zip/backups/core.sys Infected: Rootkit.Win32.Agent.eq skipped C:\SDFix\backups\backups.zip/backups/retadpu1000106.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped C:\SDFix\backups\backups.zip/backups/retadpu77.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped C:\SDFix\backups\backups.zip/backups/svhost.exe Infected: Trojan.Win32.StartPage.ahg skipped C:\SDFix\backups\backups.zip ZIP: infected - 17 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP148\A0120112.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP148\A0120112.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP148\A0120112.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP148\A0120112.exe NSIS: infected - 3 skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121115.exe Infected: Trojan.Win32.BHO.ab skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121121.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.Rond.b skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121121.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121121.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121121.exe NSIS: infected - 3 skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121122.exe/stream/data0002/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121122.exe/stream/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121122.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121122.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121122.exe NSIS: infected - 4 skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121123.exe/stream/data0002 Infected: Trojan-Dropper.Win32.Agent.bfr skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121123.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121123.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121123.exe NSIS: infected - 3 skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121126.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121127.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121128.exe Infected: Trojan.Win32.StartPage.ahg skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121130.sys Infected: Rootkit.Win32.Agent.eq skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121135.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.Rond.b skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121135.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121135.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121135.exe NSIS: infected - 3 skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121136.exe/stream/data0002/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121136.exe/stream/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121136.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121136.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121136.exe NSIS: infected - 4 skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121137.exe/stream/data0002 Infected: Trojan-Dropper.Win32.Agent.bfr skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121137.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121137.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121137.exe NSIS: infected - 3 skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121140.sys Infected: Rootkit.Win32.Agent.eq skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121142.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121143.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121144.exe Infected: Trojan.Win32.StartPage.ahg skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121175.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121176.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121192.exe Infected: Trojan-Downloader.Win32.PurityScan.eh skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121194.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121200.dll Infected: Trojan.Win32.BHO.ab skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121201.dll Infected: Trojan.Win32.BHO.ab skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121202.dll Infected: Trojan.Win32.BHO.ab skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121203.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121204.exe/data0005 Infected: Trojan-Downloader.Win32.VB.awj skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121204.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121205.exe Infected: Trojan.Win32.StartPage.ahg skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121206.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121207.exe Infected: Trojan-Downloader.Win32.Small.eqn skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121208.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121208.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121210.exe Infected: Trojan.Win32.Small.oa skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121211.exe Infected: not-a-virus:AdWare.Win32.Rond.a skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121213.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.c skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121213.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121214.exe Infected: Trojan-Downloader.Win32.Small.eqn skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121215.exe Infected: Trojan-Dropper.Win32.Agent.bfr skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121216.exe Infected: Trojan-Dropper.Win32.Agent.mu skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121219.exe Infected: Trojan-Downloader.Win32.Zlob.bqw skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121221.exe Infected: Trojan.Win32.BHO.ab skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\A0121225.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped C:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\World of Warcraft\Logs\gx.log Object is locked skipped C:\World of Warcraft\Logs\Sound.log Object is locked skipped F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped F:\System Volume Information\_restore{767FFD04-5E2A-4866-B5E8-9D8DA8D4C3D6}\RP149\change.log Object is locked skipped H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped Scan process completed. Thanks for your quick responses!!
1. The reason why I asked is because I see the following in your Kaspersky log:

C:\Documents and Settings\Ryan\Desktop\Submit [2007-07-15 20.52.09.53].zip


2. There is always a possibility that your system has been damaged to the point where there is a hole left open for a trojan to penetrate. We have done a very thorough cleaning but if you don't feel right about it, format your drive and start over. You must be comfortable with your system.

3. The infections left are in quarantine. The ones in your System Restore will be purged when we do our final cleanup procedures.

4. Please DELETE the following:

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\<===Everything in that folder but not the folder itself

C:\QooBox<==The folder and all its content
C:\SDFix\<==The folder and all its content


5. Once that is all done, please tell me how your system is running and we will perform our final cleanup procedures.
Thanks for you help and timely responses Trevuren. At this point everything seems to be functioning like normal, I don't see any noticeable concerns or problems. Although I am debating whether to wipe everything and do a new XP install due to a back door, for now I am going to leave everything as is. A bit worried about it though.
Congratulations, your log shows that your SYSTEM IS CLEAN

There are a few things you must do once you are completely clean:

1. Time for some housekeeping

Please download the OTMoveIt by OldTimer
  • Save it to your desktop.
  • Run the tool by clicking on the icon.
  • Click the Cleanup button.
  • The tools that we used as well as this one will be removed from your system.

2. Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

3. Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Here are some tips to reduce the potential for spyware infection in the future:

Make sure you keep your Windows OS current by visiting Windows update
regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
And also see TonyKlein's good advice
So how did I get infected in the first place?

Regards,

Trevuren
:rant2: Well something interesting happened less than 10 minutes ago. I was reading my email when suddenly a command prompt flashed in front of me and disappeared. Immidiately I see IE pop ups everywhere and knew something was up. Ran spybot and what do you know, smitfraud is found!!!! I don't know what to do
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Double-click smitfraudfix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm


Regards,

Trevuren
Log: SmitFraudFix v2.204 Scan done at 15:13:21.65, Tue 07/17/2007 Run from C:\Documents and Settings\Ryan\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\poolsv.exe C:\WINDOWS\ypnhpnuA.exe C:\WINDOWS\retadpu572.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ryan »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ryan\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Ryan\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: NVIDIA nForce Networking Controller - Packet Scheduler Miniport DNS Server Search Order: 71.242.0.12 DNS Server Search Order: 71.252.0.12 HKLM\SYSTEM\CCS\Services\Tcpip\..\{9A714D4F-175C-423F-B919-4EE34D4252F7}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{9A714D4F-175C-423F-B919-4EE34D4252F7}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{9A714D4F-175C-423F-B919-4EE34D4252F7}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI