This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Please Check My Hjt Log

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i went to seriall.com and downloaded a keygen, now i think i'm infected.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:32:31 PM, on 7/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\PowerDVD\PDVDServ.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\WINDOWS\system32\WService.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
D:\NetGear\wlan111t.exe
C:\PATRIOT\PreAnntt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\RCT\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\spybots\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {E6F3F9C0-F591-48FD-874B-5D6307B533EE} - C:\WINDOWS\system32\ddcyx.dll (file missing)
O3 - Toolbar: ?eé??ìò?(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\FastAIT2006\IEBand.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [RemoteControl] D:\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ACDSee] D:\ACDSee\ACDSee\8.0.Pro\ACDSee8Pro.exe /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Sui] "C:\PROGRA~1\COMMON~1\§μSTEM~1\javaw.exe" -vt yazb
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\Office\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra 'Tools' menuitem: Sun Java ????ì¨ - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra button: D??¢?ì?÷ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/dsl_settings/…vzTCPConfig.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F} (McciSM Class) - http://supportcenter.verizon.net/euserv/jsp/VOLAWeb.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
O20 - Winlogon Notify: winwly32 - winwly32.dll (file missing)
O23 - Service: WinTab Service (WinTabService) - Unknown owner - C:\WINDOWS\System32\Drivers\WTSRV.EXE (file missing)

–
End of file - 4178 bytes

Hello gray123,

My name is SNOWHITE and I will be helping you with your Malware problem.

Looking over your log, it seems you don't have any evidence of an anti-virus software.

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors:

- Antivir PersonalEdition Classic

- avast! 4 Home Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

Install one of these antivirus programs, reboot run new HijackThis scan and post the new log back here.

Regards,
hi SNOWHITE, thank you for helping me. i downloaded and install AntiVir. here is my new HJT log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:04:21 PM, on 7/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\PowerDVD\PDVDServ.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\WINDOWS\system32\WService.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
D:\NetGear\wlan111t.exe
C:\PATRIOT\PreAnntt.exe
C:\WINDOWS\System32\svchost.exe
F:\ppstream\PPStream\PPStream.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
F:\RCT\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\spybots\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {E6F3F9C0-F591-48FD-874B-5D6307B533EE} - C:\WINDOWS\system32\ddcyx.dll (file missing)
O3 - Toolbar: ?eé??ìò?(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\FastAIT2006\IEBand.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [RemoteControl] D:\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ACDSee] D:\ACDSee\ACDSee\8.0.Pro\ACDSee8Pro.exe /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Sui] "C:\PROGRA~1\COMMON~1\§μSTEM~1\javaw.exe" -vt yazb
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\Office\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra 'Tools' menuitem: Sun Java ????ì¨ - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra button: D??¢?ì?÷ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/dsl_settings/…vzTCPConfig.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F} (McciSM Class) - http://supportcenter.verizon.net/euserv/jsp/VOLAWeb.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
O20 - Winlogon Notify: winwly32 - winwly32.dll (file missing)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: WinTab Service (WinTabService) - Unknown owner - C:\WINDOWS\System32\Drivers\WTSRV.EXE (file missing)

–
End of file - 4753 bytes

Hi gray123,

Please follow the steps below exactly in the order they are written:

Step #1

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

Step #2

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

In your next post please include the following reports:
  • VundoFix report
  • dss scan reports main.txt and extra.txt
Let me know how the things went.


Regards,
i downloaded Vundo yesterday and scan it once, it deleted some infected files. but i scan it again today and it said no infected files found.

VundoFix V6.5.6

Checking Java version…

Scan started at 11:53:33 PM 7/16/2007

Listing files found while scanning….

C:\WINDOWS\system32\klnmp.bak1
C:\WINDOWS\system32\klnmp.ini
C:\WINDOWS\system32\pmnlk.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\klnmp.bak1
C:\WINDOWS\system32\klnmp.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\klnmp.ini
C:\WINDOWS\system32\klnmp.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmnlk.dll
C:\WINDOWS\system32\pmnlk.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Scan started at 4:30:23 PM 7/17/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…



this is the main.txt from dss

Deckard's System Scanner v20070711.54
Run by [removed] on 2007-07-17 at 16:40:38
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
33: 2007-07-17 20:40:42 UTC - RP64 - Deckard's System Scanner Restore Point
32: 2007-07-17 19:58:46 UTC - RP63 - AntiVir PersonalEdition Classic - 7/17/2007 15:58
31: 2007-07-17 17:55:26 UTC - RP62 - Installed RollerCoaster Tycoon?3
30: 2007-07-17 17:54:34 UTC - RP61 - Installed RollerCoaster Tycoon?3
29: 2007-07-17 05:45:43 UTC - RP60 - Removed SUPERAntiSpyware Free Edition


– First Restore Point –
1: 2007-06-22 00:50:27 UTC - RP32 - 系统检查点


Backed up registry hives.

Performed disk cleanup.


– HijackThis (run as KUANG.exe) ———————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:41:08 PM, on 7/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\PowerDVD\PDVDServ.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\WINDOWS\system32\WService.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
D:\NetGear\wlan111t.exe
C:\PATRIOT\PreAnntt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Documents and Settings\KUANG\桌面\dss.exe
C:\WINDOWS\system32\conime.exe
F:\RCT\KUANG.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\spybots\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {E6F3F9C0-F591-48FD-874B-5D6307B533EE} - C:\WINDOWS\system32\ddcyx.dll (file missing)
O3 - Toolbar: ?eé??ìò?(&K;) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\FastAIT2006\IEBand.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [RemoteControl] D:\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ACDSee] D:\ACDSee\ACDSee\8.0.Pro\ACDSee8Pro.exe /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Sui] "C:\PROGRA~1\COMMON~1\§μSTEM~1\javaw.exe" -vt yazb
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X;) - res://D:\Office\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra 'Tools' menuitem: Sun Java ????ì¨ - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra button: D??¢?ì?÷ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/dsl_settings/…vzTCPConfig.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F} (McciSM Class) - http://supportcenter.verizon.net/euserv/jsp/VOLAWeb.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
O20 - Winlogon Notify: winwly32 - winwly32.dll (file missing)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: WinTab Service (WinTabService) - Unknown owner - C:\WINDOWS\System32\Drivers\WTSRV.EXE (file missing)

–
End of file - 4740 bytes

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 TClass2k (Tablet Class Driver) - c:\windows\system32\drivers\tclass2k.sys


extra.txt

Deckard's System Scanner v20070711.54
Extra logfile - please post this as an attachment with your post.
——————————————————————————–

– System Information ———————————————————-

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: Chinese

CPU 0: Intel® Celeron® CPU 3.20GHz
Percentage of Memory in Use: 63%
Physical Memory (total/avail): 479.48 MiB / 177.29 MiB
Pagefile Memory (total/avail): 1169.72 MiB / 920.75 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1964.13 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 14.65 GiB total, 7.35 GiB free.
D: is Fixed (NTFS) - 2.93 GiB total, 1.65 GiB free.
E: is Fixed (NTFS) - 24.41 GiB total, 24.34 GiB free.
F: is Fixed (NTFS) - 62.96 GiB total, 59.26 GiB free.
G: is Fixed (NTFS) - 6.84 GiB total, 6.8 GiB free.
H: is CDROM (No Media)
J: is CDROM (No Media)


– Security Center ————————————————————-

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

AV: Avira AntiVir PersonalEdition v 6.39.0.159
(Avira GmbH)

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"F:\\ppstream\\PPStream\\PPStream.exe"="F:\\ppstream\\PPStream\\PPStream.exe:*:Enabled:PPS网络电视"


– Environment Variables ——————————————————-

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\KUANG\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=63B26897616
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\KUANG
LOGONSERVER=\\63B26897616
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0409
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\KUANG\LOCALS~1\Temp
TMP=C:\DOCUME~1\KUANG\LOCALS~1\Temp
USERDOMAIN=63B26897616
USERNAME=KUANG
USERPROFILE=C:\Documents and Settings\KUANG
windir=C:\WINDOWS


– User Profiles —————————————————————

KUANG (admin)


– Add/Remove Programs ———————————————————

–> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
–> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 9 ActiveX –> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
Avira AntiVir PersonalEdition Classic –> C:\Program Files\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
FastAIT 2006 –> MsiExec.exe /I{09AD093B-BB4C-4732-9F59-02C49B66E025}
HijackThis 2.0.2 –> "F:\RCT\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) –> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Java 2 Runtime Environment, SE v1.4.2_14 –> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142140}
Kaspersky Online Scanner –> C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
Microsoft Compression Client Pack 1.0 for Windows XP –> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003 –> MsiExec.exe /I{90110804-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 –> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Nero 6 Ultra Edition –> D:\Nero\nero\uninstall\UNNERO.exe /UNINSTALL
NETGEAR WG111T 108Mbps Wireless USB2.0 Adapter –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{51123D42-6B9C-4B93-900C-29F9EC5963C9}\Setup.exe"
Panda ActiveScan –> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
PowerDVD –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
Powerword 2006 –> MsiExec.exe /I{1D44EA4F-C446-4C4F-92F7-02F72E589989}
PPStream –> "F:\ppstream\PPStream\unins000.exe"
QQ广东麻将 –> G:\QQGAME~1\QQGAME\GDMJ\UNWISE.EXE G:\QQGAME~1\QQGAME\GDMJ\INSTALL.LOG
QQ火拼泡泡龙 –> G:\QQGAME~1\QQGAME\PAOPAO~1\UNWISE.EXE G:\QQGAME~1\QQGAME\PAOPAO~1\INSTALL.LOG
RealPlayer –> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek AC'97 Audio –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\Setup.exe" -l0x804 -removeonly
SiS 661FX –> Rundll32 SiSInst.dll,Uninstall VGA,R,oem3.inf
SiS 900 PCI Fast Ethernet Adapter Driver –> C:\Progra~1\SiSLan\Uninst.exe
SiSAGP driver –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DC226AC9-0314-496C-BE6A-B6A132628466}\SETUP.EXE" -l0x804
Spybot - Search & Destroy 1.4 –> "F:\spybots\Spybot - Search & Destroy\unins000.exe"
Verizon Online Help and Support –> C:\PROGRA~1\Verizon\UNWISE.EXE C:\PROGRA~1\Verizon\INSTALL.LOG
Verizon SmartCall –> C:\PROGRA~1\VERIZO~1\SMARTC~1\UNWISE.EXE C:\PROGRA~1\VERIZO~1\SMARTC~1\INSTALL.LOG
VideoLAN VLC media player 0.8.6b –> F:\VLC\uninstall.exe
Windows Live Messenger –> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Media Format 11 runtime –> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows XP (KB923689) 安全更新 –> "C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Windows XP 修补程序包 - KB873339 –> C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Windows XP 修补程序包 - KB885835 –> C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Windows XP 修补程序包 - KB885836 –> C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Windows XP 修补程序包 - KB886185 –> C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Windows XP 修补程序包 - KB886677 –> C:\WINDOWS\$NtUninstallKB886677$\spuninst\spuninst.exe
Windows XP 修补程序包 - KB887472 –> C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Windows XP 修补程序包 - KB888302 –> C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Windows XP 修补程序包 - KB890859 –> "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Windows XP 修补程序包 - KB891781 –> C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Windows XP 安全更新 (KB893756) –> "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB896358) –> "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB896423) –> "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB896428) –> "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB899587) –> "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB899591) –> "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB900725) –> "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB901017) –> "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB901190) –> "C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB901214) –> "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB902400) –> "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB904706) –> "C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB905414) –> "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB905749) –> "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB908519) –> "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB911562) –> "C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB911927) –> "C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB913580) –> "C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB914388) –> "C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB914389) –> "C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB917344) –> "C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB917422) –> "C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB917953) –> "C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB918118) –> "C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB918439) –> "C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB919007) –> "C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB920213) –> "C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB920670) –> "C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB920683) –> "C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB920685) –> "C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB922819) –> "C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB923191) –> "C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB923414) –> "C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB923694) –> "C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB923789) –> C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Windows XP 安全更新 (KB923980) –> "C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB924191) –> "C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB924270) –> "C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB924496) –> "C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB924667) –> "C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB925902) –> "C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB926255) –> "C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB926436) –> "C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB927779) –> "C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB927802) –> "C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB928090) –> "C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB928255) –> "C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB928843) –> "C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB929123) –> "C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB929969) –> "C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB930178) –> "C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB931261) –> "C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB931768) –> "C:\WINDOWS\$NtUninstallKB931768$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB931784) –> "C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB932168) –> "C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB933566) –> "C:\WINDOWS\$NtUninstallKB933566$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB935839) –> "C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Windows XP 安全更新 (KB935840) –> "C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Windows XP 更新 (KB894391) –> "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Windows XP 更新 (KB898461) –> "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Windows XP 更新 (KB900485) –> "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Windows XP 更新 (KB908531) –> "C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Windows XP 更新 (KB910437) –> "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Windows XP 更新 (KB911280) –> "C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Windows XP 更新 (KB916595) –> "C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Windows XP 更新 (KB920872) –> "C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Windows XP 更新 (KB922582) –> "C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Windows XP 更新 (KB927891) –> "C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Windows XP 更新 (KB930916) –> "C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Windows XP 更新 (KB931836) –> "C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
Windows XP 更新 (KB936357) –> "C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
WinRAR archiver –> D:\WinRAR\uninstall.exe
华旗资讯 –> C:\WINDOWS\uninst.exe -f"f:\我的文档\my videos\DeIsL1.isu" -c"f:\我的文档\my videos\_ISREG32.DLL"
暴风影音2.0 –> C:\Program Files\StormII\uninst.exe
敬碔 –> C:\WINDOWS\IsUninst.exe -ff:\叮当大富翁\Uninst.isu


– End of Deckard's System Scanner: finished at 2007-07-17 at 16:41:44 ———

gray123,

Please re-open HiJackThis and click on "Do a system scan only". Check the boxes next to all the entries listed below.

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {E6F3F9C0-F591-48FD-874B-5D6307B533EE} - C:\WINDOWS\system32\ddcyx.dll (file missing)
O20 - Winlogon Notify: winwly32 - winwly32.dll (file missing)

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.


1. Download combofix from one of these links:
Link1
Link2
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Reboot, then run new scan with HijackThis. Post back with Combofix report and the new log from HIjackThis.
here is my combofix log

"KUANG" - 2007-07-17 17:58:09 - ComboFix 07-07-14.6 - Service Pack 2 NTFS


((((((((((((((((((((((((( Files Created from 2007-06-17 to 2007-07-17 )))))))))))))))))))))))))))))))


2007-07-17 16:40

d——– C:\Deckard
2007-07-17 15:58 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic
2007-07-17 02:01 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-17 02:01 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-17 01:46 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-17 01:35 d——– C:\WINDOWS\system32\ActiveScan
2007-07-17 00:01 6,369 —hs—- C:\WINDOWS\system32\xycdd.bak1
2007-07-16 23:59 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-16 23:53 d——– C:\VundoFix Backups
2007-07-16 22:46 d——– C:\Program Files\Common Files\?уstem32
2007-07-16 22:38 d——– C:\DOCUME~1\KUANG\APPLIC~1\Atari
2007-07-16 20:21 685,816 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-07-16 16:18 45,056 –a—— C:\WINDOWS\system32\UnACE.dll
2007-07-16 16:18 314,368 –a—— C:\WINDOWS\IsUninst.exe
2007-07-16 16:18 d–h—– C:\WINDOWS\PIF
2007-07-11 03:17 d——– C:\Program Files\NextLink
2007-07-01 00:30 d——– C:\DOCUME~1\KUANG\Contacts
2007-07-01 00:29 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-07-01 00:29 d——– C:\Program Files\MSN Messenger
2007-06-30 23:39 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-30 21:25 d——– C:\DOCUME~1\KUANG\APPLIC~1\Apple Computer
2007-06-29 15:35 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PPStream
2007-06-29 14:10 204,800 –a—— C:\WINDOWS\system32\lsvxdec.dll
2007-06-29 14:09 150,016 –a—— C:\WINDOWS\system32\ativcr2.dll
2007-06-29 14:07 92,672 –a—— C:\WINDOWS\system32\asusasv2.dll
2007-06-29 14:07 88,464 –a—— C:\WINDOWS\system32\DECVW_32.DLL
2007-06-29 14:07 761,856 –a—— C:\WINDOWS\system32\xvidcore.dll
2007-06-29 14:07 76,800 –a—— C:\WINDOWS\system32\VDODEC32.dll
2007-06-29 14:07 75,264 –a—— C:\WINDOWS\system32\MACDec.dll
2007-06-29 14:07 71,680 –a—— C:\WINDOWS\system32\asusasv1.dll
2007-06-29 14:07 630,784 –a—— C:\WINDOWS\system32\vp7vfw.dll
2007-06-29 14:07 5,120 –a—— C:\WINDOWS\system32\ff_vfw.dll
2007-06-29 14:07 438,272 –a—— C:\WINDOWS\system32\vp6vfw.dll
2007-06-29 14:07 40,960 –a—— C:\WINDOWS\system32\frapsvid.dll
2007-06-29 14:07 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2007-06-29 14:07 338,432 –a—— C:\WINDOWS\system32\LCodcCMP.dll
2007-06-29 14:07 312,832 –a—— C:\WINDOWS\system32\CLRVIDDC.DLL
2007-06-29 14:07 307,200 –a—— C:\WINDOWS\system32\icmw_32.dll
2007-06-29 14:07 24,064 –a—— C:\WINDOWS\system32\aasc32.dll
2007-06-29 14:07 163,840 –a—— C:\WINDOWS\system32\vmnc.dll
2007-06-29 14:07 155,648 –a—— C:\WINDOWS\system32\avidavicodec.dll
2007-06-29 14:07 135,168 –a—— C:\WINDOWS\system32\clrviddd.dll
2007-06-29 14:07 102,400 –a—— C:\WINDOWS\system32\tsccvid.dll
2007-06-28 21:51 480 –a—— C:\WINDOWS\system32\keys.dat
2007-06-28 21:49 d——– C:\Program Files\StormII
2007-06-28 21:49 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Storm
2007-06-28 20:51 d——– C:\DOCUME~1\KUANG\APPLIC~1\ppstream
2007-06-27 17:18 d——– C:\WINDOWS\system32\PPLive
2007-06-27 03:23 d——– C:\DOCUME~1\KUANG\APPLIC~1\Motive
2007-06-27 03:17 d——– C:\Program Files\Verizon
2007-06-26 21:56 d——– C:\Program Files\Verizon Online
2007-06-26 21:56 d——– C:\Program Files\Common Files\Motive
2007-06-26 21:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive
2007-06-25 00:03 229,376 –a—— C:\WINDOWS\SETUPX32.EXE
2007-06-25 00:03 d——– C:\PATRIOT
2007-06-25 00:00 299,520 –a—— C:\WINDOWS\uninst.exe
2007-06-22 20:13 d——– C:\WINDOWS\system32\appmgmt


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-17 17:55:26 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-07-17 05:29:30 ——– d—–w C:\Program Files\Common Files\?уstem32
2007-07-07 22:04:18 163,644 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-07-05 21:38:31 ——– d—–w C:\Program Files\Real
2007-07-05 21:37:15 ——– d—–w C:\Program Files\Google
2007-06-29 17:27:21 ——– d—–w C:\Program Files\Common Files\Real
2007-06-23 00:13:21 ——– d—–w C:\Program Files\Common Files\ACD Systems
2007-06-03 02:26:27 ——– d—–w C:\Program Files\Common Files\Nullsoft
2007-05-30 00:24:50 ——– d—–w C:\DOCUME~1\KUANG\APPLIC~1\Google
2007-05-30 00:24:48 ——– d—–w C:\DOCUME~1\KUANG\APPLIC~1\Real
2007-05-30 00:24:02 ——– d—–w C:\Program Files\Common Files\xing shared
2007-05-30 00:18:26 ——– d—–w C:\DOCUME~1\KUANG\APPLIC~1\vlc
2007-05-27 04:33:13 ——– d—–w C:\DOCUME~1\KUANG\APPLIC~1\WinRAR
2007-05-20 22:41:55 ——– d—–w C:\Program Files\Windows Media Connect 2
2007-05-20 14:30:11 40,494 —-a-w C:\WINDOWS\system32\prfc0804.dat
2007-05-20 14:30:11 118,416 —-a-w C:\WINDOWS\system32\prfh0804.dat
2007-05-20 14:28:52 17,801 —-a-w C:\WINDOWS\system32\drivers\AegisP.sys
2007-05-16 15:13:33 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-03 19:41:20 0 –sha-r C:\MSDOS.SYS
2007-05-03 19:41:20 0 –sha-r C:\IO.SYS
2007-05-03 19:41:20 0 —-a-w C:\CONFIG.SYS
2007-05-03 19:41:20 0 —-a-w C:\AUTOEXEC.BAT
2007-05-03 19:38:16 21,464 —-a-w C:\WINDOWS\system32\emptyregdb.dat
2007-04-25 14:21:06 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:14 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— F:\spybots\SPYBOT~1\SDHelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-11-11 02:07 C:\WINDOWS\soundman.exe]
"SiSPower"="SiSPower.dll" [2005-11-10 02:28 C:\WINDOWS\system32\SiSPower.dll]
"RemoteControl"="D:\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"IMSCMig"="C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.exe" [2003-07-14 22:57]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-29 20:23]
"WService"="WService.EXE" [2001-08-01 05:39 C:\WINDOWS\system32\WService.exe]
"Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-06-06 19:52]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe" []
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 10:35]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 20:52]
"ACDSee"="D:\ACDSee\ACDSee\8.0.Pro\ACDSee8Pro.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"Sui"="C:\PROGRA~1\COMMON~1\УSTEM~1\javaw.exe" []


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76a426d6-187e-11dc-a485-00184d2db005}]
AutoRun\command- RavMon.exe

*Newly Created Service* - ANTIVIRSCHEDULER
*Newly Created Service* - ANTIVIRSERVICE
*Newly Created Service* - AVGIO
*Newly Created Service* - AVGNTFLT
*Newly Created Service* - AVIPBB

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-17 17:59:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-17 17:59:58
C:\ComboFix-quarantined-files.txt … 2007-07-17 17:59
C:\ComboFix2.txt … 2007-07-17 02:43
C:\ComboFix3.txt … 2007-07-17 01:48

— E O F —


new HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:03:09 PM, on 7/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\WService.EXE
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
D:\NetGear\wlan111t.exe
C:\PATRIOT\PreAnntt.exe
C:\WINDOWS\system32\wuauclt.exe
F:\RCT\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\spybots\SPYBOT~1\SDHelper.dll
O3 - Toolbar: ?eé??ìò?(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\FastAIT2006\IEBand.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [RemoteControl] D:\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ACDSee] D:\ACDSee\ACDSee\8.0.Pro\ACDSee8Pro.exe /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Sui] "C:\PROGRA~1\COMMON~1\§μSTEM~1\javaw.exe" -vt yazb
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\Office\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra 'Tools' menuitem: Sun Java ????ì¨ - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra button: D??¢?ì?÷ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/dsl_settings/…vzTCPConfig.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F} (McciSM Class) - http://supportcenter.verizon.net/euserv/jsp/VOLAWeb.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: WinTab Service (WinTabService) - Unknown owner - C:\WINDOWS\System32\Drivers\WTSRV.EXE (file missing)

–
End of file - 4423 bytes

gray123,


Step #1

CLICK THIS TO LINK TO BE SURE YOU CAN VIEW HIDDEN FILES

Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these folders/files (if present):

C:\Program Files\Common Files\?уstem32 << This folder

C:\WINDOWS\system32\xycdd.bak1 << This file

Close Windows Explorer.


Step #2

Lets run scan with AntiVir, follow the steps below, also see this tutorial for setting up and running scan with AntiVir : http://jamielaw.ipbfree.com/index.php?show…=0&#entry37
  • Start AntiVir

    Right-Click the AntiVir icon on your desktop and select Start update.
  • Make sure that AntiVir Guard is Activated
  • Check the box: Expert Mode. Expand all the drop-down lists. Under the Scanner heading select Scan. Make sure next is selected:
    • All files
    • Scan boot sectors of selected drives
    • Search master boot sectors
    • Scan memory
    • Ignore offline files
  • Under Scan process:
    • Allow stopping the scanner
      - Scanner priority: low
    Press OK button.
  • Under the Scanner heading select Scan then select Action for concerning files. Make sure next is selected:
  • Under Action for concerning files select
    • Automatic
    • Copy file to quarantine before action
    • Primary action set to - repair
    • Secondary action set to - delete
    Press OK button.
  • Under the Scanner heading select Scan then select Archives. Make sure next is selected:
    • Scan archives
    • All archive types
    • Smart extensions
    • Limit recursion depth
      - Maximum recursion depth set to - 20
  • Into the Archives box, leave everything checked.

    Press OK button.
  • Under the Guard heading select Scan. Check the box: All files
    -Leave everything else as default.

    Press OK button.
  • Close AntiVir, and reboot in Safe Mode. Restart your computer, as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.Use your up arrow key to highlight SafeMode then hit Enter.


    On-demand Scanning with AntiVir

    1. Right-Click the AntiVir icon on your desktop and select Start AntiVir.

    2. Select the Scanner tab. Right-click on Local Hard Disks. Select Scan.

    3. When the scan has finished the results will be displayed. Post the report back here in this thread.
here is the report.

AntiVir PersonalEdition Classic
Report file date: Tuesday, July 17, 2007 20:18

Scanning for 947853 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: KUANG
Computer name: 63B26897616

Version information:
BUILD.DAT : 247 14437 Bytes 2007-5-10 11:55:00
AVSCAN.EXE : [removed] 282664 Bytes 2007-4-20 17:37:14
AVSCAN.DLL : [removed] 33832 Bytes 2007-3-27 17:31:54
LUKE.DLL : [removed] 143400 Bytes 2007-3-27 17:26:04
LUKERES.DLL : [removed] 10280 Bytes 2007-3-19 17:18:59
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 2006-5-31 19:08:58
ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 2007-7-10 20:02:50
ANTIVIR2.VDF : 6.39.0.148 395776 Bytes 2007-7-16 20:02:50
ANTIVIR3.VDF : 6.39.0.159 63488 Bytes 2007-7-17 20:02:50
AVEWIN32.DLL : [removed] 2490880 Bytes 2007-7-17 20:02:50
AVWINLL.DLL : 1.0.0.7 14376 Bytes 2007-2-26 15:36:26
AVPREF.DLL : [removed] 24616 Bytes 2007-3-27 17:31:50
AVREP.DLL : [removed] 155688 Bytes 2007-4-16 18:16:24
AVPACK32.DLL : [removed] 360488 Bytes 2007-7-17 20:02:51
AVREG.DLL : [removed] 31784 Bytes 2007-3-15 14:05:08
AVEVTLOG.DLL : [removed] 86056 Bytes 2007-3-27 17:16:05
AVARKT.DLL : 1.0.0.17 278568 Bytes 2007-5-2 16:32:26
NETNT.DLL : [removed] 7720 Bytes 2007-3-8 16:09:42
RCIMAGE.DLL : [removed] 2228264 Bytes 2007-3-13 15:46:18
RCTEXT.DLL : [removed] 86056 Bytes 2007-3-19 17:42:42

Configuration settings for the scan:
Jobname……………………..: Local Drives
Configuration file……………: C:\Program Files\AntiVir PersonalEdition Classic\alldrives.avp
Logging……………………..: low
Primary action……………….: repair
Secondary action……………..: delete
Scan master boot sector……….: on
Scan boot sector……………..: on
Boot sectors…………………: J:,
Scan memory………………….: on
Process scan…………………: on
Scan registry………………..: on
Search for rootkits…………..: off
Scan all files……………….: All files
Scan archives………………..: on
Recursion depth………………: 20
Smart extensions……………..: on
Deviating archive types……….: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
Macro heuristic………………: on
File heuristic……………….: medium

Start of the scan: Tuesday, July 17, 2007 20:18

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
12 processes with 12 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[NOTE] No virus was found!
Master boot sector HD1
[NOTE] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Boot sector 'E:\'
[NOTE] No virus was found!
Boot sector 'F:\'
[NOTE] No virus was found!
Boot sector 'G:\'
[NOTE] No virus was found!
Boot sector 'I:\'
[NOTE] No virus was found!
Boot sector 'A:\'
[NOTE] In the drive 'A:\' no data medium is inserted!

Starting to scan the registry.
The registry was scanned ( '19' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\WINDOWS\mgrs.exe~
[DETECTION] Is the Trojan horse TR/Dldr.Agent.11776
[INFO] A backup was created as '470f5e1d.qua' ( QUARANTINE )
[INFO] The file was deleted!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\'
Begin scan in 'E:\'
Begin scan in 'F:\'
F:\ppstream\PPStream\partner\update.exe
[DETECTION] Is the Trojan horse TR/PSW.Wow.MM.20
[INFO] A backup was created as '4701640a.qua' ( QUARANTINE )
[INFO] The file was deleted!
Begin scan in 'G:\'
Begin scan in 'I:\'
Begin scan in 'A:\'
Search path A:\ could not be opened!
设备未就绪。

Begin scan in 'H:\'
Search path H:\ could not be opened!
设备未就绪。

Begin scan in 'J:\'
Search path J:\ could not be opened!
设备未就绪。



End of the scan: Tuesday, July 17, 2007 20:55
Used time: 37:04 min

The scan has been done completely.

2529 Scanning directories
116404 Files were scanned
2 viruses and/or unwanted programs were found
0 classified as suspicious:
2 files were deleted
0 files were repaired
2 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
116402 Files not concerned
741 Archives were scanned
2 Warnings
131 Notes
0 Hidden objects were found

Hello gray123,

Its looking good, but lets do more researching before i let you go.

PLEASE READ THIS POST COMPLETELY, IT MAY MAKE IT EASIER FOR YOU IF YOU COPY AND PASTE THIS POST INTO A NEW TEXT DOCUMENT OR PRINT IT FOR REFERENCE LATER



Please follow the steps below exactly in the order they are written:

Step #1

1. Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only


2. Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

If you are unable to run scan with AVG Anti-Spyware in Safe Mode, Click the next link http://fileserver.ewido.net/public.cgi?id=20990 and download AVG_Anti-Spyware_7.5.1.36_Safe_Mode_Registry_Patch.reg to your desktop. It should look like this -> [external image: Posted Image] double click on it. You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer "Yes" and wait for a message to appear similar to "Merged Successfully".

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

Step #2


Download and Save Blacklight to your desktop (choose "I ACCEPT" then click "DOWNLOAD" on the website).

Double-click fsbl.exe then accept the agreement, click > "Scan" then > "Next".

You'll see a list of all items found. There will also be a log on your desktop with the name "fsbl.xxxxxxxxxxxxxx.log" (the xxxxxxxxxxxxxx stand for numbers).

Copy and paste this log in your next reply. Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"


Post back with AVG Anti-Spyware report, Blacklight report and new HijackThis log.
Let me know how is the computer running.


Rehards,
my computer is running fine… not seeing any problems

here is the AVG anti-spyware report

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 12:06:33 PM 7/18/2007

+ Scan result:



C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP59\A0013536.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP59\A0013542.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP59\A0013535.exe -> Downloader.Alphabet.h : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP60\A0013566.exe -> Downloader.Small.eqn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP58\A0012559.exe/keygen.exe -> Dropper.Small.ayg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP59\A0013539.exe -> Dropper.Small.ayg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP60\A0013568.exe/keygen.exe -> Dropper.Small.ayg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP59\A0013540.dll -> Trojan.Agent.qt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP59\A0013534.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP59\A0013538.exe -> Trojan.Small : Cleaned with backup (quarantined).


::Report end


fsbl report… when i clicked on apply all action, i couldn't save reports, it said there is not report or something similar to that. i think the fsbl report is wrong… i'll do another scan.

fsbl report

07/18/07 12:14:48 [Info]: BlackLight Engine 1.0.64 initialized
07/18/07 12:14:48 [Info]: OS: 5.1 build 2600 (Service Pack 2)
07/18/07 12:14:48 [Note]: 7019 4
07/18/07 12:14:48 [Note]: 7005 0
07/18/07 12:14:55 [Note]: 7006 0
07/18/07 12:14:56 [Note]: 7011 1616
07/18/07 12:14:56 [Note]: 7026 0
07/18/07 12:14:56 [Note]: 7026 0
07/18/07 12:15:00 [Note]: FSRAW library version 1.7.1022
07/18/07 12:16:56 [Note]: 2000 1012
07/18/07 12:16:56 [Note]: 2000 1012
07/18/07 12:16:56 [Note]: 2000 1012
07/18/07 12:20:44 [Note]: 7007 0


HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:30:45 PM, on 7/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\PowerDVD\PDVDServ.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\WINDOWS\system32\WService.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
D:\NetGear\wlan111t.exe
C:\PATRIOT\PreAnntt.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
F:\AVG Anti-Spyware\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
F:\RCT\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\spybots\SPYBOT~1\SDHelper.dll
O3 - Toolbar: ?eé??ìò?(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\FastAIT2006\IEBand.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [RemoteControl] D:\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ACDSee] D:\ACDSee\ACDSee\8.0.Pro\ACDSee8Pro.exe /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Sui] "C:\PROGRA~1\COMMON~1\§μSTEM~1\javaw.exe" -vt yazb
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\Office\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra 'Tools' menuitem: Sun Java ????ì¨ - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra button: D??¢?ì?÷ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/dsl_settings/…vzTCPConfig.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F} (McciSM Class) - http://supportcenter.verizon.net/euserv/jsp/VOLAWeb.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\AVG Anti-Spyware\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: WinTab Service (WinTabService) - Unknown owner - C:\WINDOWS\System32\Drivers\WTSRV.EXE (file missing)

–
End of file - 4634 bytes

Hello gray123,

I don't recognise this programs :

QQ广东麻将 –> G:\QQGAME~1\QQGAME\GDMJ\UNWISE.EXE G:\QQGAME~1\QQGAME\GDMJ\INSTALL.LOG
QQ火拼泡泡龙 –> G:\QQGAME~1\QQGAME\PAOPAO~1\UNWISE.EXE G:\QQGAME~1\QQGAME\PAOPAO~1\INSTALL.LOG
华旗资讯 –> C:\WINDOWS\uninst.exe -f"f:\我的文档\my videos\DeIsL1.isu" -c"f:\我的文档\my videos\_ISREG32.DLL"
暴风影音2.0 –> C:\Program Files\StormII\uninst.exe
敬碔 –> C:\WINDOWS\IsUninst.exe -ff:\叮当大富翁\Uninst.isu

So if you haven't install them and don't know what they are remove them.

Step #1

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 2 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u2…allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Read the License Agreement and then check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.
Step #2

Lets set you up with Firewall to keep your computer safer! Having a firewall is important in protecting your computer from hackers or viruses. Read this Understanding and Using FirewallsBoth of the firewall programs are free and easy to install, make sure to install only one of them :)

If you decide to install Comodo, here is a good and easy to understand tutorial http://www.nordicnature.net/tutorials/index.html


Step #3

* Click start then run, type prefetch then press enter, click edit then select all, (all files will highlight), right click any file, click delete, confirm.


* Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Click the "Delete Cookies" button
  • Next to it, Click the "Delete Files" button
  • When prompted, place a check in: "Delete all offline content", click OK
* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu on the left side of the Options window.
  • Click the Clear button located to the right of each option (History, Cookies, Cache).
  • Click OK to close the Options window
    Alternatively, you can clear all information stored while browsing by clicking Clear All.
    A confirmation dialog box will be shown before clearing the information.
* Clean other Temporary files + Recycle bin
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.
Step #4

Please do an online scan with Kaspersky WebScanner

NOTE: This Scanner will work with Internet Explorer Only!


Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save Report As… button:
  • Under Save as type select Text file write name for the file and save it to your Desktop.
  • Locate the file at the Desktop, open it, then copy and paste that information in your next post.
Post back with Kaspersky scan report and new HijackThis log.

Also do you have flash drive?

Regards,
this is the online scan:

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, July 18, 2007 11:11:23 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 19/07/2007
Kaspersky Anti-Virus database records: 364971
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
J:\

Scan Statistics:
Total number of scanned objects: 60159
Number of viruses found: 2
Number of infected objects: 2
Number of suspicious objects: 2
Duration of the scan process: 01:10:33

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip/win1B.tmp.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\KUANG\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\KUANG\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\KUANG\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\KUANG\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\KUANG\Local Settings\History\History.IE5\MSHist012007071820070719\index.dat Object is locked skipped
C:\Documents and Settings\KUANG\Local Settings\Temp\~DF1121.tmp Object is locked skipped
C:\Documents and Settings\KUANG\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\KUANG\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\KUANG\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{EBD310F9-0EF1-4809-847A-FD746C7F7090}\RP72\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{8F5F30FB-C85B-4134-8731-4EB941A5291F}\RP36\A0006695.exe/data0011 Infected: not-a-virus:AdWare.Win32.Comet.bb skipped
F:\System Volume Information\_restore{8F5F30FB-C85B-4134-8731-4EB941A5291F}\RP36\A0006695.exe NSIS: infected - 1 skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.


HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:13:07 PM, on 7/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\PowerDVD\PDVDServ.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\WService.EXE
F:\Java\bin\jusched.exe
F:\Comodo Free Firewall\Comodo\Firewall\CPF.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
F:\AVG Anti-Spyware\AVG Anti-Spyware 7.5\guard.exe
F:\Comodo Free Firewall\Comodo\Firewall\cmdagent.exe
D:\NetGear\wlan111t.exe
C:\PATRIOT\PreAnntt.exe
C:\WINDOWS\System32\svchost.exe
F:\RCT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ebay.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ??
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\spybots\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Java\bin\ssv.dll
O3 - Toolbar: ????(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\FastAIT2006\IEBand.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [RemoteControl] D:\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Java\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "F:\Comodo Free Firewall\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE
O4 - HKCU\..\Run: [ACDSee] D:\ACDSee\ACDSee\8.0.Pro\ACDSee8Pro.exe /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Sui] "C:\PROGRA~1\COMMON~1\?STEM~1\javaw.exe" -vt yazb
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Java\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java ??? - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Java\bin\ssv.dll
O9 - Extra button: ???? - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/dsl_settings/…vzTCPConfig.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F} (McciSM Class) - http://supportcenter.verizon.net/euserv/jsp/VOLAWeb.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\AVG Anti-Spyware\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - F:\Comodo Free Firewall\Comodo\Firewall\cmdagent.exe
O23 - Service: WinTab Service (WinTabService) - Unknown owner - C:\WINDOWS\System32\Drivers\WTSRV.EXE (file missing)

–
End of file - 5047 bytes


i have a flash drive for my internet, because my computer couldn't get wireless, so i bought a flash drive instead.. too lazy to install it..
Hello gray123,

i have a flash drive for my internet, because my computer couldn't get wireless, so i bought a flash drive instead.. too lazy to install it..


There is one entry that points to flash drive infection, except this, your logs are looking good.

Please run new scan with dss and post the contents of main.txt.

Regards,
i have a portable hard drive… probably that one got infected

main.txt

Deckard's System Scanner v20070711.54
Run by [removed] on 2007-07-19 at 11:28:42
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as KUANG.exe) ———————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:51 AM, on 7/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
D:\PowerDVD\PDVDServ.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
F:\AVG Anti-Spyware\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\WService.EXE
C:\Program Files\Verizon\McciTrayApp.exe
F:\Comodo Free Firewall\Comodo\Firewall\cmdagent.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
F:\Java\bin\jusched.exe
F:\Comodo Free Firewall\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\CTFMON.EXE
C:\Program Files\Messenger\msmsgs.exe
D:\NetGear\wlan111t.exe
C:\PATRIOT\PreAnntt.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\KUANG\桌面\dss.exe
F:\RCT\KUANG.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\spybots\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Java\bin\ssv.dll
O3 - Toolbar: ?eé??ìò?(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\FastAIT2006\IEBand.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [RemoteControl] D:\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Java\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "F:\Comodo Free Firewall\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ACDSee] D:\ACDSee\ACDSee\8.0.Pro\ACDSee8Pro.exe /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Sui] "C:\PROGRA~1\COMMON~1\§μSTEM~1\javaw.exe" -vt yazb
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\Office\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Java\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java ??? - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Java\bin\ssv.dll
O9 - Extra button: D??¢?ì?÷ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/dsl_settings/…vzTCPConfig.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F} (McciSM Class) - http://supportcenter.verizon.net/euserv/jsp/VOLAWeb.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\AVG Anti-Spyware\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - F:\Comodo Free Firewall\Comodo\Firewall\cmdagent.exe
O23 - Service: WinTab Service (WinTabService) - Unknown owner - C:\WINDOWS\System32\Drivers\WTSRV.EXE (file missing)

–
End of file - 5095 bytes

– Files created between 2007-06-19 and 2007-07-19 —————————–

2007-07-19 02:01:58 1350 –a—— C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
2007-07-19 00:10:38 0 d——– C:\Documents and Settings\KUANG\Application Data\Comodo
2007-07-18 23:40:33 0 d——– C:\WINDOWS\SIS
2007-07-18 23:39:41 0 d——– C:\Program Files\SiS VGA Utilities V3.81
2007-07-18 23:35:24 49152 –a—— C:\WINDOWS\system32\sis660.bin
2007-07-18 18:29:55 0 d——– C:\Documents and Settings\All Users\Application Data\Comodo
2007-07-18 18:05:43 4456448 –a—— C:\Documents and Settings\KUANG\ntuser.dat
2007-07-18 17:52:35 43520 –a—— C:\WINDOWS\system32\CmdLineExt03.dll
2007-07-18 17:42:28 0 d——– C:\Program Files\Sun
2007-07-18 17:39:27 0 d——– C:\Program Files\Common Files\Java
2007-07-18 14:59:25 155648 –a—— C:\WINDOWS\system32\libssl32.dll
2007-07-18 10:47:12 0 d——– C:\Documents and Settings\KUANG\Application Data\Grisoft
2007-07-18 10:46:56 0 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-07-18 01:13:25 0 d——– C:\Downloads
2007-07-17 15:58:58 0 d——– C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
2007-07-17 02:01:03 0 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-07-17 02:01:02 0 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-17 01:59:20 0 dr-h—– C:\Documents and Settings\KUANG\Recent
2007-07-17 01:35:47 0 d——– C:\WINDOWS\system32\ActiveScan
2007-07-16 23:59:03 0 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-07-16 23:53:33 0 d——– C:\VundoFix Backups
2007-07-16 22:38:49 0 d——– C:\Documents and Settings\KUANG\Application Data\Atari
2007-07-16 20:21:22 685816 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-07-16 16:18:42 0 d–h—– C:\WINDOWS\PIF
2007-07-16 16:18:20 45056 –a—— C:\WINDOWS\system32\UnACE.dll
2007-07-16 16:18:01 314368 –a—— C:\WINDOWS\IsUninst.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI