This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Relentless Windows Security Alert Popups

70 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello :) Thank you all in advance for your time and effort to assist me. I think I have been infected with a variant of the dreaded Cool Web Search. I am getting relentless notifications from my Taskbar that say "Your computer is infected!" Along with these are continous popups that say "Warning! Potential Spyware Operation! Computer is making unauthorized copies of your system and Internet files. Run full scan now to prevent any unauthorized access to your files! Click here to download spyware remover…" I have run CWShredder and it found and removed a couple of instances of Cool Web Search. I have also ran Ad Aware and Spybot, both of which find some other infected items on every restart. My homepage is currently not taken over and I am not being redirected to other websites. The popups seem to be the major problem right now. Below is my HijackThis Log. Thank you again for helping me out. :D

Logfile of HijackThis v1.99.1
Scan saved at 10:19:49 PM, on 8/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\winavxx.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\printer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\WinAvXX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\WinAvXX.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
C:\Documents and Settings\Christopher Combs\Start Menu\Programs\Startup\system.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe
O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\vtr455.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - Startup: system.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: autorun.exe
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O4 - Global Startup: Ulead Photo Express Calendar Checker For My Custom Edition.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} - http://supportsoft.adelphia.net/sdccommon/…ad/tgctlins.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/0795c98f45fa19…tzip/RdxIE2.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum455.txt
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.


Hi cjdragon,

I'm Gary R, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
If you can do these things, everything should go smoothly.
  • Please note you'll need to have Administrator priviledges to perform the fixes. (XP accounts are Administrator by default)
  • Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.
  • Download combofix.exe by sUBs
  • Alternate Download
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log for you. Post that log in your next reply please. (it can also be found at C:\Combofix.txt)
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Please download SmitfraudFix (by S!Ri) and extract it to your Desktop.

Now run SmitfraudFix.
    • Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    • Select option #1 - Search by typing 1 and press Enter (a text file will appear, which lists infected files if present). (Do not run any other option at this time, it may cause damage).
    • Please copy/paste the content of that report into your next reply.
  • Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Now run a new scan with HijackThis and post me the log please.

Summary of the logs I need from you in your next post:
  • Combofix log
  • Smitfraudfix log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.
Hi, thanks for taking a look at this. Before we go any further I should let you know that there are three accounts on this computer. You said this may affect the instructions so I figured I would go ahead swing this by you before running the software and posting the logs.
OK, thanks for letting me know, it just means I'll have to check the other accounts once I've finished with the one we're on now. The infection you have is a new one and I don't know whether it "migrates" to the other accounts or not. Please run the tools now, and send me the logs I asked for in my last post.
Here are the logs:

ComboFix 07-08-14.4 - "Christopher Combs" 2007-08-17 20:14:13.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.663 [GMT -5:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup.\autorun.exe
C:\DOCUME~1\CHRIST~1\STARTM~1\Programs\Startup.\system.exe
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\printer.exe
C:\WINDOWS\system32\WinAvXX.exe


((((((((((((((((((((((((( Files Created from 2007-07-18 to 2007-08-18 )))))))))))))))))))))))))))))))


2007-08-17 20:11 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-15 04:05 37,376 –a—— C:\WINDOWS\SYSTEM32\vtr455.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-16 23:42 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-08-14 18:49 ——— d——– C:\Program Files\City of Heroes
2007-07-19 01:59 3583488 –a—— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-16 22:51 ——— d——– C:\DOCUME~1\CHRIST~1\APPLIC~1\uTorrent
2007-07-12 18:31 765952 –a—— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-27 09:34 823808 –a—— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 09:34 671232 –a—— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 09:34 6058496 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 09:34 52224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 09:34 477696 –a—— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 09:34 459264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 09:34 44544 ——— C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 09:34 384512 ——— C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 09:34 383488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 09:34 27648 –a—— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 09:34 267776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 09:34 232960 ——— C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 09:34 230400 ——— C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 09:34 193024 –a—— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 09:34 153088 ——— C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 09:34 132608 –a—— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 09:34 124928 ——— C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 09:34 1152000 –a—— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 09:34 105984 ——— C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 09:34 102400 ——— C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 03:27 63488 ——— C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 03:27 625152 ——— C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 03:27 13824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 02:00 161792 ——— C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 01:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-26 01:08 1104896 ——— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 08:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 08:31 282112 ——— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-13 05:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-13 05:23 1033216 ——— C:\WINDOWS\system32\dllcache\explorer.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-05 21:28]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-05-03 18:12]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-14 19:45]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 20:15]
"MMTray"="C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" [2004-04-19 14:45]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-19 14:45]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 20:12]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 23:48]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 23:44]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-07-14 20:16]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2004-08-06 14:33]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"WinAVX"=C:\WINDOWS\system32\WinAvXX.exe

C:\Documents and Settings\Christopher Combs\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2004-08-11 15:15:31]
DESKTOP.INI [2002-09-03 09:00:00]
Program Neighborhood Agent.lnk - C:\Program Files\Citrix\ICA Client\pnagent.exe [2006-11-08 18:33:12]
Ulead Photo Express Calendar Checker For My Custom Edition.lnk - C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe [2004-09-06 15:03:42]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoControlPanel"=1 (0x1)
"NoWindowsUpdate"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\hrum455.txt

S3 GT680x;GrandTechICNameNT;C:\WINDOWS\system32\Drivers\gt680x.sys
S3 PAC207;Webcam Basic;C:\WINDOWS\system32\DRIVERS\pfc027.sys
S3 UsbCmxp;Scientific Atlanta WebSTAR 2000 series Cable Modem;C:\WINDOWS\system32\DRIVERS\sacmxp2.sys


Contents of the 'Scheduled Tasks' folder
2007-08-18 01:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Christopher Combs.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-17 20:19:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-17 20:22:06
C:\ComboFix-quarantined-files.txt … 2007-08-17 20:21

— E O F —
SmitFraudFix v2.212 Scan done at 20:34:34.20, Fri 08/17/2007 Run from C:\Documents and Settings\Christopher Combs\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\PAStiSvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\system32\winavxx.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DellSupport\DSAgnt.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe C:\Program Files\Citrix\ICA Client\pnagent.exe C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe C:\Documents and Settings\Christopher Combs\Start Menu\Programs\Startup\system.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Christopher Combs »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Christopher Combs\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CHRIST~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\WINDOWS\\system32\\hrum455.txt" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport DNS Server Search Order: 24.94.163.100 DNS Server Search Order: 24.94.163.101 Description: Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport DNS Server Search Order: 24.94.163.100 DNS Server Search Order: 24.94.163.101 HKLM\SYSTEM\CCS\Services\Tcpip\..\{FA259881-8103-444A-B37A-C67F9ABDFB73}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\..\{FE3FCC6A-EC2D-4DD2-AA4E-B03D39D89EAE}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{FA259881-8103-444A-B37A-C67F9ABDFB73}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{FE3FCC6A-EC2D-4DD2-AA4E-B03D39D89EAE}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{FA259881-8103-444A-B37A-C67F9ABDFB73}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{FE3FCC6A-EC2D-4DD2-AA4E-B03D39D89EAE}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Logfile of HijackThis v1.99.1
Scan saved at 8:36:31 PM, on 8/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\winavxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
C:\Documents and Settings\Christopher Combs\Start Menu\Programs\Startup\system.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O4 - Global Startup: Ulead Photo Express Calendar Checker For My Custom Edition.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} - http://supportsoft.adelphia.net/sdccommon/…ad/tgctlins.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/0795c98f45fa19…tzip/RdxIE2.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum455.txt
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
OK, looking better, but still some work to do.

Download RegSearch by Bobbi Flekman.
  • Create a folder in your C: drive C:\Regsearch, and extract all the files from the zip archive into that folder.
  • Double click regsearch.exe to launch the programme.
  • Copy/Paste the following into the Search Box hrum455
  • On the next line Copy/Paste winavxx
  • Click OK.
Regsearch will now search your Registry for the required strings, when it is finished it will open a Notepad file RegSearch.txt, saved to the Regsearch folder.

Copy/Paste that file into your next post.

I'd like you to check a file for Viruses.
  • Go to VirusTotal or Jotti's, and scan the following file.

C:\WINDOWS\system32\hrum455.txt

  • Click on the Browse button at the top of the screen.
  • Browse to the file.
  • Click OK.
  • Click Send, and the file will upload to VirusTotal / Jotti, where it will be scanned by several anti-virus programmes.
  • After a while, a window will open, with details of what the scans found.
  • Note details of any viruses found.
  • Post me the details please.
Okay, here is the RegSearch log:

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.5.0

; Results at 8/20/2007 1:17:40 AM for strings:
; 'hrum455'
; 'winavxx'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\WINDOWS\\system32\\hrum455.txt"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\WINDOWS\\system32\\WinAvXX.exe"="AntiVirus 2007 Pro"

; End Of The Log…

And here is the info on hrum455.txt from VirusTotal:

Antivirus Version Last Update Result
AhnLab-V3 2007.8.18.0 2007.08.20 Win-Trojan/Agent.6144.CF
AntiVir 7.4.1.62 2007.08.19 TR/Crypt.XPACK.Gen
Authentium 4.93.8 2007.08.17 -
Avast 4.7.1029.0 2007.08.20 Win32:Agent-JKI
AVG 7.5.0.484 2007.08.19 Generic6.ASQ
BitDefender 7.2 2007.08.20 Trojan.Clicker.DB
CAT-QuickHeal 9.00 2007.08.18 Trojan.Agent.ali
ClamAV 0.91 2007.08.20 Trojan.Small-3425
DrWeb 4.33 2007.08.19 Trojan.Proxy.1939
eSafe 7.0.15.0 2007.08.16 Win32.Agent.ali
eTrust-Vet 31.1.5069 2007.08.18 -
Ewido 4.0 2007.08.19 Trojan.Agent.ali
FileAdvisor 1 2007.08.20 -
Fortinet 2.91.0.0 2007.08.19 W32/Agent.ALI!tr
F-Prot 4.3.2.48 2007.08.17 -
F-Secure 6.70.13030.0 2007.08.19 Trojan.Win32.Agent.ali
Ikarus T3.1.1.12 2007.08.20 Trojan.Win32.Agent.ali
Kaspersky 4.0.2.24 2007.08.20 -
McAfee 5100 2007.08.17 -
Microsoft 1.2803 2007.08.20 Trojan:Win32/Small!2233
NOD32v2 2470 2007.08.19 -
Norman 5.80.02 2007.08.17 W32/Agent.BXRV
Panda 9.0.0.4 2007.08.19 Trj/Downloader.MDW
Prevx1 V2 2007.08.20 Generic.Malware
Rising 19.36.60.00 2007.08.19 -
Sophos 4.20.0 2007.08.12 -
Sunbelt 2.2.907.0 2007.08.18 Trojan.FakeAlert
Symantec 10 2007.08.20 Trojan.Perfcoo
TheHacker 6.1.8.170 2007.08.17 Trojan/Agent.ali
VBA32 3.12.2.2 2007.08.20 Trojan.Win32.Agent.ali
VirusBuster 4.3.26:9 2007.08.19 Trojan.Agent.JQG
Webwasher-Gateway 6.0.1 2007.08.20 Trojan.Crypt.XPACK.Gen
Additional information
File size: 6144 bytes
MD5: 33222c3e3ff11791876a87988030484a
SHA1: 48593b0d0df4a7ec2846c7f0ecb6cc5d14e2c79a
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PX5…B9654007EFDA9C6
Sunbelt info: Trojan.FakeAlert consists of files that cause false warnings of spyware on the computer. Usually the alerts are displayed in a balloon type pop-up from an icon in the system tray.
OK, still some cleaning up to do.

Download OTMoveIt by OldTimer to your Desktop.
  • Double click OTMoveIt.exe to launch it.
  • Copy/Paste the contents of the box below into the left hand pane of OTMoveIt.

C:\WINDOWS\system32\winavxx.exe
C:\Documents and Settings\Christopher Combs\Start Menu\Programs\Startup\system.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
C:\WINDOWS\system32\hrum455.txt

  • Click the Move It button.
  • The list will be processed and the results will appear in the right hand pane.
  • If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
  • When finished click Exit to exit the programme.
  • A log C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log will be created (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
  • Post the log back here please.
Run a scan with HJT and when finished check the following items (if found).

O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum455.txt

Now close all open windows and click Fix Checked to remove them.
  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.
Please do an online scan with Kaspersky Online Scanner

Note: You must be using Internet Explorer as your browser as it will be necessary to install an Active X component to your computer.

Important If you have previously used Kaspersky Online Scanner (before 8th Aug 2006), you will have to uninstall the old version using Add/Remove Programs in Control Panel before you can use the new version.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK.
  • Now under select a target to scan select My Computer.
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.

Run a new HJT scan and send me the log please.

Summary of the logs I need from you in your next post:
  • OTMoveIt log
  • Kaspersky log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.
Looks like we got a problem. I ran OTMoveIT and then tried to fix the hrum455.txt file with HijackThis. The following error was returned: An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum455.txt) Error #5 - Invalid procedure call or argument Please email me at [removed], reporting the following: * What you were trying to fix when the error occurred, if applicable * How you can reproduce the error * A complete HijackThis scan log, if possible Windows version: Windows NT 5.01.2600 MSIE version: 7.0.5730.11 HijackThis version: 1.99.1 This message has been copied to your clipboard. Click OK to continue the rest of the scan.
Sorry, I was in a bit of a rush and I accidentally put things in the wrong order. Should have run HJT scan first. No damage is done by doing things in the order I gave them to you, it's just that you got that message, which you otherwise wouldn't of. Because we ran OTMoveIt first, it had already removed the file, as HJT cannot find the file referred to by the registry entry it throws up that message. It should have still removed the 020 entry. As merijn no longer supports HJT the request for an email is pointless. There's no real problem, just run HJT again and send me the log, along with the OTMoveIt log and the Kaspersky log please.
Here are the logs: File/Folder C:\WINDOWS\system32\winavxx.exe not found. File/Folder C:\Documents and Settings\Christopher Combs\Start Menu\Programs\Startup\system.exe not found. File/Folder C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe not found. C:\WINDOWS\system32\hrum455.txt moved successfully. Created on 08/20/2007 19:56:32
——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Tuesday, August 21, 2007 9:36:19 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 22/08/2007 Kaspersky Anti-Virus database records: 386929 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 78362 Number of viruses found: 23 Number of infected objects: 138 Number of suspicious objects: 2 Duration of the scan process: 00:59:22 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\71aa05b4eb24b8703a344fa97eeb827c_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-08-21_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped C:\Documents and Settings\Christopher Combs\Application Data\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped C:\Documents and Settings\Christopher Combs\Application Data\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped C:\Documents and Settings\Christopher Combs\Application Data\GTek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped C:\Documents and Settings\Christopher Combs\Application Data\GTek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20018-5f6f700f.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20018-5f6f700f.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20018-5f6f700f.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20018-5f6f700f.zip ZIP: infected - 3 skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-43e35824-219569ff.zip/BaaaaBaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-43e35824-219569ff.zip/VaaaaaaaBaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-43e35824-219569ff.zip/Baaaaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-43e35824-219569ff.zip ZIP: infected - 3 skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-2d1f1292-6f5307c2.zip/Installer.class Infected: Trojan-Downloader.Java.OpenStream.z skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-2d1f1292-6f5307c2.zip ZIP: infected - 1 skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-95238a7-55ebdf50.zip/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-95238a7-55ebdf50.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-95238a7-55ebdf50.zip ZIP: infected - 2 skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv237.jar-2d8175f5-7d9f1ba1.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv237.jar-2d8175f5-7d9f1ba1.zip ZIP: infected - 1 skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv458.jar-1b1d3a1c-2f939929.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv458.jar-1b1d3a1c-2f939929.zip/Counter.class Infected: Trojan.Java.ClassLoader.h skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv458.jar-1b1d3a1c-2f939929.zip/Parser.class Infected: Trojan.Java.ClassLoader.d skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv458.jar-1b1d3a1c-2f939929.zip ZIP: infected - 3 skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms-counter.jar-7be50d8f-4af562bc.zip/BaaaaBaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms-counter.jar-7be50d8f-4af562bc.zip/VaaaaaaaBaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms-counter.jar-7be50d8f-4af562bc.zip/Baaaaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Christopher Combs\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms-counter.jar-7be50d8f-4af562bc.zip ZIP: infected - 3 skipped C:\Documents and Settings\Christopher Combs\Cookies\INDEX.DAT Object is locked skipped C:\Documents and Settings\Christopher Combs\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Christopher Combs\Desktop\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Christopher Combs\Desktop\SmitfraudFix.zip ZIP: infected - 1 skipped C:\Documents and Settings\Christopher Combs\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Christopher Combs\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped C:\Documents and Settings\Christopher Combs\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Christopher Combs\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Christopher Combs\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\Christopher Combs\Local Settings\History\History.IE5\MSHist012007082120070822\index.dat Object is locked skipped C:\Documents and Settings\Christopher Combs\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Christopher Combs\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Christopher Combs\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Christopher Combs\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine2F2205B.cla Infected: Trojan.Java.ClassLoader.Dummy.d skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine4B969AD.zip/MyFunction.class Infected: Trojan-Dropper.Java.Small.c skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine4B969AD.zip ZIP: infected - 1 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine4B969AD.zip CryptFF: infected - 1 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineA7431BC.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineA7431BC.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineA7431BC.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineA7431BC.zip ZIP: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineA7431BC.zip CryptFF: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineE643CF1.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineE643CF1.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineE643CF1.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineE643CF1.zip ZIP: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineE643CF1.zip CryptFF: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\QuarantineF4E4045.tmp Infected: Trojan-Downloader.Java.OpenStream.c skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\102B3F73.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\102B3F73.zip/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\102B3F73.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\102B3F73.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\102B3F73.zip ZIP: infected - 4 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\102B3F73.zip CryptFF: infected - 4 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\14703532.cla Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\192452A5.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\192452A5.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\192452A5.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\192452A5.zip ZIP: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\192452A5.zip CryptFF: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2604224F.cla Infected: Trojan.Java.ClassLoader.c skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2604224F.htm Infected: Exploit.VBS.Phel.a skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2604224F.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2604224F.zip/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2604224F.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2604224F.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2604224F.zip ZIP: infected - 4 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2604224F.zip CryptFF: infected - 4 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\266232EE.cla Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\266232EE.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\266232EE.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\266232EE.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\266232EE.zip ZIP: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\266232EE.zip CryptFF: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\270F6430.htm Suspicious: Exploit.VBS.Phel skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3E817F50.cla Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\48436C02.cla Infected: Trojan.Java.ClassLoader.c skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\484615FE.cla Infected: Trojan.Java.ClassLoader.Dummy.a skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\484615FE.htm Infected: Exploit.VBS.Phel.a skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\484615FE.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\484615FE.zip/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\484615FE.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\484615FE.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\484615FE.zip ZIP: infected - 4 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\484615FE.zip CryptFF: infected - 4 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6378296C.tmp Infected: Trojan.Java.ClassLoader.k skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63932B73.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63932B73.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63932B73.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63932B73.zip ZIP: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63932B73.zip CryptFF: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\64467615.htm Infected: Exploit.HTML.Mht skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\654540FC.htm Suspicious: Exploit.HTML.Mht skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6F2E6CFC.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6F2E6CFC.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6F2E6CFC.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6F2E6CFC.zip ZIP: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6F2E6CFC.zip CryptFF: infected - 3 skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72843ED6.cla Infected: Trojan.Java.ClassLoader.Dummy.a skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7CAC5312.cla Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7DC728DF.exe Infected: Trojan.Win32.Dialer.ay skipped C:\QooBox\Quarantine\C\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\autorun.exe.vir Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\QooBox\Quarantine\C\DOCUME~1\CHRIST~1\STARTM~1\Programs\Startup\system.exe.vir Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\printer.exe.vir Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\winavxx.exe.vir Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134792.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134793.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134794.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134810.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134811.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134812.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134838.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134839.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134841.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134849.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134850.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134852.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134861.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134862.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134876.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134877.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134879.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134886.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134887.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134888.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134912.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134913.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134915.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134928.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134929.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134930.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134950.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134951.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134952.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134970.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134971.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134972.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0134999.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0135000.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP205\A0135002.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP206\A0135027.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP206\A0135028.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP206\A0135029.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP206\A0135030.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP206\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped C:\WINDOWS\SYSTEM32\hrum455.txt Infected: Trojan.Win32.Agent.ali skipped C:\WINDOWS\SYSTEM32\LogFiles\HTTPERR\httperr1.log Object is locked skipped C:\WINDOWS\SYSTEM32\vtr455.dll Infected: Trojan-Downloader.Win32.Agent.bxx skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\WIADEBUG.LOG Object is locked skipped C:\WINDOWS\WIASERVC.LOG Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\_OTMoveIt\MovedFiles\WINDOWS\system32\hrum455.txt Infected: Trojan.Win32.Agent.ali skipped Scan process completed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI