This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Extremely Frustrated About To Give Up...help Please?

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi All,

Norton Antivirus told me yesterday the following were trojan horse risks in the following folders:

Trojan Horse Winspss.exe C:\WINDOWS\system32\4875\
Trojan Horse file1[1].exe D:\Documents and Settings\jungsoo.kim\Local Settings\Temporary Internet Files\Content.IE5\ST4R0T4P\ (however, ST4R0T4P seems to be replaced with random Letters and #'s every time differently)

Norton was unable to remove any of these, and in effect, quarantines these files away. However, the next time I try browsing the web, the same pop-up notifications occur, and once again Norton quarantines the files…as you can see…this is a reoccuring thing every couple of minutes

I have tried the following: I have disabled system restore and scanned my computer with norton in safe mode (no results). I have navigated and deleted both folders stated above. (however, the trojan seems to replenish itself and recreate these folders after a reboot). I have actually PAID for RemoveIT Pro v4, where it detected System32.Winspss as a virus, but after I click "Fix It", it says it's been fixed, but nevertheless, after I do another system scan, it still exists….

Here is my HiJackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 12:40:50 PM, on 7/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\iPass\iPassConnect\iPCAgent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
C:\WINDOWS\system32\Prot_srv.exe
C:\WINDOWS\system32\pstartSr.exe
C:\Program Files\ISS\Proventia Desktop\RapApp.exe
C:\Program Files\RSA Security\Web PassPort\Plug-In\system\sdtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\RSA Security\Web PassPort\Plug-In\System\sdlss.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Creative\Sound Blaster Audigy 2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\Sound Blaster Audigy 2\SB Performance Utility\CTPowUti.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ISS\Proventia Desktop\vpatch.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\PROGRA~1\Secway\SimpPro\SimpPro.exe
C:\Program Files\ISS\Proventia Desktop\blackice.exe
C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSCM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acstp\icserv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\InCode Solutions\RemoveIT Pro v4\removeit.exe
C:\Program Files\InCode Solutions\RemoveIT Pro v4\HLP.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DMCC4 Class - {46D7627B-2D58-40F0-8AE9-C4D59A2F1C92} - C:\WINDOWS\system32\mdmcc4.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll (file missing)
O2 - BHO: noep Class - {FF71FF86-04AC-4cb2-A35A-1262BF791A01} - C:\WINDOWS\system32\psjm.dll
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\RSA Security\Web PassPort\Plug-In\system\sdtray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Accenture Connection] "C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe"
O4 - HKLM\..\Run: [Pointsec Tray] "C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\Sound Blaster Audigy 2\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTPerformanceUtility] "C:\Program Files\Creative\Sound Blaster Audigy 2\SB Performance Utility\CTPowUti.exe"
O4 - HKLM\..\Run: [SearchPiaUpdate] C:\program Files\SearchPia\Update.exe
O4 - HKLM\..\Run: [WMSRC] C:\Program Files\Windows Media Player\siratic.exe
O4 - HKLM\..\Run: [pang] C:\Program Files\Ang\ping.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Simp] C:\PROGRA~1\Secway\SimpPro\SimpPro.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [RemoveIT Pro v4Ent] C:\Program Files\InCode Solutions\RemoveIT Pro v4\removeit.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Proventia Desktop Agent.lnk = %ProgramFiles%\ISS\Proventia Desktop\blackice.exe
O4 - Global Startup: whitelist.lnk = C:\Program Files\Microsoft Office\whitelist.vbs
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=https://portal.accenture.com/
O15 - Trusted Zone: *.accenture.com
O15 - Trusted Zone: http://*.wedisk.co.kr
O15 - Trusted Zone: http://*.wedisk.net
O16 - DPF: {1ABB898B-8A1A-40CB-8DE7-DAF5E560E814} (DSubActX Control) - http://cab1.diskster.com/recab/DSubActX.cab
O16 - DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online for Web Applications) - https://partner1.thehartford.com/llclient/J…java+AXXPEE.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {61CE1CA1-6577-49B6-AE2C-43007A942429} (WebcastLogOut.Webcast) - https://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184998614682
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184998589246
O16 - DPF: {84197FFA-D750-4B68-B80C-C3ECF1F1EEBF} (clsProxy Class) - https://mylearning.accenture.com/codebase/SDHHPXY.cab
O16 - DPF: {8463A31A-7FB5-4D38-B269-57F4FEFDBB09} (SDData.clsData) - https://mylearning.accenture.com/codebase/SDData.cab
O16 - DPF: {B8FBFE7F-529C-48F5-96F6-093180417DA4} - http://down.iedoumi.com/launchIEdoumi.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {BF17C411-9ADA-4C73-B12C-BD814BDE187F} (ScheduleServices.CtlScheduleServices) - https://mylearning.accenture.com/accenture/…uleServices.cab
O16 - DPF: {D3B8B8A0-4FA3-44EB-86C7-5BEA866CEA57} (SDAICC.clsAICC) - https://mylearning.accenture.com/codebase/SDAICC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://partner1.thehartford.com/dana-cache…perSetupSP1.cab
O16 - DPF: {FE507B78-691A-4DAA-BE3D-793C86592506} (SDWAPI.clsWAPI) - https://mylearning.accenture.com/codebase/SDWAPI.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = accenture.com
O17 - HKLM\Software\..\Telephony: DomainName = accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{398406B5-D952-4376-9291-34DE1AB590FE}: Domain = accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{425233A1-0A72-46E4-939D-4CD3BC50653E}: NameServer = 68.28.114.11 68.28.122.11
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = accenture.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = accenture.com,dir.svc.accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = accenture.com,dir.svc.accenture.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\blackd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: MC/Empower i.collect Service (iCollectService) - Unknown owner - C:\WINDOWS\system32\acstp\icserv.exe
O23 - Service: IgniteService - Unknown owner - C:\Program Files\Accenture Connection\9341989\Program\IgniteService.exe" -Service (file missing)
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Neoteris Setup Service - Juniper Networks - C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
O23 - Service: Pointsec - Unknown owner - C:\WINDOWS\system32\Prot_srv.exe
O23 - Service: Pointsec Service Start (Pointsec_start) - Unknown owner - C:\WINDOWS\system32\pstartSr.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\RapApp.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SPCSUtilityService - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ISS Buffer Overflow Exploit Prevention (VPatch) - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\vpatch.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe


Could anyone please help me combat this deadly infection? It is currently Sunday July 29th 2007. ANy help would be GREATLY appreciated. thank you very much for your help in advanced!
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
here you go: SmitFraudFix v2.207 Scan done at 13:08:13.20, 07/29/2007 Sun Run from D:\Documents and Settings\jungsoo.kim\Desktop\smit\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ISS\Proventia Desktop\blackd.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\iPass\iPassConnect\iPCAgent.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe C:\WINDOWS\system32\Prot_srv.exe C:\WINDOWS\system32\pstartSr.exe C:\Program Files\ISS\Proventia Desktop\RapApp.exe C:\Program Files\RSA Security\Web PassPort\Plug-In\system\sdtray.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\RSA Security\Web PassPort\Plug-In\System\sdlss.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\conime.exe C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe C:\WINDOWS\CTHELPER.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\Creative\Sound Blaster Audigy 2\Surround Mixer\CTSysVol.exe C:\Program Files\Creative\Sound Blaster Audigy 2\SB Performance Utility\CTPowUti.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ISS\Proventia Desktop\vpatch.exe C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe C:\PROGRA~1\Secway\SimpPro\SimpPro.exe C:\Program Files\ISS\Proventia Desktop\blackice.exe C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSCM.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\acstp\icserv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\InCode Solutions\RemoveIT Pro v4\removeit.exe C:\Program Files\InCode Solutions\RemoveIT Pro v4\HLP.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\mIRC\mirc.exe C:\WINDOWS\system32\cmd.exe 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 hosts 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 D:\ 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 C:\WINDOWS C:\WINDOWS\Tasks\At?.job FOUND ! C:\WINDOWS\Tasks\At??.job FOUND ! 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 C:\WINDOWS\system 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 C:\WINDOWS\Web 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 C:\WINDOWS\system32 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 C:\WINDOWS\system32\LogFiles 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 D:\Documents and Settings\jungsoo.kim 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 D:\Documents and Settings\jungsoo.kim\Application Data 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Start Menu 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 D:\DOCUME~1\jungsoo.kim\FAVORI~1 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Desktop 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 C:\Program Files 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Corrupted keys 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Rustock 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 DNS Description: WAN (PPP/SLIP) Interface DNS Server Search Order: 68.28.114.11 DNS Server Search Order: 68.28.122.11 HKLM\SYSTEM\CCS\Services\Tcpip\..\{425233A1-0A72-46E4-939D-4CD3BC50653E}: NameServer=68.28.114.11 68.28.122.11 HKLM\SYSTEM\CS1\Services\Tcpip\..\{425233A1-0A72-46E4-939D-4CD3BC50653E}: NameServer=68.28.114.11 68.28.122.11 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Scanning for wininet.dll infection 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 End
You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.
SmitFraudFix v2.207 Scan done at 13:15:14.86, 07/29/2007 Sun Run from D:\Documents and Settings\jungsoo.kim\Desktop\smit\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Killing process 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 hosts 127.0.0.1 localhost 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Generic Renos Fix GenericRenosFix by S!Ri 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Deleting infected files C:\WINDOWS\Tasks\At?.job Deleted 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{425233A1-0A72-46E4-939D-4CD3BC50653E}: NameServer=68.28.114.11 68.28.122.11 HKLM\SYSTEM\CS1\Services\Tcpip\..\{425233A1-0A72-46E4-939D-4CD3BC50653E}: NameServer=68.28.114.11 68.28.122.11 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Deleting Temp Files 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 Registry Cleaning Registry Cleaning done. 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll 뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣뻣 End
Logfile of HijackThis v1.99.1
Scan saved at 1:27:28 PM, on 7/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\acstp\icserv.exe
C:\WINDOWS\system32\acstp\wake_up.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\iPass\iPassConnect\iPCAgent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
C:\WINDOWS\system32\Prot_srv.exe
C:\WINDOWS\system32\pstartSr.exe
C:\Program Files\ISS\Proventia Desktop\RapApp.exe
C:\Program Files\RSA Security\Web PassPort\Plug-In\system\sdtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
C:\Program Files\RSA Security\Web PassPort\Plug-In\System\sdlss.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ISS\Proventia Desktop\vpatch.exe
C:\Program Files\Creative\Sound Blaster Audigy 2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\Sound Blaster Audigy 2\SB Performance Utility\CTPowUti.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\PROGRA~1\Secway\SimpPro\SimpPro.exe
C:\Program Files\InCode Solutions\RemoveIT Pro v4\removeit.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\ISS\Proventia Desktop\blackice.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\InCode Solutions\RemoveIT Pro v4\HLP.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSCM.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\mIRC\mirc.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DMCC4 Class - {46D7627B-2D58-40F0-8AE9-C4D59A2F1C92} - C:\WINDOWS\system32\mdmcc4.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll (file missing)
O2 - BHO: noep Class - {FF71FF86-04AC-4cb2-A35A-1262BF791A01} - C:\WINDOWS\system32\psjm.dll
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\RSA Security\Web PassPort\Plug-In\system\sdtray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Accenture Connection] "C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe"
O4 - HKLM\..\Run: [Pointsec Tray] "C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\Sound Blaster Audigy 2\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTPerformanceUtility] "C:\Program Files\Creative\Sound Blaster Audigy 2\SB Performance Utility\CTPowUti.exe"
O4 - HKLM\..\Run: [SearchPiaUpdate] C:\program Files\SearchPia\Update.exe
O4 - HKLM\..\Run: [WMSRC] C:\Program Files\Windows Media Player\siratic.exe
O4 - HKLM\..\Run: [pang] C:\Program Files\Ang\ping.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Simp] C:\PROGRA~1\Secway\SimpPro\SimpPro.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [RemoveIT Pro v4Ent] C:\Program Files\InCode Solutions\RemoveIT Pro v4\removeit.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Proventia Desktop Agent.lnk = %ProgramFiles%\ISS\Proventia Desktop\blackice.exe
O4 - Global Startup: whitelist.lnk = C:\Program Files\Microsoft Office\whitelist.vbs
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=https://portal.accenture.com/
O15 - Trusted Zone: *.accenture.com
O15 - Trusted Zone: http://*.wedisk.co.kr
O15 - Trusted Zone: http://*.wedisk.net
O16 - DPF: {1ABB898B-8A1A-40CB-8DE7-DAF5E560E814} (DSubActX Control) - http://cab1.diskster.com/recab/DSubActX.cab
O16 - DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online for Web Applications) - https://partner1.thehartford.com/llclient/J…java+AXXPEE.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {61CE1CA1-6577-49B6-AE2C-43007A942429} (WebcastLogOut.Webcast) - https://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184998614682
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184998589246
O16 - DPF: {84197FFA-D750-4B68-B80C-C3ECF1F1EEBF} (clsProxy Class) - https://mylearning.accenture.com/codebase/SDHHPXY.cab
O16 - DPF: {8463A31A-7FB5-4D38-B269-57F4FEFDBB09} (SDData.clsData) - https://mylearning.accenture.com/codebase/SDData.cab
O16 - DPF: {B8FBFE7F-529C-48F5-96F6-093180417DA4} - http://down.iedoumi.com/launchIEdoumi.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {BF17C411-9ADA-4C73-B12C-BD814BDE187F} (ScheduleServices.CtlScheduleServices) - https://mylearning.accenture.com/accenture/…uleServices.cab
O16 - DPF: {D3B8B8A0-4FA3-44EB-86C7-5BEA866CEA57} (SDAICC.clsAICC) - https://mylearning.accenture.com/codebase/SDAICC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://partner1.thehartford.com/dana-cache…perSetupSP1.cab
O16 - DPF: {FE507B78-691A-4DAA-BE3D-793C86592506} (SDWAPI.clsWAPI) - https://mylearning.accenture.com/codebase/SDWAPI.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = accenture.com
O17 - HKLM\Software\..\Telephony: DomainName = accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{398406B5-D952-4376-9291-34DE1AB590FE}: Domain = accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{425233A1-0A72-46E4-939D-4CD3BC50653E}: NameServer = 68.28.114.11 68.28.122.11
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = accenture.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = accenture.com,dir.svc.accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = accenture.com,dir.svc.accenture.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\blackd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: MC/Empower i.collect Service (iCollectService) - Unknown owner - C:\WINDOWS\system32\acstp\icserv.exe
O23 - Service: IgniteService - Unknown owner - C:\Program Files\Accenture Connection\9341989\Program\IgniteService.exe" -Service (file missing)
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Neoteris Setup Service - Juniper Networks - C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
O23 - Service: Pointsec - Unknown owner - C:\WINDOWS\system32\Prot_srv.exe
O23 - Service: Pointsec Service Start (Pointsec_start) - Unknown owner - C:\WINDOWS\system32\pstartSr.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\RapApp.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SPCSUtilityService - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ISS Buffer Overflow Exploit Prevention (VPatch) - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\vpatch.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Open Hijackthis and click scan. Then check mark the following entries

O2 - BHO: DMCC4 Class - {46D7627B-2D58-40F0-8AE9-C4D59A2F1C92} - C:\WINDOWS\system32\mdmcc4.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll (file missing)
O2 - BHO: noep Class - {FF71FF86-04AC-4cb2-A35A-1262BF791A01} - C:\WINDOWS\system32\psjm.dll
O4 - HKLM\..\Run: [WMSRC] C:\Program Files\Windows Media Player\siratic.exe

Now close all open windows except Hijackthis and click fix checked

Then Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Combo Fix Log

"jungsoo.kim" - 2007-07-29 13:48:20 [GMT -4:00] - ComboFix 07-07-24 - Service Pack 2 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\grouppolicy\machine\scripts\scripts.ini


((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-29 )))))))))))))))))))))))))))))))


2007-07-29 13:15 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-07-29 13:15 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-07-29 13:15 4,348 –a—— C:\WINDOWS\system32\tmp.reg
2007-07-29 13:15 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-07-28 20:09 d——– C:\Program Files\InCode Solutions
2007-07-28 19:48 77,312 –a—— C:\WINDOWS\ua2.dll
2007-07-28 19:32 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-07-28 19:24 d——– C:\WINDOWS\network diagnostic
2007-07-28 18:58 d——– D:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-28 18:16 77,312 –a—— C:\WINDOWS\system32\ztvunace26.dll
2007-07-28 18:16 69,632 –a—— C:\WINDOWS\system32\ztvcabinet.dll
2007-07-28 18:16 162,304 –a—— C:\WINDOWS\system32\ztvunrar36.dll
2007-07-28 18:16 153,088 –a—— C:\WINDOWS\system32\UNRAR3.dll
2007-07-28 18:16 d-a—— D:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-28 16:41 d——– D:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-28 16:10 d——– C:\WINDOWS\system32\4875
2007-07-28 16:05 d——– C:\WINDOWS\system32\1033
2007-07-21 02:41 d——– C:\Program Files\MSN Messenger
2007-07-21 02:25 d——– C:\WINDOWS\pss
2007-07-20 22:52 d——– C:\Program Files\Absolute Poker
2007-07-19 15:00 d——– D:\DOCUME~1\jungsoo.kim\APPLIC~1\ACD Systems
2007-07-19 14:59 10,368 –a—— C:\WINDOWS\system32\drivers\pfc.sys
2007-07-19 14:59 d——– C:\Program Files\Common Files\ACD Systems
2007-07-16 01:16 d——– D:\DOCUME~1\jungsoo.kim\APPLIC~1\Help
2007-07-15 13:08 d——– C:\Program Files\RadioStar
2007-07-14 21:58 59,264 –a—— C:\WINDOWS\system32\drivers\USBAUDIO.sys
2007-07-14 21:45 368,640 –a—— C:\WINDOWS\system32\ReWire.dll
2007-07-14 21:45 d——– D:\DOCUME~1\jungsoo.kim\APPLIC~1\Ableton
2007-07-14 21:43 1,777,664 –a—— C:\WINDOWS\system32\gdiplus.dll
2007-07-09 17:28 4,608 –a—— C:\WINDOWS\system32\W95Inf32.DLL
2007-07-09 17:28 2,272 –a—— C:\WINDOWS\system32\W95Inf16.DLL
2007-07-09 16:09 24 –a—— C:\WINDOWS\vd.dat
2007-07-09 16:09 217,206 –a—— C:\WINDOWS\system32\psjm.dll
2007-07-09 16:08 491,520 –a—— C:\WINDOWS\Zins.exe
2007-07-07 14:53 83,688 –a—— C:\WINDOWS\system32\WeDisk.dll
2007-07-07 14:53 65,536 –a—— C:\WINDOWS\system32\WeDiskFileData.exe
2007-07-07 14:53 602,112 –a—— C:\WINDOWS\system32\WeDiskUpLoad.exe
2007-07-07 14:53 59,112 –a—— C:\WINDOWS\system32\WeDiskFilog.dll
2007-07-07 14:53 2,008,808 –a—— C:\WINDOWS\system32\WeDiskDownLoad.exe
2007-07-03 15:37 311,296 –a—— C:\WINDOWS\system32\uninstallds.exe
2007-07-03 15:35 299,008 –a—— C:\WINDOWS\system32\uninstallsp.exe
2007-07-03 15:35 28,672 –a—— C:\WINDOWS\system32\SPSub.dll
2007-07-03 15:35 151,552 –a—— C:\WINDOWS\system32\UnInstall.exe
2007-07-03 15:35 d——– C:\Program Files\SearchPia
2007-07-03 15:34 d——– C:\Program Files\IEDoumi
2007-07-02 00:07 d——– D:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-07-02 00:07 d——– D:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-07-02 00:06 d——– C:\Program Files\Common Files\AOL
2007-07-02 00:01 d——– C:\Program Files\AIM6
2007-07-01 23:49 d——– D:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-06-30 12:48 d–h—– C:\WINDOWS\PIF
2007-06-29 17:44 57,344 –a—— C:\WINDOWS\Unwash6.exe
2007-06-29 17:07 849,408 –a—— C:\WINDOWS\system32\DivX.dll
2007-06-29 17:07 1,335,296 –a—— C:\WINDOWS\system32\PSIKey.dll
2007-06-29 17:07 d——– C:\Program Files\RM-X Player V4.2


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-29 17:41:25 ——– d—–w C:\Program Files\mIRC
2007-07-29 17:20:50 ——– d—–w C:\Program Files\Symantec AntiVirus
2007-07-29 14:07:13 ——– d—–w C:\Program Files\FlashFXP
2007-07-29 14:04:48 ——– d—–w D:\DOCUME~1\jungsoo.kim\APPLIC~1\uTorrent
2007-07-29 05:42:08 ——– d—–w C:\Program Files\Soulseek
2007-07-29 04:28:24 ——– d—–w C:\Program Files\Winamp
2007-07-26 04:20:05 ——– d—–w D:\DOCUME~1\jungsoo.kim\APPLIC~1\Juniper Networks
2007-07-21 07:34:45 ——– d—–w C:\Program Files\Full Tilt Poker
2007-07-21 06:51:17 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-07-14 19:49:06 30,892 —ha-w C:\WINDOWS\system32\mlfcache.dat
2007-07-14 19:44:00 ——– d—–w D:\DOCUME~1\jungsoo.kim\APPLIC~1\Apple Computer
2007-07-13 23:18:40 ——– d—–w C:\Program Files\Nortel Networks
2007-07-04 02:57:05 ——– d—–w D:\DOCUME~1\jungsoo.kim\APPLIC~1\Viewpoint
2007-07-02 04:27:59 ——– d—–w C:\Program Files\AIM
2007-07-02 04:06:44 ——– d—–w C:\Program Files\Viewpoint
2007-07-02 04:01:00 335 —-a-w C:\WINDOWS\nsreg.dat
2007-06-27 19:57:10 23,040 —-a-w C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-06-27 19:57:04 ——– d—–w D:\DOCUME~1\jungsoo.kim\APPLIC~1\WholeSecurity
2007-06-24 20:50:20 ——– d—–w D:\DOCUME~1\jungsoo.kim\APPLIC~1\SimpLogs
2007-06-24 20:50:03 ——– d—–w C:\Program Files\Secway
2007-06-24 17:34:19 ——– d—–w D:\DOCUME~1\jungsoo.kim\APPLIC~1\Smart Recorder
2007-06-21 14:49:52 ——– d—–w C:\Program Files\Sierra Wireless
2007-06-21 01:03:12 ——– d—–w C:\Program Files\Sprint
2007-06-15 03:41:34 ——– d—–w D:\DOCUME~1\jungsoo.kim\APPLIC~1\Smith Micro
2007-06-15 03:40:15 ——– d—–w C:\Program Files\Novatel Wireless
2007-06-15 03:39:56 ——– d—–w C:\Program Files\Verizon Wireless
2007-06-11 20:55:21 ——– d—–w C:\Program Files\SkillSoft
2007-06-11 03:23:44 ——– d—–w C:\Program Files\eMule
2007-06-03 21:56:39 ——– d—–w C:\Program Files\Firm Applications
2007-06-03 21:56:39 ——– d—–w C:\Program Files\Common Files\Accenture
2007-06-03 15:55:41 ——– d—–w C:\Program Files\Messenger
2007-06-02 18:46:49 ——– d—–w C:\Program Files\QuickTime
2007-06-02 18:42:48 ——– d—–w C:\Program Files\Apple Software Update
2007-06-02 18:07:54 ——– d—–w D:\DOCUME~1\jungsoo.kim\APPLIC~1\Aim
2007-06-02 17:35:57 ——– d—–w C:\Program Files\Creative
2007-06-02 17:35:12 225,280 —-a-w C:\WINDOWS\system32\wrap_oal.dll
2007-06-02 17:34:06 ——– d—–w D:\DOCUME~1\jungsoo.kim\APPLIC~1\Creative
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-08 19:14:16 154 —-a-w C:\WINDOWS\proxy.vbs
2007-05-08 19:01:02 120,988 —-a-w C:\WINDOWS\proxysetting.exe
2006-12-14 21:47:22 45,056 —-a-w C:\Program Files\Common Files\Period20.dll
2006-12-14 21:47:20 24,576 —-a-w C:\Program Files\Common Files\Artes32X.dll
2006-12-14 21:47:20 24,576 —-a-w C:\Program Files\Common Files\ACTripsLog.dll
2006-09-12 20:21:18 319 —-a-w C:\Program Files\VersionMarker.dat


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SDTray"="C:\Program Files\RSA Security\Web PassPort\Plug-In\system\sdtray.exe" [2006-03-08 14:28]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-12-21 12:33]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-05-27 16:06]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 12:33]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 12:26]
"Accenture Connection"="C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe" [2007-04-20 13:38]
"Pointsec Tray"="C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe" [2007-02-06 12:48]
"CTHelper"="CTHELPER.EXE" [2004-10-06 04:49 C:\WINDOWS\CTHELPER.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Audigy 2\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43]
"CTPerformanceUtility"="C:\Program Files\Creative\Sound Blaster Audigy 2\SB Performance Utility\CTPowUti.exe" [2004-09-30 11:58]
"SearchPiaUpdate"="C:\program Files\SearchPia\Update.exe" []
"pang"="C:\Program Files\Ang\ping.exe" []
"AIMPro"="C:\Program Files\AIM\AIM Pro\aimpro.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 11:00]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 14:32]
"SetDefaultMIDI"="MIDIDef.exe" [2004-10-06 04:23 C:\WINDOWS\MIDIDEF.EXE]
"Simp"="C:\PROGRA~1\Secway\SimpPro\SimpPro.exe" [2007-05-23 15:04]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17]
"RemoveIT Pro v4Ent"="C:\Program Files\InCode Solutions\RemoveIT Pro v4\removeit.exe" [2007-07-29 09:58]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]

D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"LogonType"=0 (0x0)
"disablecad"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\]
"Script"=sernum.wsf

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\1]
"Script"=admincln.exe

R0 prot_2k;prot_2k;C:\WINDOWS\system32\drivers\prot_2k.sys
R1 APPDRV;APPDRV;C:\WINDOWS\system32\DRIVERS\APPDRV.SYS
R1 FsVga;FsVga;C:\WINDOWS\system32\DRIVERS\fsvga.sys
R2 BlackICE;BlackICE;"C:\Program Files\ISS\Proventia Desktop\blackd.exe"
R2 CryptSvc;Cryptographic Services;C:\WINDOWS\system32\svchost.exe -k netsvcs
R2 IISADMIN;IIS Admin;C:\WINDOWS\system32\inetsrv\inetinfo.exe
R2 iPassP;iPass Protocol (IEEE 802.1x) v3.4.9.0;C:\WINDOWS\system32\DRIVERS\iPassP.sys
R2 iPCAgent;iPCAgent;C:\Program Files\iPass\iPassConnect\iPCAgent.exe
R2 Neoteris Setup Service;Neoteris Setup Service;"C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe"
R2 Pointsec;Pointsec;C:\WINDOWS\system32\Prot_srv.exe
R2 Pointsec_start;Pointsec Service Start;C:\WINDOWS\system32\pstartSr.exe
R2 RapApp;RapApp;C:\Program Files\ISS\Proventia Desktop\RapApp.exe
R2 VPatch;ISS Buffer Overflow Exploit Prevention;C:\Program Files\ISS\Proventia Desktop\vpatch.exe
R2 W3SVC;World Wide Web Publishing;C:\WINDOWS\system32\inetsrv\inetinfo.exe
R3 ctmmfilt;Audio Filter Driver;C:\WINDOWS\system32\drivers\ctmmfilt.sys
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys
R3 hap17v2k;Creative P17V HAL Driver;C:\WINDOWS\system32\drivers\hap17v2k.sys
R3 HSFHWICH;HSFHWICH;C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
R3 MakoNT;MakoNT;C:\WINDOWS\system32\drivers\MakoNT.sys
R3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys
R3 pfc;Padus ASPI Shell;C:\WINDOWS\system32\drivers\pfc.sys
R3 PptpMiniport;WAN Miniport (PPTP);C:\WINDOWS\system32\DRIVERS\raspptp.sys
R3 rap;rap;C:\WINDOWS\system32\drivers\RapDrv.sys
R3 RasPppoe;Remote Access PPPOE Driver;C:\WINDOWS\system32\DRIVERS\raspppoe.sys
R3 Raspti;Direct Parallel;C:\WINDOWS\system32\DRIVERS\raspti.sys
R3 SWMX00;Sierra Wireless USB MUX Driver (#00);C:\WINDOWS\system32\DRIVERS\swmx00.sys
R4 black;black;C:\WINDOWS\system32\drivers\BlackCat.sys
S0 iaStor;Intel AHCI Controller;C:\WINDOWS\system32\drivers\iaStor.sys
S1 WmiAcpi;Microsoft Windows Management Interface for ACPI;C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S3 aspnet_state;ASP.NET State Service;C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
S3 Bridge;MAC Bridge;C:\WINDOWS\system32\DRIVERS\bridge.sys
S3 BridgeMP;MAC Bridge Miniport;C:\WINDOWS\system32\DRIVERS\bridge.sys
S3 CO_Mon;CO_Mon;\??\C:\WINDOWS\system32\Drivers\CO_Mon.sys
S3 CTMSFSYN;Creative SoundFont Synth;C:\WINDOWS\system32\drivers\ctmsfsyn.sys
S3 IgniteService;IgniteService;"C:\Program Files\Accenture Connection\9341989\Program\IgniteService.exe" -Service
S3 NWUSBModem;Novatel Wireless USB Modem Driver;C:\WINDOWS\system32\DRIVERS\nwusbmdm.sys
S3 NWUSBPort;Novatel Wireless USB Status Port Driver;C:\WINDOWS\system32\DRIVERS\nwusbser.sys
S3 sdbus;sdbus;C:\WINDOWS\system32\DRIVERS\sdbus.sys
S3 SWNC5E00;Sierra Wireless MUX NDIS Driver (#00);C:\WINDOWS\system32\DRIVERS\SWNC5E00.sys
S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys


HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ProxySetting
c:\windows\proxysetting.exe

HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}
rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmactedp.inf,PerUserStub

Contents of the 'Scheduled Tasks' folder
2007-07-25 23:39:01 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-29 13:50:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000000ac
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\DTS+AC3 \xd544\xd130]
"Order"=hex:08,00,00,00,02,00,00,00,1a,01,00,00,01,00,00,00,02,00,00,00,82,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\xd0aborrent]
"Order"=hex:08,00,00,00,02,00,00,00,12,01,00,00,01,00,00,00,02,00,00,00,7a,..

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-29 13:51:43
C:\ComboFix-quarantined-files.txt … 2007-07-29 13:51

— E O F —
Hijack This Log

Logfile of HijackThis v1.99.1
Scan saved at 1:52:35 PM, on 7/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\acstp\icserv.exe
C:\WINDOWS\system32\acstp\wake_up.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\iPass\iPassConnect\iPCAgent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
C:\WINDOWS\system32\Prot_srv.exe
C:\WINDOWS\system32\pstartSr.exe
C:\Program Files\ISS\Proventia Desktop\RapApp.exe
C:\Program Files\RSA Security\Web PassPort\Plug-In\system\sdtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
C:\Program Files\RSA Security\Web PassPort\Plug-In\System\sdlss.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ISS\Proventia Desktop\vpatch.exe
C:\Program Files\Creative\Sound Blaster Audigy 2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\Sound Blaster Audigy 2\SB Performance Utility\CTPowUti.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\PROGRA~1\Secway\SimpPro\SimpPro.exe
C:\Program Files\InCode Solutions\RemoveIT Pro v4\removeit.exe
C:\Program Files\ISS\Proventia Desktop\blackice.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\InCode Solutions\RemoveIT Pro v4\HLP.exe
C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSCM.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\RSA Security\Web PassPort\Plug-In\system\sdtray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Accenture Connection] "C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe"
O4 - HKLM\..\Run: [Pointsec Tray] "C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\Sound Blaster Audigy 2\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTPerformanceUtility] "C:\Program Files\Creative\Sound Blaster Audigy 2\SB Performance Utility\CTPowUti.exe"
O4 - HKLM\..\Run: [SearchPiaUpdate] C:\program Files\SearchPia\Update.exe
O4 - HKLM\..\Run: [pang] C:\Program Files\Ang\ping.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Simp] C:\PROGRA~1\Secway\SimpPro\SimpPro.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [RemoveIT Pro v4Ent] C:\Program Files\InCode Solutions\RemoveIT Pro v4\removeit.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Proventia Desktop Agent.lnk = %ProgramFiles%\ISS\Proventia Desktop\blackice.exe
O4 - Global Startup: whitelist.lnk = C:\Program Files\Microsoft Office\whitelist.vbs
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=https://portal.accenture.com/
O15 - Trusted Zone: *.accenture.com
O15 - Trusted Zone: http://*.wedisk.co.kr
O15 - Trusted Zone: http://*.wedisk.net
O16 - DPF: {1ABB898B-8A1A-40CB-8DE7-DAF5E560E814} (DSubActX Control) - http://cab1.diskster.com/recab/DSubActX.cab
O16 - DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online for Web Applications) - https://partner1.thehartford.com/llclient/J…java+AXXPEE.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {61CE1CA1-6577-49B6-AE2C-43007A942429} (WebcastLogOut.Webcast) - https://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184998614682
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184998589246
O16 - DPF: {84197FFA-D750-4B68-B80C-C3ECF1F1EEBF} (clsProxy Class) - https://mylearning.accenture.com/codebase/SDHHPXY.cab
O16 - DPF: {8463A31A-7FB5-4D38-B269-57F4FEFDBB09} (SDData.clsData) - https://mylearning.accenture.com/codebase/SDData.cab
O16 - DPF: {B8FBFE7F-529C-48F5-96F6-093180417DA4} - http://down.iedoumi.com/launchIEdoumi.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {BF17C411-9ADA-4C73-B12C-BD814BDE187F} (ScheduleServices.CtlScheduleServices) - https://mylearning.accenture.com/accenture/…uleServices.cab
O16 - DPF: {D3B8B8A0-4FA3-44EB-86C7-5BEA866CEA57} (SDAICC.clsAICC) - https://mylearning.accenture.com/codebase/SDAICC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://partner1.thehartford.com/dana-cache…perSetupSP1.cab
O16 - DPF: {FE507B78-691A-4DAA-BE3D-793C86592506} (SDWAPI.clsWAPI) - https://mylearning.accenture.com/codebase/SDWAPI.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = accenture.com
O17 - HKLM\Software\..\Telephony: DomainName = accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{398406B5-D952-4376-9291-34DE1AB590FE}: Domain = accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{425233A1-0A72-46E4-939D-4CD3BC50653E}: NameServer = 68.28.114.11 68.28.122.11
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = accenture.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = accenture.com,dir.svc.accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = accenture.com,dir.svc.accenture.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\blackd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: MC/Empower i.collect Service (iCollectService) - Unknown owner - C:\WINDOWS\system32\acstp\icserv.exe
O23 - Service: IgniteService - Unknown owner - C:\Program Files\Accenture Connection\9341989\Program\IgniteService.exe" -Service (file missing)
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Neoteris Setup Service - Juniper Networks - C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
O23 - Service: Pointsec - Unknown owner - C:\WINDOWS\system32\Prot_srv.exe
O23 - Service: Pointsec Service Start (Pointsec_start) - Unknown owner - C:\WINDOWS\system32\pstartSr.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\RapApp.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SPCSUtilityService - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ISS Buffer Overflow Exploit Prevention (VPatch) - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\vpatch.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Delete the files. (if present)

C:\WINDOWS\system32\psjm.dll

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
Panda Active Scan Results Incident Status Location Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\ComboFix\nircmd.cfexe Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\ComboFix\nircmd.exe Possible Virus. Not disinfected C:\Program Files\IEDoumi\tmp\a.tmp Possible Virus. Not disinfected C:\Program Files\IEDoumi\uninstall.exe Potentially unwanted tool:Application/Pskill.B Not disinfected C:\WINDOWS\Source\ax\AXinstall.exe[AXUNINSTALL.EXE][PSKILL.EXE] Potentially unwanted tool:Application/Pskill.B Not disinfected C:\WINDOWS\Source\proventia\ProventiaDesktop.EXE[PSKILL.EXE] Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe Spyware:Cookie/Advertising Not disinfected D:\Documents and Settings\jungsoo.kim\Cookies\jungsoo.kim@advertising[2].txt Spyware:Cookie/Advertising Not disinfected D:\Documents and Settings\jungsoo.kim\Cookies\jungsoo.kim@advertising[3].txt Spyware:Cookie/Atwola Not disinfected D:\Documents and Settings\jungsoo.kim\Cookies\jungsoo.kim@atwola[1].txt Spyware:Cookie/Atwola Not disinfected D:\Documents and Settings\jungsoo.kim\Cookies\jungsoo.kim@atwola[2].txt Spyware:Cookie/Doubleclick Not disinfected D:\Documents and Settings\jungsoo.kim\Cookies\jungsoo.kim@doubleclick[1].txt Spyware:Cookie/Doubleclick Not disinfected D:\Documents and Settings\jungsoo.kim\Cookies\jungsoo.kim@doubleclick[2].txt Spyware:Cookie/Mediaplex Not disinfected D:\Documents and Settings\jungsoo.kim\Cookies\jungsoo.kim@mediaplex[1].txt Spyware:Cookie/WebtrendsLive Not disinfected D:\Documents and Settings\jungsoo.kim\Cookies\[removed][2].txt Potentially unwanted tool:Application/NirCmd.A Not disinfected D:\Documents and Settings\jungsoo.kim\Desktop\ComboFix.exe[nircmd.exe] Potentially unwanted tool:Application/Processor Not disinfected D:\Documents and Settings\jungsoo.kim\Desktop\smit\SmitfraudFix\Process.exe Potentially unwanted tool:Application/SuperFast Not disinfected D:\Documents and Settings\jungsoo.kim\Desktop\smit\SmitfraudFix\restart.exe Potentially unwanted tool:Application/Processor Not disinfected D:\Documents and Settings\jungsoo.kim\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe] Potentially unwanted tool:Application/SuperFast Not disinfected D:\Documents and Settings\jungsoo.kim\Desktop\SmitfraudFix.zip[SmitfraudFix/restart.exe] Potentially unwanted tool:Application/Processor Not disinfected D:\Documents and Settings\jungsoo.kim\My Documents\SmitfraudFix\Process.exe Potentially unwanted tool:Application/SuperFast Not disinfected D:\Documents and Settings\jungsoo.kim\My Documents\SmitfraudFix\restart.exe Potentially unwanted tool:Application/Pskill.B Not disinfected E:\gwpl\lastapps.exe[AXINSTALL.EXE][AXUNINSTALL.EXE][PSKILL.EXE] Potentially unwanted tool:Application/Pskill.B Not disinfected E:\gwpl\UserLoad62.exe[PROVENTIADESKTOP.EXE][PSKILL.EXE] Potentially unwanted tool:Application/Pskill.B Not disinfected E:\gwpl\UserLoad62.exe[LASTAPPS.EXE][AXINSTALL.EXE][AXUNINSTALL.EXE][PSKILL.EXE]
Logfile of HijackThis v1.99.1
Scan saved at 12:01:29 PM, on 7/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\acstp\icserv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\acstp\wake_up.exe
C:\Program Files\iPass\iPassConnect\iPCAgent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
C:\WINDOWS\system32\Prot_srv.exe
C:\WINDOWS\system32\pstartSr.exe
C:\Program Files\ISS\Proventia Desktop\RapApp.exe
C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\ISS\Proventia Desktop\vpatch.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\RSA Security\Web PassPort\Plug-In\system\sdtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe
C:\Program Files\RSA Security\Web PassPort\Plug-In\System\sdlss.exe
C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Creative\Sound Blaster Audigy 2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\Sound Blaster Audigy 2\SB Performance Utility\CTPowUti.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\PROGRA~1\Secway\SimpPro\SimpPro.exe
C:\Program Files\InCode Solutions\RemoveIT Pro v4\removeit.exe
C:\Program Files\ISS\Proventia Desktop\blackice.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSCM.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\InCode Solutions\RemoveIT Pro v4\HLP.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\RSA Security\Web PassPort\Plug-In\system\sdtray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Accenture Connection] "C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe"
O4 - HKLM\..\Run: [Pointsec Tray] "C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\Sound Blaster Audigy 2\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTPerformanceUtility] "C:\Program Files\Creative\Sound Blaster Audigy 2\SB Performance Utility\CTPowUti.exe"
O4 - HKLM\..\Run: [SearchPiaUpdate] C:\program Files\SearchPia\Update.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Simp] C:\PROGRA~1\Secway\SimpPro\SimpPro.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [RemoveIT Pro v4Ent] C:\Program Files\InCode Solutions\RemoveIT Pro v4\removeit.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Proventia Desktop Agent.lnk = %ProgramFiles%\ISS\Proventia Desktop\blackice.exe
O4 - Global Startup: whitelist.lnk = C:\Program Files\Microsoft Office\whitelist.vbs
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=https://portal.accenture.com/
O15 - Trusted Zone: *.accenture.com
O15 - Trusted Zone: http://*.wedisk.co.kr
O15 - Trusted Zone: http://*.wedisk.net
O16 - DPF: {1ABB898B-8A1A-40CB-8DE7-DAF5E560E814} (DSubActX Control) - http://cab1.diskster.com/recab/DSubActX.cab
O16 - DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online for Web Applications) - https://partner1.thehartford.com/llclient/J…java+AXXPEE.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {61CE1CA1-6577-49B6-AE2C-43007A942429} (WebcastLogOut.Webcast) - https://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184998614682
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184998589246
O16 - DPF: {84197FFA-D750-4B68-B80C-C3ECF1F1EEBF} (clsProxy Class) - https://mylearning.accenture.com/codebase/SDHHPXY.cab
O16 - DPF: {8463A31A-7FB5-4D38-B269-57F4FEFDBB09} (SDData.clsData) - https://mylearning.accenture.com/codebase/SDData.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {BF17C411-9ADA-4C73-B12C-BD814BDE187F} (ScheduleServices.CtlScheduleServices) - https://mylearning.accenture.com/accenture/…uleServices.cab
O16 - DPF: {D3B8B8A0-4FA3-44EB-86C7-5BEA866CEA57} (SDAICC.clsAICC) - https://mylearning.accenture.com/codebase/SDAICC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://partner1.thehartford.com/dana-cache…perSetupSP1.cab
O16 - DPF: {FE507B78-691A-4DAA-BE3D-793C86592506} (SDWAPI.clsWAPI) - https://mylearning.accenture.com/codebase/SDWAPI.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = accenture.com
O17 - HKLM\Software\..\Telephony: DomainName = accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{398406B5-D952-4376-9291-34DE1AB590FE}: Domain = accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{425233A1-0A72-46E4-939D-4CD3BC50653E}: NameServer = 68.28.114.11 68.28.122.11
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = accenture.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = accenture.com,dir.svc.accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = accenture.com,dir.svc.accenture.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\blackd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: MC/Empower i.collect Service (iCollectService) - Unknown owner - C:\WINDOWS\system32\acstp\icserv.exe
O23 - Service: IgniteService - Unknown owner - C:\Program Files\Accenture Connection\9341989\Program\IgniteService.exe" -Service (file missing)
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Neoteris Setup Service - Juniper Networks - C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
O23 - Service: Pointsec - Unknown owner - C:\WINDOWS\system32\Prot_srv.exe
O23 - Service: Pointsec Service Start (Pointsec_start) - Unknown owner - C:\WINDOWS\system32\pstartSr.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\RapApp.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SPCSUtilityService - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ISS Buffer Overflow Exploit Prevention (VPatch) - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\vpatch.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
yes i deleted that file. all seems to be working fine and dandy. thanks so much for your help! really appreciate it. you are doing a great thing for the community!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI