This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Winantispyware20007 Removal

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was infected by all sorts of things but most of it seems to be gone. The notable exception is Winantispyware2007 which pops up every 30 seconds or so.


Here's my log….

Logfile of HijackThis v1.99.1
Scan saved at 2:28:15 PM, on 9/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec AntiVirus\SavRoam.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\svhost.exe
C:\WINDOWS\retadpu77.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\WinPop\winpop.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [howyro] C:\Program Files\MSN\howyro22011.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\fqgrxgri.dll",forkonce
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\lsdsrngl.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
Hello debrak and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


A. Some trojans have a way of masking their presence from the HijackThis program when they recognize the name. I think that this is the case here because there are no 02 or 020 entries visible in your log.

Please locate the following file on your desktop: HijackThis.exe
Next, right click on the file and from the popup menu that appears, choose the RENAME option and rename the file Killer.exe.

From now on, when I ask you to start HijackThis, just click on the Killer.exe file.


B. Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.



C. Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall


D. Reports/Logs to post:
  • VundoFix.txt
  • ComboFix.txt
  • HijackThis log
Thanks for the reply Trevuren. Here are my logs. I did receive an error message when doing the hijack this scan and that message is before the log.

Thank you.

VundoFix V6.5.8

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Scan started at 11:08:29 AM 9/6/2007

Listing files found while scanning….

C:\windows\system32\dbfqfrxw.ini
C:\windows\system32\fqgrxgri.dll
C:\WINDOWS\system32\gebyx.dll
C:\windows\system32\irgxrgqf.ini
C:\WINDOWS\system32\khfcaba.dll
C:\WINDOWS\system32\lhewdysb.dll
C:\WINDOWS\system32\wxrfqfbd.dll
C:\WINDOWS\system32\xybeg.bak1
C:\WINDOWS\system32\xybeg.bak2
C:\WINDOWS\system32\xybeg.ini
C:\WINDOWS\system32\xybeg.ini2
C:\WINDOWS\system32\xybeg.tmp

Beginning removal…

Attempting to delete C:\windows\system32\dbfqfrxw.ini
C:\windows\system32\dbfqfrxw.ini Has been deleted!

Attempting to delete C:\windows\system32\fqgrxgri.dll
C:\windows\system32\fqgrxgri.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebyx.dll
C:\WINDOWS\system32\gebyx.dll Has been deleted!

Attempting to delete C:\windows\system32\irgxrgqf.ini
C:\windows\system32\irgxrgqf.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\khfcaba.dll
C:\WINDOWS\system32\khfcaba.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wxrfqfbd.dll
C:\WINDOWS\system32\wxrfqfbd.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xybeg.bak1
C:\WINDOWS\system32\xybeg.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\xybeg.bak2
C:\WINDOWS\system32\xybeg.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\xybeg.ini
C:\WINDOWS\system32\xybeg.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xybeg.ini2
C:\WINDOWS\system32\xybeg.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\xybeg.tmp
C:\WINDOWS\system32\xybeg.tmp Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.8

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Scan started at 11:14:43 AM 9/6/2007

Listing files found while scanning….

C:\windows\system32\wxrfqfbd.dll

Beginning removal…

Attempting to delete C:\windows\system32\wxrfqfbd.dll
C:\windows\system32\wxrfqfbd.dll Has been deleted!

Performing Repairs to the registry.
Done!




ComboFix log……

ComboFix 07-09-06.4 - "Debra.Kemerling" 2007-09-06 11:24:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.180 [GMT -7:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\ProductCode
C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\ICROSO~1.NET
C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\WinAntiSpyware 2006
C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\WinAntiSpyware 2006\Logs\update.log
C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\WinAntiSpyware 2007
C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\WinAntiSpyware 2007\Logs\update.log
C:\DOCUME~1\DEBRAK~1.CA\STARTM~1\Programs\Startup.\TA_Start.lnk
C:\DOCUME~1\DEBRAK~1.CA\STARTM~1\Programs\Startup\ta_start.lnk
C:\Program Files\Common Files\racle~1
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\Common Files\ystem~1
C:\Program Files\inetget2
C:\Program Files\MSN Gaming Zone\proky.html
C:\Program Files\svhost
C:\Program Files\svhost\wr-1-0000077.exe
C:\Program Files\svhost\wr-1-77.exe
C:\Program Files\winpop
C:\Program Files\winpop\UnInstall.exe
C:\Program Files\winpop\winpop.exe
C:\tempb9
C:\tempb9\tmpTF.log
C:\tempc2
C:\tempc2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\temp\iee
C:\temp\iee\tmpZTF.log
C:\WINDOWS\b103.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\b143.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\retadpu77.exe
C:\WINDOWS\svhost.exe
C:\WINDOWS\system32\afeedyla.exe
C:\WINDOWS\system32\auvjegqp.exe
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\bcpytvrc.exe
C:\WINDOWS\system32\beaptbxr.exe
C:\WINDOWS\system32\bnjfxqxc.exe
C:\WINDOWS\system32\bqjrlybv.exe
C:\WINDOWS\system32\bxyyrlko.exe
C:\WINDOWS\system32\cbgoximd.exe
C:\WINDOWS\system32\cugvrtjj.exe
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\dtndgyrf.exe
C:\WINDOWS\system32\dxwlasjh.exe
C:\WINDOWS\system32\eenvvbgh.exe
C:\WINDOWS\system32\eijpwirx.exe
C:\WINDOWS\system32\eqnleqty.exe
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\system32\fecvqbqi.exe
C:\WINDOWS\system32\G1
C:\WINDOWS\system32\G11
C:\WINDOWS\system32\G2
C:\WINDOWS\system32\G3
C:\WINDOWS\system32\G4
C:\WINDOWS\system32\G5
C:\WINDOWS\system32\G7
C:\WINDOWS\system32\gleyplsn.exe
C:\WINDOWS\system32\govvnhhv.exe
C:\WINDOWS\system32\hkdjcdsn.exe
C:\WINDOWS\system32\hwahghwk.exe
C:\WINDOWS\system32\irspxpgp.exe
C:\WINDOWS\system32\keoyielh.exe
C:\WINDOWS\system32\kresibjo.exe
C:\WINDOWS\system32\ktuxedev.exe
C:\WINDOWS\system32\kuvtcbhp.exe
C:\WINDOWS\system32\lhjjvepw.exe
C:\WINDOWS\system32\ltcofwaq.exe
C:\WINDOWS\system32\lvnhvlfr.exe
C:\WINDOWS\system32\lwssasjt.exe
C:\WINDOWS\system32\mwouvxqe.exe
C:\WINDOWS\system32\myxyyxuc.exe
C:\WINDOWS\system32\nijywybf.exe
C:\WINDOWS\system32\o02PrEz
C:\WINDOWS\system32\omvshikl.exe
C:\WINDOWS\system32\onoodfux.exe
C:\WINDOWS\system32\ooqjaeyq.exe
C:\WINDOWS\system32\oqwtyqeq.exe
C:\WINDOWS\system32\oshuijor.exe
C:\WINDOWS\system32\ovinedgi.exe
C:\WINDOWS\system32\pfmfrrxm.exe
C:\WINDOWS\system32\ptrnxipe.exe
C:\WINDOWS\system32\qhkxxwox.exe
C:\WINDOWS\system32\rvglnhrm.exe
C:\WINDOWS\system32\smante~1
C:\WINDOWS\system32\svshghul.exe
C:\WINDOWS\system32\svsvpscr.exe
C:\WINDOWS\system32\tprbogkb.exe
C:\WINDOWS\system32\trrtlhbu.exe
C:\WINDOWS\system32\tvcmravc.exe
C:\WINDOWS\system32\ufsslrbf.exe
C:\WINDOWS\system32\ugvkjfex.exe
C:\WINDOWS\system32\upagsfar.exe
C:\WINDOWS\system32\uveetjch.exe
C:\WINDOWS\system32\vbinguai.exe
C:\WINDOWS\system32\vhrjlxhh.exe
C:\WINDOWS\system32\vmvlcfln.exe
C:\WINDOWS\system32\voebjhmw.exe
C:\WINDOWS\system32\whauhhsr.exe
C:\WINDOWS\system32\whdklipa.exe
C:\WINDOWS\system32\win
C:\WINDOWS\system32\wjxxgkbb.exe
C:\WINDOWS\system32\wmwmwhhg.exe
C:\WINDOWS\system32\wsiwxrpp.exe
C:\WINDOWS\system32\wvufpsqw.exe
C:\WINDOWS\system32\xavaeijw.exe
C:\WINDOWS\system32\xavjpcxq.exe
C:\WINDOWS\system32\xcqvbkpu.exe
C:\WINDOWS\system32\xidlknqp.exe
C:\WINDOWS\system32\xikaelda.exe
C:\WINDOWS\system32\ybwlddbk.exe
C:\WINDOWS\system32\youxypem.exe
C:\WINDOWS\system32\yqtywlmg.exe
C:\WINDOWS\system32\zxdnt3d.cfg


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_FOPN
——-\LEGACY_NETWORK_MONITOR
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 )))))))))))))))))))))))))))))))


2007-09-06 11:23 51,200 –a–c— C:\WINDOWS\NirCmd.exe
2007-09-06 11:08 d—-c— C:\VundoFix Backups
2007-08-19 15:12 d—-c— C:\WINDOWS\fffr
2007-08-19 15:12 d—-c— C:\Program Files\Common Files\fffr
2007-08-19 12:25 d—-c— C:\WINDOWS\system32\tmps7
2007-08-19 12:25 d—-c— C:\WINDOWS\system32\ICM23
2007-08-19 12:25 d—-c— C:\WINDOWS\system32\cofig1
2007-08-17 10:57 3,648 –a–c— C:\WINDOWS\system32\phemrfgg.dll
2007-08-15 15:41 d-a–c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-08-15 15:41 d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
2007-08-15 15:40 d—-c— C:\Program Files\Jolly Bear Games


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-04 16:07 3766 –ahsc— C:\WINDOWS\system32\KGyGaAvL.sys
2007-09-04 16:06 56 -r-hsc— C:\WINDOWS\system32\A849232B04.sys
2007-09-02 18:09 ——— d–h-c— C:\Program Files\InstallShield Installation Information
2007-09-02 18:09 ——— d—-c— C:\Program Files\CyberLink
2007-09-02 02:59 ——— d—-c— C:\Program Files\DBxtra 2005
2007-08-15 14:56 ——— d—-c— C:\Program Files\JetAudio
2007-08-14 15:20 ——— d—-c— C:\Program Files\SecureCRT
2007-07-31 11:04 1731852 —hsc— C:\WINDOWS\system32\qttss.ini2
2007-07-31 10:56 1732366 —hsc— C:\WINDOWS\system32\qttss.bak2
2007-07-31 10:19 ——— d—-c— C:\Program Files\Yahoo!
2007-07-31 10:19 ——— d—-c— C:\Program Files\Common Files\Scanner
2007-07-31 10:18 ——— dr-h-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\yahoo!
2007-07-31 10:18 ——— d—-c— C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\Yahoo!
2007-07-31 10:18 ——— d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-07-30 19:19 92504 –a–c— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a–c— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a–c— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a–c— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a–c— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 –a–c— C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 –a–c— C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 –a–c— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a–c— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a–c— C:\WINDOWS\system32\wups.dll
2007-07-27 15:07 783224 –a–c— C:\WINDOWS\system32\aswBoot.exe
2007-07-27 15:02 94416 –a–c— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-27 15:02 92848 –a–c— C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-27 15:00 23152 –a–c— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-27 14:59 42912 –a–c— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-27 14:58 26624 –a–c— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-27 14:57 95608 –a–c— C:\WINDOWS\system32\AvastSS.scr
2007-07-25 16:19 ——— d—-c— C:\Program Files1-mp3search
2007-07-23 13:31 ——— d—-c— C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\webex
2007-07-23 13:27 202314 –a–c— C:\WINDOWS\system32\atasnt40.dll
2007-07-17 11:42 ——— d—-c— C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\COWON
2007-07-14 18:24 1940014 —hsc— C:\WINDOWS\system32\qttss.bak1
2007-07-11 16:21 ——— d—-c— C:\Program Files\COWON
2007-07-11 14:24 ——— d—-c— C:\Program Files\Common Files\COWON
2007-06-25 23:08 1104896 –a–c— C:\WINDOWS\system32\msxml3.dll
2007-06-19 06:31 282112 –a–c— C:\WINDOWS\system32\gdi32.dll
2007-06-13 10:23 24576 –a–c— C:\WINDOWS\system32\ERD.dll
2007-06-13 03:23 1033216 –a–c— C:\WINDOWS\explorer.exe
2007-03-05 12:11 56912 –a–c— C:\DOCUME~1\DEBRAK~1.CA\g2mdlhlpx.exe
2006-06-08 14:03 28672 –a–c— C:\DOCUME~1\DEBRAK~1.CA\atwbxdet.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10A12DCE-4852-49C9-9967-0B85BEA518C1}]
C:\WINDOWS\system32\gebyx.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61C07397-1519-45B4-A6F4-902B8327A0BF}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F676EFE-843A-AE93-1814-888DCE278497}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E7968C08-65CC-4E68-EF5B-3C76616C5698}]
C:\WINDOWS\system32\xajdvs.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-29 10:07]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-27 15:03]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-07-31 10:40]
"RegistryMechanic"="" []
"howyro"="C:\Program Files\MSN\howyro22011.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-01-03 16:03]
"svhost"="C:\WINDOWS\svhost.exe" []
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 07:59]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 07:59]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqqon]
awtqqon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 15:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssttq]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuromm]
wvuromm.dll

R2 ATNT40K;ActiveTouch NT Appsharing Driver;C:\WINDOWS\system32\DRIVERS\ATNT40K.SYS
R2 LogWatch;Event Log Watch;"C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe"
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
R3 dpK0Bx01;Fingerprint Reader Filter Driver;C:\WINDOWS\system32\DRIVERS\dpK0Bx01.sys
R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
R3 UsbdpFP;Fingerprint Reader Class Driver;C:\WINDOWS\system32\DRIVERS\UsbdpFP.sys
S3 AX88772;ASIX AX88772 USB2.0 to Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\ax88772.sys
S3 CA_LIC_CLNT;CA License Client;"C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe"
S3 cmudau;C-Media USB Sound Interface;C:\WINDOWS\system32\drivers\cmudaxu.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec93f582-129f-11db-85e4-00038a000015}]
AutoRun\command- E:\Kingston.exe


Contents of the 'Scheduled Tasks' folder
"2007-09-01 01:30:02 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (COMMON-Administrator).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-06 11:31:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-06 11:32:51 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-06 11:32


HijackThis log………First an error message. I completed the scan.



An unexpected error has occurred at procedure: modMain_CheckOther1Item()
Error #5 - Invalid procedure call or argument

Please email me at [removed], reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 7.0.5730.11
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.


Logfile of HijackThis v1.99.1
Scan saved at 11:34, on 2007-09-06
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec AntiVirus\SavRoam.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\killer.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {10A12DCE-4852-49C9-9967-0B85BEA518C1} - C:\WINDOWS\system32\gebyx.dll (file missing)
O2 - BHO: (no name) - {61C07397-1519-45B4-A6F4-902B8327A0BF} - (no file)
O2 - BHO: (no name) - {6F676EFE-843A-AE93-1814-888DCE278497} - (no file)
O2 - BHO: (no name) - {E7968C08-65CC-4E68-EF5B-3C76616C5698} - C:\WINDOWS\system32\xajdvs.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [howyro] C:\Program Files\MSN\howyro22011.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: awtqqon - awtqqon.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: ssttq - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wvuromm - wvuromm.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
A. I notice that you are using more than one antivirus program. This is very dangerous, as multiple AVs can interfere with one another and actually allow MORE viruses to get through. In addition, the presence of two running Antivirus programs greatly degrades system performance. I strongly suggest you either
  • configure only one antivirus program to enable automatic realtime scanning, and leave the rest disabled most of the time, or
  • go to Start -> Control Panel -> Add/Remove Programs and uninstall all but one antivirus program

B. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 2 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u2…allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Read the License Agreement and then check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.

C. Please disable AVG AntiSpyware by opening the program and on the Status page - beside "Resident Shield" click on "change status" so that it says "inactive" for it may interfere with our HJT fix.
  • Remember to reactivate this feature when all our work is finished.

D. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
    O2 - BHO: (no name) - {10A12DCE-4852-49C9-9967-0B85BEA518C1} - C:\WINDOWS\system32\gebyx.dll (file missing)
    O2 - BHO: (no name) - {61C07397-1519-45B4-A6F4-902B8327A0BF} - (no file)
    O2 - BHO: (no name) - {6F676EFE-843A-AE93-1814-888DCE278497} - (no file)
    O2 - BHO: (no name) - {E7968C08-65CC-4E68-EF5B-3C76616C5698} - C:\WINDOWS\system32\xajdvs.dll (file missing)
    O4 - HKLM\..\Run: [howyro] C:\Program Files\MSN\howyro22011.exe
    O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
    O20 - Winlogon Notify: awtqqon - awtqqon.dll (file missing)
    O20 - Winlogon Notify: ssttq - C:\WINDOWS\
    O20 - Winlogon Notify: wvuromm - wvuromm.dll (file missing)



  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

E. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\qttss.ini2
C:\WINDOWS\system32\qttss.bak2
C:\WINDOWS\system32\qttss.bak1
C:\WINDOWS\system32\A849232B04.sys
C:\WINDOWS\system32\phemrfgg.dll
C:\WINDOWS\system32\ERD.dll
C:\Program Files\MSN\howyro22011.exe
C:\WINDOWS\svhost.exe

Folder::
C:\WINDOWS\system32\ICM23
C:\WINDOWS\system32\tmps7
C:\WINDOWS\fffr
C:\Program Files\Common Files\fffr
C:\WINDOWS\system32\cofig1
C:\Program Files1-mp3search


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Ok. I uninstalled everything but symantec. My pc is faster already!

ComboFix 07-09-06.4 - "Debra.Kemerling" 2007-09-06 14:48:37.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.250 [GMT -7:00]
Command switches used :: C:\Documents and Settings\Debra.Kemerling.CA\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\system32\qttss.ini2
C:\WINDOWS\system32\qttss.bak2
C:\WINDOWS\system32\qttss.bak1
C:\WINDOWS\system32\A849232B04.sys
C:\WINDOWS\system32\phemrfgg.dll
C:\WINDOWS\system32\ERD.dll
C:\Program Files\MSN\howyro22011.exe
C:\WINDOWS\svhost.exe


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\fffr
C:\Program Files\Common Files\fffr\fffra.lck
C:\Program Files\Common Files\fffr\fffrd\class-barrel
C:\Program Files\Common Files\fffr\fffrl.lck
C:\Program Files\Common Files\fffr\fffrm.lck
C:\WINDOWS\fffr
C:\WINDOWS\fffr\fffr.dat
C:\WINDOWS\fffr\wu
C:\WINDOWS\system32\A849232B04.sys
C:\WINDOWS\system32\cofig1
C:\WINDOWS\system32\ERD.dll
C:\WINDOWS\system32\ICM23
C:\WINDOWS\system32\ICM23\nnx22011.exe
C:\WINDOWS\system32\phemrfgg.dll
C:\WINDOWS\system32\qttss.bak1
C:\WINDOWS\system32\qttss.bak2
C:\WINDOWS\system32\qttss.ini2
C:\WINDOWS\system32\tmps7


((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 )))))))))))))))))))))))))))))))


2007-09-06 11:23 51,200 –a–c— C:\WINDOWS\NirCmd.exe
2007-09-06 11:08 d—-c— C:\VundoFix Backups
2007-08-15 15:41 d-a–c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-08-15 15:41 d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
2007-08-15 15:40 d—-c— C:\Program Files\Jolly Bear Games


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-06 14:06 ——— d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-06 14:05 ——— d—-c— C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\Lavasoft
2007-09-04 16:07 3766 –ahsc— C:\WINDOWS\system32\KGyGaAvL.sys
2007-09-02 18:09 ——— d–h-c— C:\Program Files\InstallShield Installation Information
2007-09-02 18:09 ——— d—-c— C:\Program Files\CyberLink
2007-09-02 02:59 ——— d—-c— C:\Program Files\DBxtra 2005
2007-08-15 14:56 ——— d—-c— C:\Program Files\JetAudio
2007-08-14 15:20 ——— d—-c— C:\Program Files\SecureCRT
2007-07-31 10:19 ——— d—-c— C:\Program Files\Yahoo!
2007-07-31 10:19 ——— d—-c— C:\Program Files\Common Files\Scanner
2007-07-31 10:18 ——— dr-h-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\yahoo!
2007-07-31 10:18 ——— d—-c— C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\Yahoo!
2007-07-31 10:18 ——— d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-07-30 19:19 92504 –a–c— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a–c— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a–c— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a–c— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a–c— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 –a–c— C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 –a–c— C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 –a–c— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a–c— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a–c— C:\WINDOWS\system32\wups.dll
2007-07-25 16:19 ——— d—-c— C:\Program Files1-mp3search
2007-07-23 13:31 ——— d—-c— C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\webex
2007-07-23 13:27 202314 –a–c— C:\WINDOWS\system32\atasnt40.dll
2007-07-17 11:42 ——— d—-c— C:\DOCUME~1\DEBRAK~1.CA\APPLIC~1\COWON
2007-07-11 16:21 ——— d—-c— C:\Program Files\COWON
2007-07-11 14:24 ——— d—-c— C:\Program Files\Common Files\COWON
2007-06-25 23:08 1104896 –a–c— C:\WINDOWS\system32\msxml3.dll
2007-06-19 06:31 282112 –a–c— C:\WINDOWS\system32\gdi32.dll
2007-06-13 03:23 1033216 –a–c— C:\WINDOWS\explorer.exe
2007-03-05 12:11 56912 –a–c— C:\DOCUME~1\DEBRAK~1.CA\g2mdlhlpx.exe
2006-06-08 14:03 28672 –a–c— C:\DOCUME~1\DEBRAK~1.CA\atwbxdet.dll


((((((((((((((((((((((((((((( snapshot_2007-09-06_113220.14 )))))))))))))))))))))))))))))))))))))))))

-c–a-w 135,168 2007-07-12 08:22:00 C:\WINDOWS\system32\java.exe
-c–a-w 135,168 2007-07-12 08:22:04 C:\WINDOWS\system32\javaw.exe
-c–a-w 139,264 2007-07-12 09:22:38 C:\WINDOWS\system32\javaws.exe

-c–a-w 24,681 2003-11-19 22:36:26 C:\WINDOWS\system32\java.exe
-c–a-w 28,779 2003-11-19 22:36:30 C:\WINDOWS\system32\javaw.exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E7968C08-65CC-4E68-EF5B-3C76616C5698}]
C:\WINDOWS\system32\xajdvs.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-29 10:07]
"RegistryMechanic"="" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-01-03 16:03]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 07:59]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 07:59]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 15:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

R2 ATNT40K;ActiveTouch NT Appsharing Driver;C:\WINDOWS\system32\DRIVERS\ATNT40K.SYS
R2 LogWatch;Event Log Watch;"C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe"
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
R3 dpK0Bx01;Fingerprint Reader Filter Driver;C:\WINDOWS\system32\DRIVERS\dpK0Bx01.sys
R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
R3 UsbdpFP;Fingerprint Reader Class Driver;C:\WINDOWS\system32\DRIVERS\UsbdpFP.sys
S3 AX88772;ASIX AX88772 USB2.0 to Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\ax88772.sys
S3 CA_LIC_CLNT;CA License Client;"C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe"
S3 cmudau;C-Media USB Sound Interface;C:\WINDOWS\system32\drivers\cmudaxu.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec93f582-129f-11db-85e4-00038a000015}]
AutoRun\command- E:\Kingston.exe


Contents of the 'Scheduled Tasks' folder
"2007-09-01 01:30:02 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (COMMON-Administrator).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-06 14:52:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-06 14:54:30 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-06 14:53
C:\ComboFix2.txt … 2007-09-06 11:32

— E O F —

Logfile of HijackThis v1.99.1
Scan saved at 14:56, on 2007-09-06
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\killer.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {E7968C08-65CC-4E68-EF5B-3C76616C5698} - C:\WINDOWS\system32\xajdvs.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
A. Make sure that AVG AS Guard is disabled as directed in my last post.

B. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
    O2 - BHO: (no name) - {E7968C08-65CC-4E68-EF5B-3C76616C5698} - C:\WINDOWS\system32\xajdvs.dll (file missing)



  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

  • Finally, RUN Hijackthis again and produce a new HJT log. Post it in this thread so we can check how everything looks now. In addition, please tell me if there are any more malware problems that you are aware of.


C. Time to check the rest of the system.

Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log
Here is the HJT log, followed by Kaspersky scan. I did stop that scan because it was starting to scan the network drives at work. But it got C:.

I have not had a problem since yesterday. My pc is running much faster, especially the internet. No popups or weird messages.

Logfile of HijackThis v1.99.1
Scan saved at 10:55, on 2007-09-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec AntiVirus\SavRoam.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hijackthis\killer.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [PCPitstop Optimize Registration Reminder] C:\Program Files\PCPitstop\Optimize\Reminder.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2007-09-07 12:48
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 7/09/2007
Kaspersky Anti-Virus database records: 410021
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
J:\
N:\
P:\
Q:\
V:\
X:\
Z:\

Scan Statistics:
Total number of scanned objects: 63285
Number of viruses found: 19
Number of infected objects: 186
Number of suspicious objects: 8
Duration of the scan process: 01:26:59

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_50e417e0-e461-474b-96e2-077b80325612 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a6662ed1ac15b778b83a39366f65e343_50e417e0-e461-474b-96e2-077b80325612 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip/retadpu2000219.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt.zip/retadpu1000106.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt11.zip/retadpu1000106.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt11.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt6.zip/retadpu572.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt6.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\Local Settings\History\History.IE5\MSHist012007090720070908\index.dat Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\Local Settings\Temp\hsperfdata_Debra.Kemerling\3900 Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\Local Settings\Temp\~DFF901.tmp Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Debra.Kemerling.CA\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_708.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log_228.trc Object is locked skipped
C:\qoobox\Quarantine\C\Program Files\svhost\wr-1-77.exe.vir Infected: Trojan-Downloader.Win32.Small.fky skipped
C:\qoobox\Quarantine\C\Program Files\WinPop\UnInstall.exe.vir Infected: Trojan.Win32.Small.oa skipped
C:\qoobox\Quarantine\C\Program Files\WinPop\winpop.exe.vir Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\qoobox\Quarantine\C\WINDOWS\b122.exe.vir Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\qoobox\Quarantine\C\WINDOWS\b138.exe.vir Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\qoobox\Quarantine\C\WINDOWS\svhost.exe.vir Infected: Trojan-Proxy.Win32.VB.x skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\afeedyla.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\auvjegqp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bcpytvrc.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\beaptbxr.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bnjfxqxc.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bqjrlybv.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bxyyrlko.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\cbgoximd.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\cugvrtjj.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\dtndgyrf.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\dxwlasjh.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\eenvvbgh.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\eijpwirx.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\eqnleqty.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\fecvqbqi.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\gleyplsn.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\govvnhhv.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\hkdjcdsn.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\hwahghwk.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ICM23\nnx22011.exe.vir/data0004 Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ICM23\nnx22011.exe.vir NSIS: infected - 1 skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\irspxpgp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\keoyielh.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kresibjo.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ktuxedev.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kuvtcbhp.exe.vir Infected: Trojan.Win32.Agent.bck skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\lhjjvepw.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ltcofwaq.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\lvnhvlfr.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\lwssasjt.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\mwouvxqe.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\myxyyxuc.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\nijywybf.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\omvshikl.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\onoodfux.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ooqjaeyq.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\oqwtyqeq.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\oshuijor.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ovinedgi.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\pfmfrrxm.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ptrnxipe.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\qhkxxwox.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\rvglnhrm.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\svshghul.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\svsvpscr.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\tprbogkb.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\trrtlhbu.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\tvcmravc.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ufsslrbf.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ugvkjfex.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\upagsfar.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\uveetjch.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vbinguai.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vhrjlxhh.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vmvlcfln.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\voebjhmw.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\whauhhsr.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\whdklipa.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\wjxxgkbb.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\wmwmwhhg.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\wsiwxrpp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\wvufpsqw.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\xavaeijw.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\xavjpcxq.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\xcqvbkpu.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\xidlknqp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\xikaelda.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ybwlddbk.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\youxypem.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\yqtywlmg.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP516\A0118852.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP516\A0118853.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP520\A0121965.exe/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP520\A0121965.exe Inno: infected - 1 skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP521\A0123947.exe Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP521\A0123949.exe Infected: Trojan-Downloader.Win32.Agent.cpj skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP523\A0125050.exe Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131195.exe Infected: Trojan-Downloader.Win32.Agent.cpj skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131198.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131199.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131210.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131210.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131210.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131210.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131214.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131215.exe Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131216.exe Infected: Trojan-Downloader.Win32.VB.bgd skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131217.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131227.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131349.exe Infected: Trojan-Downloader.Win32.Small.fky skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131362.exe Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131363.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131364.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131365.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131366.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP525\A0131367.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP526\A0131384.exe Infected: Trojan-Downloader.Win32.Small.fky skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP526\A0131391.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP526\A0131415.exe Infected: Trojan-Downloader.Win32.Small.fky skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131437.exe Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131438.exe Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131440.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131441.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131442.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131443.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131444.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131445.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131446.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131447.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131448.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131449.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131450.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131451.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131452.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131453.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131454.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131455.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131456.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131457.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131458.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131459.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131460.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131461.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131462.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131463.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131464.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131465.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131466.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131467.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131468.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131469.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131470.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131471.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131472.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131473.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131474.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131475.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131476.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131477.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131478.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131479.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131480.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131481.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131482.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131483.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131484.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131485.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131486.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131487.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131488.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131489.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131490.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131491.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131492.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131493.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131494.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131495.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131496.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131497.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131498.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131499.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131500.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131501.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131502.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131503.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131504.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131505.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131506.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131507.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131509.exe Infected: Trojan-Downloader.Win32.Small.fky skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131510.exe Infected: Trojan.Win32.Small.oa skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131511.exe Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP527\A0131512.exe Infected: Trojan-Proxy.Win32.VB.x skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP530\A0131916.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP530\A0131916.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP530\change.log Object is locked skipped
C:\VundoFix Backups\khfcaba.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\WINDOWS\CSC\000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
J:\ADMARC\Documents\CUSTOM\American Assoc of Retired Persons\vnc-3.3.7-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
J:\ADMARC\Documents\CUSTOM\American Assoc of Retired Persons\vnc-3.3.7-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
J:\ADMARC\Documents\CUSTOM\American Assoc of Retired Persons\vnc-3.3.7-x86_win32.exe/data0004 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
J:\ADMARC\Documents\CUSTOM\American Assoc of Retired Persons\vnc-3.3.7-x86_win32.exe Inno: infected - 3 skipped
J:\ADMARC\Documents\CUSTOM\Newsday\BOE-INTERNAL Newsday SR19345.xls Object is locked skipped
J:\ADMARC\Documents\CUSTOM\Newsday\Options.xls Object is locked skipped

Scan was interrupted by user!
Good News. All the infected items are in Quarantine or in your System Restore Cache. The restore cache will be cleaned during our final cleanup procedures.


A. Please DELETE the following folders :

C:\qoobox
C:\VundoFix Backups


B. Now, please delete the content of the following folder, not the folder itself:

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\


C. If you have no more malware-related problems that you are aware of, just give me the OK and we can start the final but essential cleanup procedures and recommendations.

Trevuren
Sorry, to see that folder you must show Hidden Files:

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and shutdown My Computer.
10. Now your computer is configured to show all hidden files.


Now DELETE the entire folder instead:

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy


Now please rehide these files and folders by reversing the initial process


Please tell me how your system is now running.
Congratulations, your logs look CLEAN

There are a few things you must do once you system is completely clean:

1. Time for some housekeeping

Please download the OTMoveIt by OldTimer
  • Save it to your desktop.
  • Run the tool by clicking on the icon.
  • Click the Cleanup button.
  • The tools that we used as well as this one will be removed from your system.

2. Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

3. Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Here are some tips to reduce the potential for spyware infection in the future:

Make sure you keep your Windows OS current by visiting Windows update
regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
And also see TonyKlein's good advice
So how did I get infected in the first place?

Regards,

Trevuren
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI