macditty
Topic Starter
ok a short description of my problem. i am a linux user, i logged onto my mothers computer and i was having tons of popups, she didnt see this as odd because windows has always done this. anyway i did a scan and cleared most of the stuff but one program is giving me problems. i cant seem to shake it. please help, im not used to dealing with all of this new spyware technology in windows being away for so long.
hijackthis log ————-
Logfile of HijackThis v1.99.1
Scan saved at 4:46:09 PM, on 10/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Eset\nod32kui.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Common Files\AOL\1189882368\ee\AOLSoftware.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\EssNetTools3\Ent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13F815B5-BC6E-43C4-AE05-9EBC2408468C} - (no file)
O2 - BHO: (no name) - {2D624F0B-9EDA-46CD-A29C-B07CCC4A6638} - (no file)
O2 - BHO: (no name) - {3AA3D6F8-D18A-470F-A9EA-DB354A350970} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {73552DCE-4D7F-4D47-93D7-41BB4A9CA501} - (no file)
O2 - BHO: (no name) - {7f9aaf14-478f-4b6b-b0c1-7322427f46ec} - (no file)
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\cwyuldai.dll (file missing)
O2 - BHO: (no name) - {92D4828D-EE1F-4056-A49D-9733885CF4C8} - (no file)
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {B8B6B908-BFB0-4BBE-A940-0094BADF099F} - (no file)
O2 - BHO: (no name) - {D73F0BA8-5E00-4784-9FE8-545BE1D78CA2} - C:\WINDOWS\system32\jkkjk.dll (file missing)
O2 - BHO: (no name) - {DE8BA79A-6281-4795-92EF-5C186D7E2E76} - (no file)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1189882368\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Essential NetTools] C:\Program Files\EssNetTools3\Ent.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: ljjhigh - C:\WINDOWS\
O20 - Winlogon Notify: urqppol - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\oseoqjrm.exe (file missing)
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
a few more logs and events from NOD32 the one in bold worries me
Time Module Object Name Threat Action User Information
10/3/2007 15:53:12 PM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\C5MRCLOF\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/3/2007 15:51:06 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\amnymcjn.exe Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/3/2007 15:50:48 PM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan Connection terminated YOUR-AE066C3A9B\HP_Owner
10/3/2007 7:05:09 AM AMON file C:\WINDOWS\system32\dxlhoaho.dll a variant of Win32/BHO.G trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/2/2007 7:29:32 AM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\O9EZGD6J\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/2/2007 7:29:32 AM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\iepnqxbf.exe Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/2/2007 7:29:31 AM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan YOUR-AE066C3A9B\HP_Owner
10/2/2007 6:29:49 AM AMON file C:\WINDOWS\system32\varapbbx.dll a variant of Win32/BHO.G trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:36:10 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\uetuhxdp.dll a variant of Win32/BHO.G trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\explorer.exe. The file was moved to quarantine. You may close this window.
10/1/2007 19:27:27 PM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\XZ9NXY3H\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\explorer.exe. The file was moved to quarantine. You may close this window.
10/1/2007 19:27:27 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\sutuuiyc.exe Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\explorer.exe. The file was moved to quarantine. You may close this window.
10/1/2007 19:27:27 PM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan YOUR-AE066C3A9B\HP_Owner
10/1/2007 19:26:02 PM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\Q7MRODC9\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:25:55 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\rmkhnjar.exe Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:25:53 PM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan Connection terminated YOUR-AE066C3A9B\HP_Owner
10/1/2007 19:17:57 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\qkhrbnrk.dll a variant of Win32/BHO.G trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:14:04 PM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE552R41UJ\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:13:56 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\xooyxolr.exe Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:13:49 PM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan Connection terminated YOUR-AE066C3A9B\HP_Owner
10/1/2007 19:12:13 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\nyixiftf.dll a variant of Win32/BHO.G trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:11:46 PM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\Q7MRODC9\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:11:35 PM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan quarantined - Connection terminated YOUR-AE066C3A9B\HP_Owner
10/1/2007 6:18:34 AM AMON file C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll Win32/Adware.WBug.A application quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred at an attempt to access the file by the application: C:\Documents and Settings\HP_Owner\Desktop\FixVundo.exe.
hijackthis log ————-
Logfile of HijackThis v1.99.1
Scan saved at 4:46:09 PM, on 10/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Eset\nod32kui.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Common Files\AOL\1189882368\ee\AOLSoftware.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\EssNetTools3\Ent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13F815B5-BC6E-43C4-AE05-9EBC2408468C} - (no file)
O2 - BHO: (no name) - {2D624F0B-9EDA-46CD-A29C-B07CCC4A6638} - (no file)
O2 - BHO: (no name) - {3AA3D6F8-D18A-470F-A9EA-DB354A350970} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {73552DCE-4D7F-4D47-93D7-41BB4A9CA501} - (no file)
O2 - BHO: (no name) - {7f9aaf14-478f-4b6b-b0c1-7322427f46ec} - (no file)
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\cwyuldai.dll (file missing)
O2 - BHO: (no name) - {92D4828D-EE1F-4056-A49D-9733885CF4C8} - (no file)
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {B8B6B908-BFB0-4BBE-A940-0094BADF099F} - (no file)
O2 - BHO: (no name) - {D73F0BA8-5E00-4784-9FE8-545BE1D78CA2} - C:\WINDOWS\system32\jkkjk.dll (file missing)
O2 - BHO: (no name) - {DE8BA79A-6281-4795-92EF-5C186D7E2E76} - (no file)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1189882368\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Essential NetTools] C:\Program Files\EssNetTools3\Ent.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: ljjhigh - C:\WINDOWS\
O20 - Winlogon Notify: urqppol - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\oseoqjrm.exe (file missing)
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
a few more logs and events from NOD32 the one in bold worries me
Time Module Object Name Threat Action User Information
10/3/2007 15:53:12 PM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\C5MRCLOF\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/3/2007 15:51:06 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\amnymcjn.exe Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/3/2007 15:50:48 PM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan Connection terminated YOUR-AE066C3A9B\HP_Owner
10/3/2007 7:05:09 AM AMON file C:\WINDOWS\system32\dxlhoaho.dll a variant of Win32/BHO.G trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/2/2007 7:29:32 AM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\O9EZGD6J\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/2/2007 7:29:32 AM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\iepnqxbf.exe Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/2/2007 7:29:31 AM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan YOUR-AE066C3A9B\HP_Owner
10/2/2007 6:29:49 AM AMON file C:\WINDOWS\system32\varapbbx.dll a variant of Win32/BHO.G trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:36:10 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\uetuhxdp.dll a variant of Win32/BHO.G trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\explorer.exe. The file was moved to quarantine. You may close this window.
10/1/2007 19:27:27 PM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\XZ9NXY3H\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\explorer.exe. The file was moved to quarantine. You may close this window.
10/1/2007 19:27:27 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\sutuuiyc.exe Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\explorer.exe. The file was moved to quarantine. You may close this window.
10/1/2007 19:27:27 PM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan YOUR-AE066C3A9B\HP_Owner
10/1/2007 19:26:02 PM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\Q7MRODC9\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:25:55 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\rmkhnjar.exe Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:25:53 PM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan Connection terminated YOUR-AE066C3A9B\HP_Owner
10/1/2007 19:17:57 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\qkhrbnrk.dll a variant of Win32/BHO.G trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:14:04 PM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE552R41UJ\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:13:56 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\xooyxolr.exe Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:13:49 PM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan Connection terminated YOUR-AE066C3A9B\HP_Owner
10/1/2007 19:12:13 PM AMON file C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\nyixiftf.dll a variant of Win32/BHO.G trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:11:46 PM AMON file C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\Q7MRODC9\valera[1] Win32/Agent.BCK trojan quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
10/1/2007 19:11:35 PM IMON file http://82.98.235.78/netob/valera.exe?uid=6…0CA6A391F503BB4 Win32/Agent.BCK trojan quarantined - Connection terminated YOUR-AE066C3A9B\HP_Owner
10/1/2007 6:18:34 AM AMON file C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll Win32/Adware.WBug.A application quarantined - deleted YOUR-AE066C3A9B\HP_Owner Event occurred at an attempt to access the file by the application: C:\Documents and Settings\HP_Owner\Desktop\FixVundo.exe.