Ok I have finished all task.
Couldn't flush the dns resolver cache:function failed during execution
here are the reports.
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, September 14, 2007 5:45:36 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 14/09/2007
Kaspersky Anti-Virus database records: 418620
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
G:\
H:\
Scan Statistics:
Total number of scanned objects: 69760
Number of viruses found: 9
Number of infected objects: 59
Number of suspicious objects: 0
Duration of the scan process: 01:55:58
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01204/X-Scan/dat/cgi.lst Infected: Exploit.Win32.WebDir skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01204/X-Scan/Xscan.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01204/X-Scan/xscan_gui.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01204 RAR: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01204 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01724/X-Scan/dat/cgi.lst Infected: Exploit.Win32.WebDir skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01724/X-Scan/Xscan.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01724/X-Scan/xscan_gui.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01724 RAR: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01724 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01972/X-Scan/dat/cgi.lst Infected: Exploit.Win32.WebDir skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01972/X-Scan/Xscan.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01972/X-Scan/xscan_gui.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01972 RAR: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\X-Scan.rar.bac_a01972 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall\Quarantine\xray_edit_by_tc_fxp.exe.bac_a01724 Infected: HackTool.Win32.Xray.a skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\Dc225.exe.bac_a01056 Infected: Trojan.Win32.Agent.tv skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\rxflkyy.exe.bac_a01056 Infected: Trojan-Spy.Win32.Goldun.lw skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a00528/X-Scan/dat/cgi.lst Infected: Exploit.Win32.WebDir skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a00528/X-Scan/Xscan.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a00528/X-Scan/xscan_gui.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a00528 RAR: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a00528 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01204/X-Scan/dat/cgi.lst Infected: Exploit.Win32.WebDir skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01204/X-Scan/Xscan.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01204/X-Scan/xscan_gui.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01204 RAR: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01204 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01724/X-Scan/dat/cgi.lst Infected: Exploit.Win32.WebDir skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01724/X-Scan/Xscan.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01724/X-Scan/xscan_gui.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01724 RAR: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01724 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01972/X-Scan/dat/cgi.lst Infected: Exploit.Win32.WebDir skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01972/X-Scan/Xscan.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01972/X-Scan/xscan_gui.exe Infected: HackTool.Win32.XScan.23 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01972 RAR: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\X-Scan.rar.bac_a01972 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\xray_edit_by_tc_fxp.exe.bac_a01724 Infected: HackTool.Win32.Xray.a skipped
C:\Documents and Settings\Administrator\Application Data\SiteAdvisor\SiteAdv.csh Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\vnc-4.0-x86_win32_viewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee\VirusScan\Data\TFR2.tmp Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\easynews\nero\Nero 7.8.5.0 working version\Nero-7.8.5.0 eng.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\easynews\nero\Nero 7.8.5.0 working version\Nero-7.8.5.0 eng.exe RAR: infected - 1 skipped
C:\easynews\vnc-4_1_2-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\easynews\vnc-4_1_2-x86_win32.exe/file2 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\easynews\vnc-4_1_2-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\easynews\vnc-4_1_2-x86_win32.exe/file5 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\easynews\vnc-4_1_2-x86_win32.exe Inno: infected - 4 skipped
C:\Excursion9.5\mIRC.ExCurSioN.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.612 skipped
C:\Program Files\ASUS\Probe\Record\2007914 Object is locked skipped
C:\Program Files\Opera\profile\cache4\opr029P9.exe/stream/Script Infected: Trojan.Win32.DNSChanger.ka skipped
C:\Program Files\Opera\profile\cache4\opr029P9.exe/stream Infected: Trojan.Win32.DNSChanger.ka skipped
C:\Program Files\Opera\profile\cache4\opr029P9.exe NSIS: infected - 2 skipped
C:\Program Files\Opera\profile\cache4\temporary_download\codec-club4125.exe/stream/Script Infected: Trojan.Win32.DNSChanger.ka skipped
C:\Program Files\Opera\profile\cache4\temporary_download\codec-club4125.exe/stream Infected: Trojan.Win32.DNSChanger.ka skipped
C:\Program Files\Opera\profile\cache4\temporary_download\codec-club4125.exe NSIS: infected - 2 skipped
C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcmsc_iWaPHUvf42VWqhI Object is locked skipped
C:\X-Scan\xscan_gui.exe Infected: HackTool.Win32.XScan.23 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Logfile of HijackThis v1.99.1
Scan saved at 5:51:07 PM, on 9/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
C:\WINDOWS\asuskbservice.exe
C:\WINDOWS\CDProxyServ.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\hphmon03.exe
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\HPHipm09.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar6.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar6.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6009\SiteAdv.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.excite.com
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) -
http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1122415502578
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) -
http://www.lowrance.com/Software/PCSoftwar…330C/isetup.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CBBEE890-CB43-46B4-A428-7702DEA50265}: NameServer = 63.107.192.14,199.170.121.15
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
O23 - Service: ASUSKeyboardService - ASUSTeK COMPUTER INC. - C:\WINDOWS\asuskbservice.exe
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
Username "Administrator" - 09/14/2007 13:58:14 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdjgq.exe"
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{6CFD130F-79B0-4471-BFC3-52FB470A5E16}
"DhcpNameServer"="[removed],[removed]"
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{CBBEE890-CB43-46B4-A428-7702DEA50265}
"DhcpNameServer"="[removed],[removed]"
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{E50E18E8-9742-40AB-BC20-3062502B46CC}
"DhcpNameServer"="[removed],[removed]"
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{FD2D24FE-9E9E-4A42-A0E5-FEA07F7255C2}
"DhcpNameServer"="[removed],[removed]"
Could not flush the DNS Resolver Cache: Function failed during execution.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
….
~~~~~ Misc files.
….
~~~~~ Checking for older varients.
….
~~~~~ Other
C:\WINDOWS\Temp\kdjgq.ren 71207 08/04/2004
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"HPHmon03"="C:\\WINDOWS\\system32\\hphmon03.exe"
"anvshell"="anvshell.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"nForce Tray Options"="sstray.exe /r"
"SiteAdvisor"="C:\\Program Files\\SiteAdvisor\\6009\\SiteAdv.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"CARPService"="carpserv.exe"
"ASUS Probe"="C:\\Program Files\\ASUS\\Probe\\AsusProb.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"mcagent_exe"="C:\\Program Files\\McAfee.com\\Agent\\mcagent.exe /runkey"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
….
Hosts file was reset, If you use a custom hosts file please replace it…
~~~~~ End report ~~~~~
Symantec Ryknos Removal Tool 1.2.0
Ryknos has not been found on your computer.