This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Kid's Computer infected

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
My daughter's computer appears to be badly infected. It runs so slowly, with so many popups, it is basically disabled. Besides posting the Hijackthis log, I can only add that she uses AIM, Facebook, MySpace and ITunes. Here is the Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 2:06:19 PM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nusrmgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\aim\aim.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\ISM2\ISMPack7.exe
C:\Program Files\ISM\ISMModule8.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\iPod\bin\iPodService.exe
E:\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: COMMUNICATOR - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - C:\WINDOWS\system32\communicator.dll
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: BndShell3 BHO Class - {8ABA9A9C-8791-4d61-8D5B-BCC9448EA573} - C:\Program Files\ISM\BndDrive7.dll
O2 - BHO: BndDrive2 BHO Class - {8B27CC68-110C-46a9-80D3-F3107DE6EB98} - C:\Program Files\ISM\BndDrive3.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: Microsoft copyright - {971D5B7B-F7DF-43ee-B771-6B7FA09975C3} - tcprp.dll (file missing)
O2 - BHO: BndDrive BHO Class - {9815DA81-2E0C-478c-90E4-06E474E704D0} - C:\Program Files\ISM\BndDrive.dll
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: oembios32.msdn_hlp - {D79E1D43-C805-40EF-8ACB-DFFB17E9A4AF} - C:\WINDOWS\system32\oembios32.dll
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: COMMUNICATOR - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - C:\WINDOWS\system32\communicator.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [stb] C:\WINDOWS\System32\stb.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu11.exe 61A847B5BBF72813338B2B27128065E9C084320161C4661227A755E9C2933154389A284662E902BC
ED7286138F75F2F0C8D6E84A1EF604776CA6C1637E744AB97
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - HKCU\..\Run: [Soeal] "C:\Program Files\Common Files\?dobe\w?nlogon.exe"
O4 - HKCU\..\Run: [Jihi] C:\WINDOWS\F?nts\l?gonui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1125335325997
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125335881153
O16 - DPF: {E9670165-86FE-4C34-8C4B-D3158DDC5D92} (Installer Class) - http://downloads.shopathomeselect.com/axin…Install4110.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

I also have the Startuplist if needed. We thank you very much for your consideration.
GracesDad
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.

Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Hello Scotty, Thank you very much for your time and assistance. Here is the uninstall list you asked that I post: Ad-Aware SE Personal Adobe Acrobat 5.0 Adobe Flash Player ActiveX Adobe Shockwave Player AIM 6.0 AOL Coach Version 1.0(Build:20011028.1) AOL Explorer AOL Instant Messenger AOL Uninstaller (Choose which Products to Remove) Apple Mobile Device Support Apple Software Update Avance AC'97 Audio ClueFinders Mystery Mansion Arcade CompuServe Conexant SoftK56 Modem(M) Escape From Horrorland HijackThis 1.99.1 HP Deskjet 3840 HP Software Update ICQ Intel® Extreme Graphics Driver Software Internet Speed Monitor iTunes Java 2 Runtime Environment Standard Edition v1.3.1_02 Logical Journey of the Zoombinis V1.1.0 McAfee Firewall McAfee VirusScan McAfee VirusScan Enterprise Microsoft Money 2002 Microsoft Money 2002 System Pack Microsoft Office XP Professional with FrontPage Microsoft Works 6.0 Microsoft XML Parser and SDK Move Networks Player for Internet Explorer Mozilla Firefox (2.0) MSN Music Assistant MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) Netscape 6 (6.2.1) Print Perfect Deluxe Quick Links QuickTime RealPlayer Basic Related Sites Toolbar Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Spybot - Search & Destroy 1.4 UBCD4Win 3.06 Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Viewpoint Manager (Remove Only) Viewpoint Media Player Winamp (remove only) Windows Backup Utility Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Service Pack 2 WinZip Thanks again, GracesDad
Hi Scotty, Oh sorry. Right after your instruction on Uninstall manager you mentioncutting and pasting it as a reply, so I thought you wanted that before I got the other stuff. I'll get on that now. Thanks very much! GracesDad
Hi Scotty, Well now another problem. I can access the correct screen on startup by pressing F8, but when I try to choose Safe Mode, the up and down keys are not working for some reason, and I seem unable to do anything except let it count down to "start windows normally". Could this be because I havent shut the computer down properly? thanks, GracesDad
HI again Scotty, I browsedthe internet and read that not all systems will allow a USB mouse/keyboard in safe mode. Is it possible that I need a non-USB keyboard?? thanks, GracesDad
Hi Scotty,

My non-usb keyboard worked in Safe mode! Here are the SDFix, Combofix and new Hijackthis files:

SDFix: Version 1.112

Run by [removed] on Sat 10/27/2007 at 06:48 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\Owner\Desktop\SDFix

Safe Mode:
Checking Services:

Name:
runtime

ImagePath:
\??\C:\WINDOWS\System32\drivers\runtime.sys

runtime - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…

Service runtime2 - Deleted after Reboot

Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\system32\.exe - Deleted
C:\3FD.TMP - Deleted
C:\2E7.TMP - Deleted
C:\2E8.TMP - Deleted
C:\2E9.TMP - Deleted
C:\2EA.TMP - Deleted
C:\WINDOWS\retadpu.exe.tmp - Deleted
C:\WINDOWS\retadpu11.exe.tmp - Deleted
C:\WINDOWS\retadpu.exe - Deleted
C:\WINDOWS\retadpu11.exe - Deleted
C:\WINDOWS\retadpu72.exe - Deleted
C:\WINDOWS\system32\.exe - Deleted
C:\WINDOWS\system32\1_exception.nls - Deleted
C:\WINDOWS\system32\rt25.exe - Deleted
C:\WINDOWS\system32\sipov.dll - Deleted
C:\WINDOWS\system32\tcprp.dll - Deleted
C:\WINDOWS\system32\wsnpoem\audio.dll - Deleted
C:\WINDOWS\system32\wsnpoem\video.dll - Deleted
C:\WINDOWS\Temp\startdrv.exe - Deleted
C:\WINDOWS\wr.txt - Deleted
C:\WINDOWS\system32\drivers\runtime2.sys - Deleted
C:\WINDOWS\system32\ntos.exe - Deleted


Folder C:\WINDOWS\system32\wsnpoem - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\aim\\aim.exe"="C:\\Program Files\\aim\\aim.exe:*:Disabled:AOL Instant Messenger"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1127353525\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1127353525\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1127353525\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1127353525\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
—————

File Backups: - C:\DOCUME~1\Owner\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes:

Mon 26 Nov 2001 102,467 A..H. — "C:\Program Files\America Online 7.0\aolphx.exe"
Tue 27 Nov 2001 32,839 A..H. — "C:\Program Files\America Online 7.0\aoltray.exe"
Mon 26 Nov 2001 40,960 A..H. — "C:\Program Files\America Online 7.0\RBM.exe"
Mon 26 Nov 2001 180,287 A..H. — "C:\Program Files\America Online 7.0\waol.exe"
Tue 5 Mar 2002 106,564 A..H. — "C:\Program Files\CompuServe 7.0\csphx.exe"
Tue 5 Mar 2002 32,840 A..H. — "C:\Program Files\CompuServe 7.0\cstray.exe"
Mon 4 Mar 2002 40,960 A..H. — "C:\Program Files\CompuServe 7.0\RBM.exe"
Tue 5 Mar 2002 180,288 A..H. — "C:\Program Files\CompuServe 7.0\wcs2000.exe"
Wed 19 Jul 2006 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 26 Nov 2001 49,221 A..H. — "C:\Program Files\America Online 7.0\COMIT\cswitch.exe"
Tue 5 Mar 2002 77,894 A..H. — "C:\Program Files\CompuServe 7.0\COMIT\cswitch.exe"
Fri 27 Sep 1996 198,144 A..H. — "C:\Program Files\DreamWorks Interactive\Horrorland\setup95.exe"
Mon 4 Dec 2006 1,511 A..H. — "C:\Program Files\Common Files\AOL\IPHSend\IPH.BAK"
Sat 20 Oct 2007 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\573b8bee2d25ffedabde94732ae6dbae\BIT17.tmp"
Thu 25 Oct 2001 106,496 A..H. — "C:\Program Files\Common Files\aolshare\shell\us\shellext.dll"
Wed 12 Dec 2001 102,400 A..H. — "C:\Program Files\Common Files\csshare\shell\us\shellext.dll"

Finished!

ComboFix 07-10-27.4 - Owner 2007-10-27 19:41:34.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.125 [GMT -4:00]
Running from: E:\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.

2007-10-27 19:14 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-27 18:46 d——– C:\WINDOWS\ERUNT
2007-10-27 15:51 18,432 –a—— C:\WINDOWS\fkwggshm.exe
2007-10-27 15:14 12 –a—— C:\WINDOWS\system32\dpqaqlqx.bin
2007-10-27 15:12 123,911 –a—— C:\WINDOWS\system32\vvgeowbv.exe
2007-10-27 15:12 21,504 –a—— C:\WINDOWS\system32\aivskurq.dll
2007-10-27 11:46 218,112 –a—— C:\Program Files\HijackThis.exe
2007-10-22 21:39 d——– C:\UBCD4Win
2007-10-20 18:37 d——– C:\Program Files\iTunes
2007-10-20 17:48 d——– C:\Program Files\Apple Software Update
2007-10-20 13:12 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-20 12:57 d——– C:\WINDOWS\system32\DRVSTORE
2007-10-20 12:57 d——– C:\WINDOWS\system32\acespy
2007-10-20 12:56 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-10-20 12:55 d——– C:\Program Files\The Learning Company
2007-10-07 08:34 d——– C:\Program Files\iTunes(2)
2007-10-01 18:59 d——– C:\Program Files\AntispyStorm
2007-10-01 06:43 4 –a—— C:\WINDOWS\system32\stfv.bin
2007-10-01 06:40 30,464 –a—— C:\WINDOWS\system32\ace16win.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-20 22:38 ——— d—–w C:\Program Files\iPod
2007-10-20 16:57 ——— d—–w C:\Program Files\QuickTime
2007-10-20 16:57 ——— d—–w C:\Program Files\Arcavista
2007-10-20 16:56 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-10-20 16:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-20 16:54 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-20 15:49 ——— d—–w C:\Program Files\Common Files\Network Associates
2007-10-07 23:48 ——— d–h–w C:\Documents and Settings\Owner\Application Data\Move Networks
2007-09-21 19:41 ——— d—–w C:\Program Files\Common Files\Apple
2007-08-31 19:00 ——— d—–w C:\Program Files\BigFix
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-07-30 23:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 23:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 23:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 23:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 23:19 43,352 —-a-w C:\WINDOWS\system32\wups2(2)(2).dll
2007-07-30 23:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 23:19 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-07-30 23:19 207,736 —-a-w C:\WINDOWS\system32\muweb.dll
2007-07-30 23:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 23:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 23:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-07-30 23:18 33,624 —-a-w C:\WINDOWS\system32\wups(2)(2).dll
2006-10-30 02:49 59,728 —-a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
2007-10-27 15:12 21504 –a—— C:\WINDOWS\system32\aivskurq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 11:46]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 13:55]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-08-18 08:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 09:48]
"HostManager"="C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe" [2006-04-20 13:10]
"stb"="C:\WINDOWS\System32\stb.exe" []
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2002-08-01 16:13]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 12:59]
"Alogserv"="C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe" [2002-01-04 06:02]
"McAfee Guardian"="C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" [2001-12-18 02:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-13 16:00]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 11:29]
"AIM"="C:\Program Files\aim\aim.exe" [2005-08-05 15:08]
"McAfee.InstantUpdate.Monitor"="C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" [2002-02-11 00:03]
"Soeal"="C:\Program Files\Common Files\?dobe\w?nlogon.exe" []
"Jihi"="C:\WINDOWS\F?nts\l?gonui.exe" []
"ISMPack7"="C:\Program Files\ISM2\ISMPack7.exe" []
"ISMModule8"="C:\Program Files\ISM\ISMModule8.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-09-28 22:28:40]

R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R2 AvSynMgr;AVSync Manager;"C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe"
R3 NETGEAR NETGEAR_MA101_USB_Adapter®;NETGEAR NETGEAR_MA101_USB_Adapter® Service for NETGEAR MA101 USB Adapter;C:\WINDOWS\system32\DRIVERS\ma1012kr.sys
S3 NaiFiltr;NaiFiltr;C:\WINDOWS\system32\DRIVERS\NaiFiltr.sys
S3 USBFVNETR;NETGEAR MA101 USB Adapter;C:\WINDOWS\system32\DRIVERS\ma101rndxp.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 19:23:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 19:43:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-27 19:44:44
C:\ComboFix2.txt … 2007-10-27 19:23
.
— E O F —

Logfile of HijackThis v1.99.1
Scan saved at 7:47:56 PM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\aim\aim.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Network Associates\VirusScan\MCUPDATE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
E:\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: aivskurq.msdn_hlp - {A6E432B4-D4C2-43B3-BF55-C364F8F7362A} - C:\WINDOWS\system32\aivskurq.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [stb] C:\WINDOWS\System32\stb.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - HKCU\..\Run: [Soeal] "C:\Program Files\Common Files\?dobe\w?nlogon.exe"
O4 - HKCU\..\Run: [Jihi] C:\WINDOWS\F?nts\l?gonui.exe
O4 - HKCU\..\Run: [ISMPack7] "C:\Program Files\ISM2\ISMPack7.exe"
O4 - HKCU\..\Run: [ISMModule8] "C:\Program Files\ISM\ISMModule8.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1125335325997
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125335881153
O16 - DPF: {E9670165-86FE-4C34-8C4B-D3158DDC5D92} (Installer Class) - http://downloads.shopathomeselect.com/axin…Install4110.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Sorry I have taken so long. I have to leave the house for a few hours, but will check back for your reply later tonite. I really appreciate your time and effort. Thanks so much!
GracesDad
Hi


Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\WINDOWS\fkwggshm.exe 
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\system32\aivskurq.dll
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\System32\stb.exe

Folder::
C:\WINDOWS\system32\acespy
C:\Program Files\AntispyStorm
C:\Program Files\Common Files\?dobe
C:\WINDOWS\F?nts

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"stb"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Soeal"=-
"Jihi"=-

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.



Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post with a new HijackThis log.
Hi Scotty,
Below I think I have the 3 things you asked me to post: the Kaspersky log, the new Combofix log, and the new Hijackthis log.

KASPERSKY ONLINE SCANNER REPORT
Sunday, October 28, 2007 6:54:31 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 28/10/2007
Kaspersky Anti-Virus database records: 447696
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 61171
Number of viruses found: 39
Number of infected objects: 183
Number of suspicious objects: 0
Duration of the scan process: 01:29:41

Infected Object Name / Virus Name / Last Action
C:\3A4.tmp/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\3A4.tmp NSIS: infected - 1 skipped
C:\3A5.tmp/stream/data0002 Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\3A5.tmp/stream/data0003 Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\3A5.tmp/stream Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\3A5.tmp NSIS: infected - 3 skipped
C:\3A6.tmp Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\77D.tmp/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\77D.tmp NSIS: infected - 1 skipped
C:\77E.tmp/stream/data0002 Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\77E.tmp/stream/data0003 Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\77E.tmp/stream Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\77E.tmp NSIS: infected - 3 skipped
C:\77F.tmp Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_EMACHINES.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_EMACHINES.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\UpdateLog.txt Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/.exe Infected: Trojan-Dropper.Win32.VB.tg skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/3FD.tmp Infected: Trojan-Spy.Win32.Zbot.bk skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/retadpu.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/retadpu.exe.tmp Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/retadpu11.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/retadpu11.exe.tmp Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/retadpu72.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/rt25.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/sipov.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/startdrv.exe Infected: Trojan-Downloader.Win32.Agent.eoa skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/tcprp.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip ZIP: infected - 11 skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\qoobox\Quarantine\C\Program Files\AntispyStorm\uninstall.exe.vir/EXE-file Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\qoobox\Quarantine\C\Program Files\AntispyStorm\uninstall.exe.vir Embedded EXE: infected - 1 skipped
C:\qoobox\Quarantine\C\Program Files\AntispyStorm\uninstall.exe.vir UPX: infected - 1 skipped
C:\qoobox\Quarantine\C\Program Files\ISM\BndDrive.dll.vir Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\qoobox\Quarantine\C\Program Files\ISM\BndDrive3.dll.vir Infected: not-a-virus:AdWare.Win32.AdBand.c skipped
C:\qoobox\Quarantine\C\Program Files\ISM\bndloader.exe.vir Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\qoobox\Quarantine\C\Program Files\ISM2\cringupd.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\qoobox\Quarantine\C\Program Files\ISM2\cringupd.exe.vir NSIS: infected - 1 skipped
C:\qoobox\Quarantine\C\Program Files\ISM2\ISMPack7.exe.vir Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\qoobox\Quarantine\C\WINDOWS\fkwggshm.exe.vir Infected: Trojan.Win32.VB.azo skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\aivskurq.dll.vir Infected: Trojan-Downloader.Win32.VB.bpt skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir/InpB/SskBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir/InpB/SskCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.aa skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.aa skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir/InpB/Ssk3RepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir CAB: infected - 5 skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\communicator.dll.vir Infected: not-a-virus:AdWare.Win32.MegaSearch.k skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\nusrmgr.exe.vir Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\oembios32.dll.vir Infected: Trojan-Downloader.Win32.VB.bkb skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\qlink32.dll.vir Infected: not-a-virus:AdWare.Win32.Suggestor.r skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\REPAIR~1.DLL.vir Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vvgeowbv.exe.vir Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\qoobox\Quarantine\C\WINDOWS\winh32.exe.vir Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP726\A0080080.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP726\A0080083.exe Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP731\A0080132.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gd skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP731\A0080133.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gc skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP744\A0081371.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP746\A0081402.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP746\A0081420.exe Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP760\A0081503.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP764\A0081524.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP769\A0082292.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ft skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP769\A0082293.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ga skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP769\A0082295.dll Infected: not-a-virus:AdWare.Win32.PurityScan.fs skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0082442.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0083472.exe Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0083484.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0083486.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0083486.exe Embedded EXE: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0083486.exe UPX: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP781\A0083510.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP782\A0083536.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP783\A0083563.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP784\A0084586.exe Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP784\A0085586.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085650.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085687.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085687.exe Embedded EXE: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085687.exe UPX: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085857.dll Infected: Trojan-Downloader.Win32.VB.bkb skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085860.exe Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085861.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085862.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085863.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0086136.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0086146.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ft skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0086147.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ga skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0086149.dll Infected: not-a-virus:AdWare.Win32.PurityScan.fs skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP786\A0086360.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP792\A0086469.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP792\A0086485.exe Infected: not-a-virus:AdWare.Win32.Agent.jn skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP797\A0086801.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP802\A0086940.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP809\A0087021.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP811\A0087042.exe Infected: Trojan.Win32.Small.rv skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP812\A0087044.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087193.exe Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087194.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087194.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087194.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087208.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087261.dll Infected: Trojan-Downloader.Win32.VB.bkb skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087264.exe Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087266.dll Infected: Trojan-Spy.Win32.Agent.ags skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087274.exe Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087278.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087292.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087452.exe Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087458.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087792.dll Infected: not-a-virus:AdWare.Win32.AdBand.b skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087793.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.AdBand.b skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087793.exe/stream Infected: not-a-virus:AdWare.Win32.AdBand.b skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087793.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087795.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0088083.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0088084.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.jn skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0088084.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP814\A0088623.exe Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP814\A0088644.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP815\A0088688.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP816\A0088690.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP817\A0088776.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103526.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103527.exe Infected: Trojan-Dropper.Win32.VB.tg skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103528.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103529.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103530.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103531.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103532.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103533.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103542.exe Infected: Trojan-Dropper.Win32.VB.tg skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103544.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103545.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103546.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103547.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103548.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103549.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103590.sys Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103591.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103591.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103593.exe Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103604.dll Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103607.dll Infected: not-a-virus:AdWare.Win32.AdBand.c skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103609.exe Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe/InpB/SskBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe/InpB/SskCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.aa skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.aa skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe/InpB/Ssk3RepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe CAB: infected - 5 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103619.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.k skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103622.dll Infected: not-a-virus:AdWare.Win32.Suggestor.r skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103623.dll Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103669.dll Infected: Trojan-Downloader.Win32.VB.bkb skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103670.exe Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103671.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103911.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103911.exe Embedded EXE: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103911.exe UPX: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103914.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103916.dll Infected: Trojan-Downloader.Win32.VB.bpt skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103917.exe Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP828\change.log Object is locked skipped
C:\UBCD4Win\plugin\Network\ipscan\ipscan.exe Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\UBCD4Win\plugin\Network\ultravnc\files\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\UBCD4Win\plugin\Network\ultravnc\files\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
C:\UBCD4Win\plugin\Network\ultravnc\files\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\UBCD4Win\plugin\Network\VNCServer\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\UBCD4Win\plugin\Network\VNCServer\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\UBCD4Win\plugin\Network\VNCServer\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\UBCD4Win\plugin\Network\VNCServer\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\UBCD4Win\plugin\System-Info\Information\keyfinderpe\keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\UBCD4Win\plugin\System-Info\Information\keyfinderpe\keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\UBCD4Win\plugin\System-Info\Information\keyfinderpe\keyfinder.exe RarSFX: infected - 2 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\UBCD4WinV306.exe/file3145 Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
E:\UBCD4WinV306.exe/file3324 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
E:\UBCD4WinV306.exe/file3326 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
E:\UBCD4WinV306.exe/file3329 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
E:\UBCD4WinV306.exe/file3382 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
E:\UBCD4WinV306.exe/file3385 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
E:\UBCD4WinV306.exe/file3386 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
E:\UBCD4WinV306.exe/file3387 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
E:\UBCD4WinV306.exe/file3587/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\UBCD4WinV306.exe/file3587/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\UBCD4WinV306.exe/file3587 Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\UBCD4WinV306.exe Inno: infected - 11 skipped

Scan process completed.

File::
C:\WINDOWS\fkwggshm.exe
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\system32\aivskurq.dll
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\System32\stb.exe

Folder::
C:\WINDOWS\system32\acespy
C:\Program Files\AntispyStorm
C:\Program Files\Common Files\?dobe
C:\WINDOWS\F?nts

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"stb"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Soeal"=-
"Jihi"=-


Logfile of HijackThis v1.99.1
Scan saved at 6:57:04 PM, on 10/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\aim\aim.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Network Associates\VirusScan\MCUPDATE.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aol\aol toolbar 3.1\aoltbhelper.exe
E:\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - HKCU\..\Run: [ISMPack7] "C:\Program Files\ISM2\ISMPack7.exe"
O4 - HKCU\..\Run: [ISMModule8] "C:\Program Files\ISM\ISMModule8.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1125335325997
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125335881153
O16 - DPF: {E9670165-86FE-4C34-8C4B-D3158DDC5D92} (Installer Class) - http://downloads.shopathomeselect.com/axin…Install4110.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Hope I got this right! Thanks very much,
GracesDad
Hello What you have post is the CFScript Id written up. You had to copy that into Notepad to create a text file then drag that file onto the Combofix icon. A log the same as the first Combo log will be produced. That's the log I need to see.
Hi Scotty,
Sorry about the mistake. Here, I think, is the correct combo log:
ComboFix 07-10-29.1 - Owner 2007-10-29 18:04:52.9 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.144 [GMT -4:00]
Running from: E:\ComboFix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\fkwggshm.exe
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\aivskurq.dll
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\System32\stb.exe
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\vvgeowbv.exe
.

((((((((((((((((((((((((( Files Created from 2007-09-28 to 2007-10-29 )))))))))))))))))))))))))))))))
.

2007-10-28 17:01 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-10-28 17:01 d——– C:\WINDOWS\LastGood
2007-10-28 17:01 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-27 19:14 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-27 18:46 d——– C:\WINDOWS\ERUNT
2007-10-27 11:46 218,112 –a—— C:\Program Files\HijackThis.exe
2007-10-22 21:39 d——– C:\UBCD4Win
2007-10-20 18:37 d——– C:\Program Files\iTunes
2007-10-20 17:48 d——– C:\Program Files\Apple Software Update
2007-10-20 13:12 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-20 12:57 d——– C:\WINDOWS\system32\DRVSTORE
2007-10-20 12:56 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-10-20 12:55 d——– C:\Program Files\The Learning Company
2007-10-07 08:34 d——– C:\Program Files\iTunes(2)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-20 22:38 ——— d—–w C:\Program Files\iPod
2007-10-20 16:57 ——— d—–w C:\Program Files\QuickTime
2007-10-20 16:57 ——— d—–w C:\Program Files\Arcavista
2007-10-20 16:56 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-10-20 16:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-20 16:54 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-20 15:49 ——— d—–w C:\Program Files\Common Files\Network Associates
2007-10-07 23:48 ——— d–h–w C:\Documents and Settings\Owner\Application Data\Move Networks
2007-09-21 19:41 ——— d—–w C:\Program Files\Common Files\Apple
2007-08-31 19:00 ——— d—–w C:\Program Files\BigFix
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-07-30 23:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 23:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 23:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 23:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 23:19 43,352 —-a-w C:\WINDOWS\system32\wups2(2)(2).dll
2007-07-30 23:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 23:19 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-07-30 23:19 207,736 —-a-w C:\WINDOWS\system32\muweb.dll
2007-07-30 23:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 23:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 23:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-07-30 23:18 33,624 —-a-w C:\WINDOWS\system32\wups(2)(2).dll
2006-10-30 02:49 59,728 —-a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 11:46]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 13:55]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-08-18 08:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 09:48]
"HostManager"="C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe" [2006-04-20 13:10]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2002-08-01 16:13]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 12:59]
"Alogserv"="C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe" [2002-01-04 06:02]
"McAfee Guardian"="C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" [2001-12-18 02:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-13 16:00]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 11:29]
"AIM"="C:\Program Files\aim\aim.exe" [2005-08-05 15:08]
"McAfee.InstantUpdate.Monitor"="C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" [2002-02-11 00:03]
"ISMPack7"="C:\Program Files\ISM2\ISMPack7.exe" []
"ISMModule8"="C:\Program Files\ISM\ISMModule8.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-09-28 22:28:40]

R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R2 AvSynMgr;AVSync Manager;"C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe"
R3 NETGEAR NETGEAR_MA101_USB_Adapter®;NETGEAR NETGEAR_MA101_USB_Adapter® Service for NETGEAR MA101 USB Adapter;C:\WINDOWS\system32\DRIVERS\ma1012kr.sys
S3 NaiFiltr;NaiFiltr;C:\WINDOWS\system32\DRIVERS\NaiFiltr.sys
S3 USBFVNETR;NETGEAR MA101 USB Adapter;C:\WINDOWS\system32\DRIVERS\ma101rndxp.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 19:23:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-29 18:06:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-29 18:07:28
C:\ComboFix2.txt … 2007-10-29 17:56
C:\ComboFix3.txt … 2007-10-28 16:56
.
— E O F —

and the new Hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 6:33:25 PM, on 10/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\aim\aim.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Network Associates\VirusScan\MCUPDATE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
E:\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - HKCU\..\Run: [ISMPack7] "C:\Program Files\ISM2\ISMPack7.exe"
O4 - HKCU\..\Run: [ISMModule8] "C:\Program Files\ISM\ISMModule8.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1125335325997
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125335881153
O16 - DPF: {E9670165-86FE-4C34-8C4B-D3158DDC5D92} (Installer Class) - http://downloads.shopathomeselect.com/axin…Install4110.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Hope this is correct. Thanks as always,
GracesDad
Hi

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself and let me know what you want to do.



Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\3A4.tmp 
C:\3A5.tmp
C:\3A6.tmp
C:\77D.tmp
C:\77E.tmp
C:\77F.tmp

Folder::
C:\Documents and Settings\Owner\Desktop\SDFix

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - (no file)
O16 - DPF: {E9670165-86FE-4C34-8C4B-D3158DDC5D92} (Installer Class) - http://downloads.shopathomeselect.com/axin…Install4110.cab


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.


Reboot the computer and scan with HijackThis again and post the new log.
Hi Scotty, here is the latest Combofix log you asked for. I'll post again shortly with the new Hijack log you requested. Oh also, I will uninstall Viewpoint or whatever components of it you think should be uninstalled. Is there anything I need to know about the uninstall? Thanks alot! Her computer is running so much better! GracesDad

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI