This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected with Adware.Agent.BN

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello

I've been infected with Adware.Agent.BN.
I've run Norton, Avg and Spyware Doctor
( Spyware Doctor is the only one that seems to find it)
But it returns immediately.

Any help will be much appreciated.

———————————————————————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:06:05 AM, on 11/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\windows\explorer.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=c:\windows\explorer.exe
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrPanelICON] C:\Program Files\Launch Manager\PanelICON.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 10987 bytes
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.

Download and Save ComboFix
  • Download this file from below:

    Here
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Adobe Flash Player 9 ActiveX
Adobe Reader 8.1.0
Adobe® Photoshop® Album Starter Edition 3.2
Apple Mobile Device Support
Apple Software Update
ATI Control Panel
ATI Display Driver
AVG Anti-Spyware 7.5
AVManager V1.1.0.7
Brother MFL-Pro Suite
CopyToDVD
DVD43 v3.9.0
ffdshow [rev 1524] [2007-10-09]
FLV Player
GetDataBack for FAT and GetDataBack for NTFS
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Updater
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Intel® PROSet/Wireless Software
iTunes
Java™ 6 Update 2
Java™ 6 Update 3
Launch Manager V1.1.9
LimeWire PRO 4.14.10
LiveUpdate 3.0 (Symantec Corporation)
Magic DVD Copier V4.6
mCore
mDriver
mDrWiFi
mHelp
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Expression Web
Microsoft Expression Web
Microsoft Expression Web MUI (English)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft User-Mode Driver Framework Feature Pack 1.0
mIWA
mLogView
mMHouse
Mozilla Firefox (2.0.0.8)
mPfMgr
mPfWiz
mProSafe
MSXML 4.0 SP2 (KB936181)
mWlsSafe
mXML
mZConfig
Nokia Connectivity Cable Driver
Nokia PC Connectivity Solution
Nokia PC Suite
Norton Security Scan
Orbit
Playlist Editor
PowerDVD
QuickTime
RegCure 1.5.0.0
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Excel 2007 (KB936509)
Security Update for Office 2007 (KB934062)
Security Update for Office 2007 (KB934062)
Security Update for Office 2007 (KB936514)
Security Update for Publisher 2007 (KB936646)
Security Update for the 2007 Microsoft Office System (KB936960)
Security Update for the 2007 Microsoft Office System (KB936960)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Spyware Doctor 5.1
SUPER © Version 2007.bld.23 (July 4, 2007)
Symantec AntiVirus
Update for Office 2007 (KB932080)
Update for Office 2007 (KB932080)
Update for Office 2007 (KB934391)
Update for Office 2007 (KB934391)
Update for Office 2007 (KB934393)
Update for Office 2007 (KB934393)
Update for Outlook 2007 (KB937608)
Update for Outlook 2007 Junk Email Filter (kb942575)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Word 2007 (KB934173)
Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver
Yahoo! Messenger


———————————————————————————————————-
———————————————————————————————————-

SDFIX

SDFix: Version 1.113

Run by [removed] on Tue 11/06/2007 at 12:05 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\dat.txt - Deleted
C:\WINDOWS\rs.txt - Deleted



Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1253 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-06 12:11:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"="C:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe:*:Enabled:iMesh"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\FileZilla\\FileZilla.exe"="C:\\Program Files\\FileZilla\\FileZilla.exe:*:Enabled:FileZilla"
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"="C:\\Program Files\\Orbitdownloader\\orbitnet.exe:*:Enabled:P2P service of Orbit Downloader"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Thu 18 Oct 2007 24 A.SH. — "C:\WINDOWS\S824E6DD3.tmp"
Wed 13 Oct 2004 1,694,208 ..SH. — "C:\Program Files\Messenger\msmsgs.exe"
Wed 3 May 2006 163,328 ..SHR — "C:\WINDOWS\system32\flvDX.dll"
Wed 21 Feb 2007 31,232 ..SHR — "C:\WINDOWS\system32\msfDX.dll"
Sun 26 Jun 2005 616,448 ..SHR — "C:\Program Files\eRightSoft\SUPER\cygwin1.dll"
Tue 21 Jun 2005 45,568 ..SHR — "C:\Program Files\eRightSoft\SUPER\cygz.dll"
Mon 22 Oct 2007 72,704 ..SHR — "C:\Program Files\eRightSoft\SUPER\Setup.exe"
Tue 16 Oct 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 6 Nov 2007 0 A..H. — "C:\Documents and Settings\Klaus Kavindele\Local Settings\Temp\BITE4.tmp"
Tue 6 Nov 2007 0 A..H. — "C:\Documents and Settings\Klaus Kavindele\Local Settings\Temp\BITE6.tmp"
Tue 4 Jun 2002 84,992 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll"
Tue 4 Jun 2002 44,032 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll"
Tue 10 Dec 2002 73,766 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll"
Tue 10 Dec 2002 65,575 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll"
Sun 9 Jun 2002 36,864 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\ddnt3260.dll"
Tue 4 Jun 2002 20,480 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll"
Tue 10 Dec 2002 102,437 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv13260.dll"
Tue 10 Dec 2002 176,165 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll"
Tue 10 Dec 2002 208,935 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll"
Tue 10 Dec 2002 217,127 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll"
Sun 9 Jun 2002 40,448 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\dspr3260.dll"
Sat 3 Nov 2001 225,280 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll"
Tue 10 Apr 2001 225,280 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll"
Fri 20 Feb 2004 232,960 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll"
Sun 9 Jun 2002 525,824 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rnco3260.dll"
Tue 10 Dec 2002 245,805 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rnlt3260.dll"
Tue 10 Dec 2002 45,093 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rv103260.dll"
Tue 10 Dec 2002 98,341 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rv203260.dll"
Tue 10 Dec 2002 94,247 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rv303260.dll"
Tue 10 Dec 2002 90,151 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rv403260.dll"
Tue 10 Dec 2002 102,439 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll"
Sun 9 Jun 2002 49,152 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\tokr3260.dll"
Wed 17 Oct 2007 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download

———————————————————————————————————————————————-
———————————————————————————————————————————————-

COMBOFIX LOG

ComboFix 07-11-06.4 - Klaus 2007-11-06 12:24:53.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.127 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Klaus\Application Data\inst.exe
C:\WINDOWS\Help\access.cni
C:\WINDOWS\nview.dll
C:\WINDOWS\system32\drivers\atmapi.sys

.
((((((((((((((((((((((((( Files Created from 2007-10-06 to 2007-11-06 )))))))))))))))))))))))))))))))
.

2007-11-06 12:22 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-06 12:04 d——– C:\WINDOWS\ERUNT
2007-11-04 19:02 d——– C:\Documents and Settings\Klaus Kavindele\Phone Browser
2007-11-04 19:02 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Datalayer
2007-11-04 19:00 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Nokia
2007-11-04 18:43 d——– C:\Program Files\DIFX
2007-11-04 18:42 d——– C:\Program Files\Common Files\PCSuite
2007-11-04 18:42 d——– C:\Program Files\Common Files\Nokia
2007-11-04 18:42 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\PC Suite
2007-11-04 18:42 d——– C:\Documents and Settings\All Users\Application Data\PC Suite
2007-11-04 18:42 127,488 –a—— C:\WINDOWS\system32\drivers\nmwcd.sys
2007-11-04 18:42 50,688 –a—— C:\WINDOWS\system32\nmwcdcls.dll
2007-11-04 18:42 30,720 –a—— C:\WINDOWS\system32\nmwcdcocls.dll
2007-11-04 18:42 13,312 –a—— C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-11-04 18:42 13,312 –a—— C:\WINDOWS\system32\drivers\nmwcdcj.sys
2007-11-04 18:42 8,704 –a—— C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-11-04 18:42 4,608 –a—— C:\WINDOWS\system32\nmwcdlog.dll
2007-11-04 18:41 d——– C:\Program Files\Nokia
2007-11-04 18:41 d——– C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-11-02 12:16 d——– C:\Program Files\Spyware Doctor
2007-11-02 12:16 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\PC Tools
2007-11-02 12:16 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-02 12:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-02 12:16 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-02 12:16 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-02 12:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-11-02 11:13 d——– C:\Program Files\LimeWire
2007-11-02 11:12 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\updater
2007-10-30 20:30 d——– C:\Program Files\Norton Security Scan
2007-10-30 20:03 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2007-10-30 20:03 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-10-30 20:03 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-10-30 20:03 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-10-30 20:03 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2007-10-30 19:44 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-30 19:43 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-10-29 22:15 d——– C:\Program Files\MagicDVDCopier
2007-10-29 18:15 d——– C:\Program Files\Trend Micro
2007-10-29 18:00 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Grisoft
2007-10-29 17:59 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-29 17:59 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-28 18:55 3,168 –a—— C:\WINDOWS\system32\tmp.reg
2007-10-27 22:13 87,608 –a—— C:\Documents and Settings\Klaus Kavindele\Application Data\ezpinst.exe
2007-10-27 20:56 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\CopyToDvd
2007-10-25 22:11 d——– C:\Program Files\Common Files\Download Manager
2007-10-23 00:05 d——– C:\Program Files\FLV Player
2007-10-23 00:05 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\GetRightToGo
2007-10-23 00:05 411,248 –a—— C:\Program Files\FLV PlayerRCSetup.exe
2007-10-22 23:36 d——– C:\Program Files\Orbitdownloader
2007-10-22 23:36 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Orbit
2007-10-22 23:32 d——– C:\WINDOWS\FLV Player
2007-10-22 23:21 0 –a—— C:\WINDOWS\nsreg.dat
2007-10-22 23:08 d——– C:\Program Files\AviSynth 2.5
2007-10-22 22:58 d——– C:\Program Files\eRightSoft
2007-10-22 22:58 163,328 -r-hs—- C:\WINDOWS\system32\flvDX.dll
2007-10-22 22:58 31,232 -r-hs—- C:\WINDOWS\system32\msfDX.dll
2007-10-22 21:47 d——– C:\Downloads
2007-10-22 20:25 d——– C:\VAZ_BACKUP
2007-10-20 21:04 d——– C:\Documents and Settings\All Users\Application Data\vsosdk
2007-10-20 20:00 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2007-10-20 18:46 d——– C:\Program Files\FriendBlasterPro
2007-10-20 18:15 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Apple Computer
2007-10-20 18:14 d——– C:\Program Files\iTunes
2007-10-20 18:14 d——– C:\Program Files\iPod
2007-10-20 18:13 d——– C:\Program Files\QuickTime
2007-10-20 18:13 d——– C:\Program Files\Common Files\Apple
2007-10-20 18:13 d——– C:\Program Files\Apple Software Update
2007-10-20 18:13 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-20 18:13 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-10-20 05:40 50 –a—— C:\WINDOWS\system32\BRIDF04A.dat
2007-10-20 05:28 d——– C:\Program Files\Brother
2007-10-20 05:26 d——– C:\Documents and Settings\All Users\Application Data\Brother
2007-10-20 04:59 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-10-20 04:59 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-10-20 04:59 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-10-20 04:59 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-10-20 02:18 d——– C:\Program Files\Runtime Software
2007-10-20 00:19 18,816 –a—— C:\WINDOWS\system32\drivers\dvd43llh.sys
2007-10-19 21:00 d——– C:\WINDOWS\Sun
2007-10-19 18:06 d——– C:\Program Files\dvd43
2007-10-19 17:52 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Vso
2007-10-19 17:52 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
2007-10-19 17:52 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-10-19 17:52 47,360 –a—— C:\Documents and Settings\Klaus Kavindele\Application Data\pcouffin.sys
2007-10-18 18:02 d——– C:\Documents and Settings\Klaus Kavindele\Contacts
2007-10-18 18:00 d——– C:\Program Files\MSN Messenger
2007-10-18 17:39 6,058,496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-18 15:20 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-18 11:13 d——– C:\Program Files\MSXML 4.0
2007-10-18 09:04 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-10-18 07:37 d——– C:\Program Files\RegCure
2007-10-18 06:14 d——– C:\Documents and Settings\NetworkService\Application Data\Intel
2007-10-18 05:27 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\1ClickDVDCopy
2007-10-18 04:54 d——– C:\Documents and Settings\All Users\Application Data\SlySoft
2007-10-18 04:31 d——– C:\Program Files\vso
2007-10-18 04:01 d——– C:\Documents and Settings\Klaus Kavindele\Shared
2007-10-18 04:01 d——– C:\Documents and Settings\Klaus Kavindele\Incomplete
2007-10-18 04:01 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\LimeWire
2007-10-18 03:51 d——– C:\Program Files\Common Files\Java
2007-10-18 03:42 d——– C:\Program Files\iMesh Applications

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-27 21:15 0 —-a-w C:\WINDOWS\system32\drivers\ASPI2K.ADP
2007-10-16 05:11 ——— d—–w C:\Program Files\microsoft frontpage
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-14 01:54 413,696 —-a-w C:\WINDOWS\system32\vbscript.dll
2007-08-14 01:54 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
2007-08-14 01:45 78,336 —-a-w C:\WINDOWS\system32\ieencode.dll
2007-08-14 01:44 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-14 01:39 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
2007-08-14 01:39 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
2007-08-14 01:36 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
2007-08-14 01:32 45,568 —-a-w C:\WINDOWS\system32\mshta.exe
2007-08-14 01:01 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
2007-08-13 18:42 17,408 —-a-w C:\WINDOWS\system32\corpol.dll
2006-05-03 09:06:54 163,328 –sh–r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 –sh–r C:\WINDOWS\system32\msfDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-07 20:02]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-03-17 13:34]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-05 00:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-12-12 18:31]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 08:07]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-03 04:50]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 21:34 C:\WINDOWS\SOUNDMAN.EXE]
"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2003-05-12 21:28]
"HotkeyApp"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2003-10-03 16:11]
"CtrlVol"="C:\Program Files\Launch Manager\CtrlVol.exe" [2003-09-16 21:28]
"LMgrPanelICON"="C:\Program Files\Launch Manager\PanelICON.exe" [2003-09-24 23:37]
"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2003-09-12 22:24]
"AVManager"="C:\Program Files\Wistron\AVManager\AVManager.exe" [2003-10-17 09:41]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 08:11]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-31 00:43]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-30 20:29]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-02 12:16:07]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

R1 Hotkey;Hotkey;C:\WINDOWS\system32\drivers\Hotkey.sys
R2 BBFat.VxD;BlueBird DSP API;C:\WINDOWS\system32\Drivers\BBFat.sys
S1 Wbutton;Wbutton;C:\WINDOWS\system32\drivers\Wbutton.sys
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\Drivers\BrScnUsb.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-06 09:07:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-02 17:38:32 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2007-11-06 12:32:24 C:\WINDOWS\Tasks\RegCure Program Check.job"
"2007-10-18 10:00:40 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2007-11-06 12:32:27 C:\WINDOWS\Tasks\XoftSpySE 2.job"
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-06 12:30:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-06 12:33:52 - machine was rebooted
.
— E O F —

———————————————————————————————————————————–
———————————————————————————————————————————–

NEW HIJACKTHIS LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:42:42 PM, on 11/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrPanelICON] C:\Program Files\Launch Manager\PanelICON.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Download; by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab; video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload; selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load; all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 10748 bytes
Hi

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\SrchSTS.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\Tasks\RegCure Program Check.job
C:\WINDOWS\Tasks\RegCure.job
C:\WINDOWS\Tasks\XoftSpySE 2.job

Folder::
C:\Program Files\Runtime Software 
C:\Program Files\RegCure

DirLook::
C:\Documents and Settings\Klaus Kavindele\Application Data\updater

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post with a new HijackThis log.
With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete.
ComboFix 07-11-06.4 - Klaus Kavindele 2007-11-07 7:41:21.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.175 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Klaus Kavindele\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\SrchSTS.exe
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\Tasks\RegCure Program Check.job
C:\WINDOWS\Tasks\RegCure.job
C:\WINDOWS\Tasks\XoftSpySE 2.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\RegCure
C:\Program Files\RegCure\0_days.htm
C:\Program Files\RegCure\1_days.htm
C:\Program Files\RegCure\15_days.htm
C:\Program Files\RegCure\2_days.htm
C:\Program Files\RegCure\30_days.htm
C:\Program Files\RegCure\5_days.htm
C:\Program Files\RegCure\Animated-Bar.gif
C:\Program Files\RegCure\AutoUpdate.dll
C:\Program Files\RegCure\buttonfill.jpg
C:\Program Files\RegCure\buttonfill_expire.jpg
C:\Program Files\RegCure\buttonfill_mo.jpg
C:\Program Files\RegCure\buttonfill_mo_expire.jpg
C:\Program Files\RegCure\config.xml
C:\Program Files\RegCure\contentwrapper.gif
C:\Program Files\RegCure\expire.css
C:\Program Files\RegCure\footerbar.gif
C:\Program Files\RegCure\help.chm
C:\Program Files\RegCure\info_bubble.jpg
C:\Program Files\RegCure\Logs\Regcure-18-10-07-00-40-45.zip
C:\Program Files\RegCure\Logs\Regcure-25-10-07-23-25-41.zip
C:\Program Files\RegCure\Logs\Regcure-28-10-07-17-08-02.zip
C:\Program Files\RegCure\Logs\SystemInfo.zip
C:\Program Files\RegCure\LogSettings.xml
C:\Program Files\RegCure\main.css
C:\Program Files\RegCure\process-animation.gif
C:\Program Files\RegCure\RegCure.exe
C:\Program Files\RegCure\settings.xml
C:\Program Files\RegCure\subtitlebar.gif
C:\Program Files\RegCure\tile_titlebar.jpg
C:\Program Files\RegCure\Tip1.html
C:\Program Files\RegCure\Tip10.html
C:\Program Files\RegCure\Tip11.html
C:\Program Files\RegCure\Tip12.html
C:\Program Files\RegCure\Tip13.html
C:\Program Files\RegCure\Tip14.html
C:\Program Files\RegCure\Tip15.html
C:\Program Files\RegCure\Tip2.html
C:\Program Files\RegCure\Tip3.html
C:\Program Files\RegCure\Tip4.html
C:\Program Files\RegCure\Tip5.html
C:\Program Files\RegCure\Tip6.html
C:\Program Files\RegCure\Tip7.html
C:\Program Files\RegCure\Tip8.html
C:\Program Files\RegCure\Tip9.html
C:\Program Files\RegCure\uninst.exe
C:\Program Files\RegCure\whitelist.dat
C:\Program Files\RegCure\zlibwapi.dll
C:\Program Files\Runtime Software
C:\Program Files\Runtime Software\GetDataBack for NTFS\DRV16.DLL
C:\Program Files\Runtime Software\GetDataBack for NTFS\gdb_nt.chm
C:\Program Files\Runtime Software\GetDataBack for NTFS\gdb_nt_deu.chm
C:\Program Files\Runtime Software\GetDataBack for NTFS\gdbnt.DEU
C:\Program Files\Runtime Software\GetDataBack for NTFS\gdbnt.exe
C:\Program Files\Runtime Software\GetDataBack for NTFS\gdbnt.ini
C:\Program Files\Runtime Software\GetDataBack\DRV16.DLL
C:\Program Files\Runtime Software\GetDataBack\gdb.DEU
C:\Program Files\Runtime Software\GetDataBack\gdb.exe
C:\Program Files\Runtime Software\GetDataBack\gdb.ini
C:\Program Files\Runtime Software\GetDataBack\gdb_fat.chm
C:\Program Files\Runtime Software\GetDataBack\gdb_fat_deu.chm
C:\WINDOWS\system32\SrchSTS.exe
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\Tasks\RegCure Program Check.job
C:\WINDOWS\Tasks\RegCure.job
C:\WINDOWS\Tasks\XoftSpySE 2.job

.
((((((((((((((((((((((((( Files Created from 2007-10-07 to 2007-11-07 )))))))))))))))))))))))))))))))
.

2007-11-06 12:22 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-06 12:04 d——– C:\WINDOWS\ERUNT
2007-11-04 19:02 d——– C:\Documents and Settings\Klaus Kavindele\Phone Browser
2007-11-04 19:02 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Datalayer
2007-11-04 19:00 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Nokia
2007-11-04 18:43 d——– C:\Program Files\DIFX
2007-11-04 18:42 d——– C:\Program Files\Common Files\PCSuite
2007-11-04 18:42 d——– C:\Program Files\Common Files\Nokia
2007-11-04 18:42 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\PC Suite
2007-11-04 18:42 d——– C:\Documents and Settings\All Users\Application Data\PC Suite
2007-11-04 18:42 127,488 –a—— C:\WINDOWS\system32\drivers\nmwcd.sys
2007-11-04 18:42 50,688 –a—— C:\WINDOWS\system32\nmwcdcls.dll
2007-11-04 18:42 30,720 –a—— C:\WINDOWS\system32\nmwcdcocls.dll
2007-11-04 18:42 13,312 –a—— C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-11-04 18:42 13,312 –a—— C:\WINDOWS\system32\drivers\nmwcdcj.sys
2007-11-04 18:42 8,704 –a—— C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-11-04 18:42 4,608 –a—— C:\WINDOWS\system32\nmwcdlog.dll
2007-11-04 18:41 d——– C:\Program Files\Nokia
2007-11-04 18:41 d——– C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-11-02 12:16 d——– C:\Program Files\Spyware Doctor
2007-11-02 12:16 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\PC Tools
2007-11-02 12:16 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-02 12:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-02 12:16 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-02 12:16 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-02 12:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-11-02 11:13 d——– C:\Program Files\LimeWire
2007-11-02 11:12 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\updater
2007-10-30 20:30 d——– C:\Program Files\Norton Security Scan
2007-10-30 20:03 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-10-30 20:03 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-10-30 19:44 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-30 19:43 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-10-29 22:15 d——– C:\Program Files\MagicDVDCopier
2007-10-29 18:15 d——– C:\Program Files\Trend Micro
2007-10-29 18:00 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Grisoft
2007-10-29 17:59 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-29 17:59 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-28 18:55 3,168 –a—— C:\WINDOWS\system32\tmp.reg
2007-10-27 22:13 87,608 –a—— C:\Documents and Settings\Klaus Kavindele\Application Data\ezpinst.exe
2007-10-27 20:56 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\CopyToDvd
2007-10-25 22:11 d——– C:\Program Files\Common Files\Download Manager
2007-10-23 00:05 d——– C:\Program Files\FLV Player
2007-10-23 00:05 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\GetRightToGo
2007-10-23 00:05 411,248 –a—— C:\Program Files\FLV PlayerRCSetup.exe
2007-10-22 23:36 d——– C:\Program Files\Orbitdownloader
2007-10-22 23:36 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Orbit
2007-10-22 23:32 d——– C:\WINDOWS\FLV Player
2007-10-22 23:21 0 –a—— C:\WINDOWS\nsreg.dat
2007-10-22 23:08 d——– C:\Program Files\AviSynth 2.5
2007-10-22 22:58 d——– C:\Program Files\eRightSoft
2007-10-22 22:58 163,328 -r-hs—- C:\WINDOWS\system32\flvDX.dll
2007-10-22 22:58 31,232 -r-hs—- C:\WINDOWS\system32\msfDX.dll
2007-10-22 21:47 d——– C:\Downloads
2007-10-22 20:25 d——– C:\VAZ_BACKUP
2007-10-20 21:04 d——– C:\Documents and Settings\All Users\Application Data\vsosdk
2007-10-20 20:00 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2007-10-20 18:46 d——– C:\Program Files\FriendBlasterPro
2007-10-20 18:15 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Apple Computer
2007-10-20 18:14 d——– C:\Program Files\iTunes
2007-10-20 18:14 d——– C:\Program Files\iPod
2007-10-20 18:13 d——– C:\Program Files\QuickTime
2007-10-20 18:13 d——– C:\Program Files\Common Files\Apple
2007-10-20 18:13 d——– C:\Program Files\Apple Software Update
2007-10-20 18:13 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-20 18:13 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-10-20 05:40 50 –a—— C:\WINDOWS\system32\BRIDF04A.dat
2007-10-20 05:28 d——– C:\Program Files\Brother
2007-10-20 05:26 d——– C:\Documents and Settings\All Users\Application Data\Brother
2007-10-20 04:59 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-10-20 04:59 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-10-20 04:59 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-10-20 04:59 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-10-20 00:19 18,816 –a—— C:\WINDOWS\system32\drivers\dvd43llh.sys
2007-10-19 21:00 d——– C:\WINDOWS\Sun
2007-10-19 18:06 d——– C:\Program Files\dvd43
2007-10-19 17:52 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Vso
2007-10-19 17:52 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
2007-10-19 17:52 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-10-19 17:52 47,360 –a—— C:\Documents and Settings\Klaus Kavindele\Application Data\pcouffin.sys
2007-10-18 18:02 d——– C:\Documents and Settings\Klaus Kavindele\Contacts
2007-10-18 18:00 d——– C:\Program Files\MSN Messenger
2007-10-18 17:39 6,058,496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-18 15:20 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-18 11:13 d——– C:\Program Files\MSXML 4.0
2007-10-18 09:04 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-10-18 06:14 d——– C:\Documents and Settings\NetworkService\Application Data\Intel
2007-10-18 05:27 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\1ClickDVDCopy
2007-10-18 04:54 d——– C:\Documents and Settings\All Users\Application Data\SlySoft
2007-10-18 04:31 d——– C:\Program Files\vso
2007-10-18 04:01 d——– C:\Documents and Settings\Klaus Kavindele\Shared
2007-10-18 04:01 d——– C:\Documents and Settings\Klaus Kavindele\Incomplete
2007-10-18 04:01 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\LimeWire
2007-10-18 03:51 d——– C:\Program Files\Common Files\Java
2007-10-18 03:42 d——– C:\Program Files\iMesh Applications
2007-10-18 03:42 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\iMesh
2007-10-18 00:52 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\1clickPro
2007-10-18 00:23 d——– C:\Program Files\ffdshow
2007-10-18 00:23 60,273 –a—— C:\WINDOWS\system32\pthreadGC2.dll
2007-10-18 00:23 7,680 –a—— C:\WINDOWS\system32\ff_vfw.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-27 21:15 0 —-a-w C:\WINDOWS\system32\drivers\ASPI2K.ADP
2007-10-16 05:11 ——— d—–w C:\Program Files\microsoft frontpage
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-14 01:54 413,696 —-a-w C:\WINDOWS\system32\vbscript.dll
2007-08-14 01:54 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
2007-08-14 01:45 78,336 —-a-w C:\WINDOWS\system32\ieencode.dll
2007-08-14 01:44 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-14 01:39 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
2007-08-14 01:39 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
2007-08-14 01:36 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
2007-08-14 01:32 45,568 —-a-w C:\WINDOWS\system32\mshta.exe
2007-08-14 01:01 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
2007-08-13 18:42 17,408 —-a-w C:\WINDOWS\system32\corpol.dll
2006-05-03 09:06:54 163,328 –sh–r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 –sh–r C:\WINDOWS\system32\msfDX.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Documents and Settings\Klaus Kavindele\Application Data\updater —-

2007-11-02 11:12 0 –a—— C:\Documents and Settings\Klaus Kavindele\Application Data\updater\boot.inf
2007-11-01 18:26 1477148 –a—— C:\Documents and Settings\Klaus Kavindele\Application Data\updater\explorer.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-07 20:02]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-03-17 13:34]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-05 00:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-12-12 18:31]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 08:07]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-03 04:50]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 21:34 C:\WINDOWS\SOUNDMAN.EXE]
"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2003-05-12 21:28]
"HotkeyApp"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2003-10-03 16:11]
"CtrlVol"="C:\Program Files\Launch Manager\CtrlVol.exe" [2003-09-16 21:28]
"LMgrPanelICON"="C:\Program Files\Launch Manager\PanelICON.exe" [2003-09-24 23:37]
"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2003-09-12 22:24]
"AVManager"="C:\Program Files\Wistron\AVManager\AVManager.exe" [2003-10-17 09:41]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 08:11]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-31 00:43]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-30 20:29]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-02 12:16:07]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

R1 Hotkey;Hotkey;C:\WINDOWS\system32\drivers\Hotkey.sys
R2 BBFat.VxD;BlueBird DSP API;C:\WINDOWS\system32\Drivers\BBFat.sys
S1 Wbutton;Wbutton;C:\WINDOWS\system32\drivers\Wbutton.sys
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\Drivers\BrScnUsb.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-06 09:07:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-02 17:38:32 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-07 07:48:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-07 7:51:45 - machine was rebooted
C:\ComboFix2.txt … 2007-11-06 12:33
.
— E O F —
————————————————————————————————————————————-
————————————————————————————————————————————-

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, November 07, 2007 10:26:04 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 7/11/2007
Kaspersky Anti-Virus database records: 452683
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 73820
Number of viruses found: 10
Number of infected objects: 19
Number of suspicious objects: 0
Duration of the scan process: 01:29:37

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\780000\477CCE6C.VBN Infected: Trojan-Downloader.Win32.Agent.dag skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\780001\477CCE8D.VBN Infected: not-a-virus:AdWare.Win32.Agent.jw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\780002\477CCE96.VBN Infected: not-a-virus:AdWare.Win32.Agent.kc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine4380000\4738F200.VBN Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\QuarantineCB40000\4FB4B6C9.VBN Infected: Trojan-Dropper.Win32.VB.lu skipped
C:\Documents and Settings\Klaus Kavindele\Application Data\Sun\Java\Deployment\cache\6.0\32\7836d960-1e7aa84a/BnnnnBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Klaus Kavindele\Application Data\Sun\Java\Deployment\cache\6.0\32\7836d960-1e7aa84a/VaannnaaBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Klaus Kavindele\Application Data\Sun\Java\Deployment\cache\6.0\32\7836d960-1e7aa84a/Bnnnnn.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Klaus Kavindele\Application Data\Sun\Java\Deployment\cache\6.0\32\7836d960-1e7aa84a ZIP: infected - 3 skipped
C:\Documents and Settings\Klaus Kavindele\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Klaus Kavindele\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Klaus Kavindele\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Klaus Kavindele\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Klaus Kavindele\Local Settings\History\History.IE5\MSHist012007110720071108\index.dat Object is locked skipped
C:\Documents and Settings\Klaus Kavindele\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Klaus Kavindele\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Klaus Kavindele\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT192NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT637NAV~.TMP Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\Help\access.cni.vir Infected: Backdoor.Win32.Agent.byy skipped
C:\qoobox\Quarantine\C\WINDOWS\nview.dll.vir Infected: Backdoor.Win32.Agent.byy skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{B11ACBF0-C53C-4F8C-A11B-4986CB5B43C1}\RP58\A0007866.exe Infected: Trojan-Downloader.Win32.Zlob.cpx skipped
C:\System Volume Information\_restore{B11ACBF0-C53C-4F8C-A11B-4986CB5B43C1}\RP76\A0008466.dll Infected: Backdoor.Win32.Agent.byy skipped
C:\System Volume Information\_restore{B11ACBF0-C53C-4F8C-A11B-4986CB5B43C1}\RP77\change.log Object is locked skipped
C:\VAZ_BACKUP\public_html0\classifieds\index.php Infected: Virus.Win32.Virut.an skipped
C:\VAZ_BACKUP\www\classifieds\index.php Infected: Virus.Win32.Virut.an skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
——————————————————————————————————————————————————–
——————————————————————————————————————————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:28:42 AM, on 11/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrPanelICON] C:\Program Files\Launch Manager\PanelICON.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 10897 bytes
Hi

Open Norton Antivirus. From the View menu, choose Quarantine. There should be a list of files. Can you right-click all of them, then select Delete?


Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\Documents and Settings\Klaus Kavindele\Application Data\updater\boot.inf
Click Send.
Please post the results of this scan to this thread.

Do the same for this file.

C:\Documents and Settings\Klaus Kavindele\Application Data\updater\explorer.exe
Hello Scotty,

Thanks for working with me, very much appreciated.

You last instructions mention opening Norton Antivirus from view menu. I do not have Norton Antivirus, at least I think I don't. Please advise.

Thanks again

Klaus

I did as requested.

Put this line in white box.
C:\Documents and Settings\Klaus Kavindele\Application Data\updater\boot.inf

I received this - 0 bytes size received / Se ha recibido un archivo vacio


For second line -
C:\Documents and Settings\Klaus Kavindele\Application Data\updater\explorer.exe

I got results below.




File explorer.exe received on 11.07.2007 18:08:21 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED


Result: 2/31 (6.46%)
Loading server information…
Your file is queued in position: 4.
Estimated start time is between 49 and 70 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:


Antivirus Version Last Update Result
AhnLab-V3 2007.11.2.1 2007.11.02 -
AntiVir 7.6.0.34 2007.11.07 -
Authentium 4.93.8 2007.11.01 -
Avast 4.7.1074.0 2007.11.06 -
AVG 7.5.0.503 2007.11.06 -
BitDefender 7.2 2007.11.07 -
CAT-QuickHeal 9.00 2007.11.06 -
ClamAV 0.91.2 2007.11.07 -
DrWeb 4.44.0.09170 2007.11.07 -
eSafe 7.0.15.0 2007.10.28 Suspicious Archive Structure
eTrust-Vet 31.2.5276 2007.11.07 -
Ewido 4.0 2007.11.06 -
FileAdvisor 1 2007.11.07 -
Fortinet 3.11.0.0 2007.10.19 -
F-Prot 4.4.2.54 2007.11.07 -
F-Secure 6.70.13030.0 2007.11.02 -
Ikarus T3.1.1.12 2007.11.07 -
Kaspersky 7.0.0.125 2007.11.02 -
McAfee 5157 2007.11.06 -
Microsoft 1.3007 2007.11.07 -
NOD32v2 2642 2007.11.06 error - password-protected file
Norman 5.80.02 2007.11.06 -
Panda 9.0.0.4 2007.11.06 -
Rising 20.16.42.00 2007.11.02 -
Sophos 4.23.0 2007.11.07 -
Sunbelt 2.2.907.0 2007.10.31 -
Symantec 10 2007.11.02 -
TheHacker 6.2.9.118 2007.11.06 -
VBA32 3.12.2.4 2007.11.06 -
VirusBuster 4.3.26:9 2007.11.06 -
Webwasher-Gateway 6.0.1 2007.11.07 -
Additional information
File size: 1477148 bytes
MD5: 2046f3383e97ddb3fdb4f3216a0a0cf1
SHA1: af57b502acc9b591fd4e33adac2f66003725efaa
packers: ZIP
I did as requested. Put this line in white box. C:\Documents and Settings\Klaus Kavindele\Application Data\updater\boot.inf I received this - 0 bytes size received / Se ha recibido un archivo vacio For second line - C:\Documents and Settings\Klaus Kavindele\Application Data\updater\explorer.exe I got results below. File explorer.exe received on 11.07.2007 18:08:21 (CET) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 2/31 (6.46%) Loading server information… Your file is queued in position: 4. Estimated start time is between 49 and 70 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2007.11.2.1 2007.11.02 - AntiVir 7.6.0.34 2007.11.07 - Authentium 4.93.8 2007.11.01 - Avast 4.7.1074.0 2007.11.06 - AVG 7.5.0.503 2007.11.06 - BitDefender 7.2 2007.11.07 - CAT-QuickHeal 9.00 2007.11.06 - ClamAV 0.91.2 2007.11.07 - DrWeb 4.44.0.09170 2007.11.07 - eSafe 7.0.15.0 2007.10.28 Suspicious Archive Structure eTrust-Vet 31.2.5276 2007.11.07 - Ewido 4.0 2007.11.06 - FileAdvisor 1 2007.11.07 - Fortinet 3.11.0.0 2007.10.19 - F-Prot 4.4.2.54 2007.11.07 - F-Secure 6.70.13030.0 2007.11.02 - Ikarus T3.1.1.12 2007.11.07 - Kaspersky 7.0.0.125 2007.11.02 - McAfee 5157 2007.11.06 - Microsoft 1.3007 2007.11.07 - NOD32v2 2642 2007.11.06 error - password-protected file Norman 5.80.02 2007.11.06 - Panda 9.0.0.4 2007.11.06 - Rising 20.16.42.00 2007.11.02 - Sophos 4.23.0 2007.11.07 - Sunbelt 2.2.907.0 2007.10.31 - Symantec 10 2007.11.02 - TheHacker 6.2.9.118 2007.11.06 - VBA32 3.12.2.4 2007.11.06 - VirusBuster 4.3.26:9 2007.11.06 - Webwasher-Gateway 6.0.1 2007.11.07 - Additional information File size: 1477148 bytes MD5: 2046f3383e97ddb3fdb4f3216a0a0cf1 SHA1: af57b502acc9b591fd4e33adac2f66003725efaa packers: ZIP
Hi

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\VAZ_BACKUP\public_html0\classifieds\index.php
C:\VAZ_BACKUP\www\classifieds\index.php

Folder::
C:\SDFix
C:\Documents and Settings\Klaus Kavindele\Application Data\updater
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix
C:\Documents and Settings\Klaus Kavindele\Application Data\Sun\Java\Deployment\cache\6.0\32\7836d960-1e7aa84a ZIP

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
ComboFix 07-11-06.4 - Klaus Kavindele 2007-11-07 20:56:25.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Klaus Kavindele\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\VAZ_BACKUP\public_html0\classifieds\index.php
C:\VAZ_BACKUP\www\classifieds\index.php
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Klaus Kavindele\Application Data\updater
C:\Documents and Settings\Klaus Kavindele\Application Data\updater\boot.inf
C:\Documents and Settings\Klaus Kavindele\Application Data\updater\explorer.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\dumphive.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\exit.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\GenericRenosFix.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\HostsChk.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\Process.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\Reboot.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\restart.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\SmitfraudFix.cmd
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\SmitfraudFix.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\SmiUpdate.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\SrchSTS.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\swreg.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\swsc.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\swxcacls.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\unzip.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\VCCLSID.exe
C:\Documents and Settings\Klaus Kavindele\Desktop\Apps\SmitfraudFix\WS2Fix.exe
C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\moveex.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\RegDACL.exe
C:\SDFix\apps\regedit.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\zip.exe
C:\SDFix\backups\attrib.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\backups.zip
C:\SDFix\backups\find.exe
C:\SDFix\backups\findstr.exe
C:\SDFix\backups\HOSTS
C:\SDFix\backups\regedit.exe
C:\SDFix\catchme.exe
C:\SDFix\dummy.sys
C:\SDFix\Report.txt
C:\SDFix\RunThis.bat
C:\SDFix\SDFIX_ReadMe_Online.url
C:\VAZ_BACKUP\public_html0\classifieds\index.php
C:\VAZ_BACKUP\www\classifieds\index.php

.
((((((((((((((((((((((((( Files Created from 2007-10-07 to 2007-11-07 )))))))))))))))))))))))))))))))
.

2007-11-07 07:59 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-11-07 07:59 d——– C:\WINDOWS\LastGood
2007-11-07 07:59 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-06 12:22 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-06 12:04 d——– C:\WINDOWS\ERUNT
2007-11-04 19:02 d——– C:\Documents and Settings\Klaus Kavindele\Phone Browser
2007-11-04 19:02 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Datalayer
2007-11-04 19:00 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Nokia
2007-11-04 18:43 d——– C:\Program Files\DIFX
2007-11-04 18:42 d——– C:\Program Files\Common Files\PCSuite
2007-11-04 18:42 d——– C:\Program Files\Common Files\Nokia
2007-11-04 18:42 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\PC Suite
2007-11-04 18:42 d——– C:\Documents and Settings\All Users\Application Data\PC Suite
2007-11-04 18:42 127,488 –a—— C:\WINDOWS\system32\drivers\nmwcd.sys
2007-11-04 18:42 50,688 –a—— C:\WINDOWS\system32\nmwcdcls.dll
2007-11-04 18:42 30,720 –a—— C:\WINDOWS\system32\nmwcdcocls.dll
2007-11-04 18:42 13,312 –a—— C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-11-04 18:42 13,312 –a—— C:\WINDOWS\system32\drivers\nmwcdcj.sys
2007-11-04 18:42 8,704 –a—— C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-11-04 18:42 4,608 –a—— C:\WINDOWS\system32\nmwcdlog.dll
2007-11-04 18:41 d——– C:\Program Files\Nokia
2007-11-04 18:41 d——– C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-11-02 12:16 d——– C:\Program Files\Spyware Doctor
2007-11-02 12:16 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\PC Tools
2007-11-02 12:16 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-02 12:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-02 12:16 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-02 12:16 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-02 12:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-11-02 11:13 d——– C:\Program Files\LimeWire
2007-10-30 20:30 d——– C:\Program Files\Norton Security Scan
2007-10-30 20:03 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-10-30 20:03 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-10-30 19:44 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-30 19:43 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-10-29 22:15 d——– C:\Program Files\MagicDVDCopier
2007-10-29 18:15 d——– C:\Program Files\Trend Micro
2007-10-29 18:00 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Grisoft
2007-10-29 17:59 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-29 17:59 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-28 18:55 3,168 –a—— C:\WINDOWS\system32\tmp.reg
2007-10-27 22:13 87,608 –a—— C:\Documents and Settings\Klaus Kavindele\Application Data\ezpinst.exe
2007-10-27 20:56 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\CopyToDvd
2007-10-25 22:11 d——– C:\Program Files\Common Files\Download Manager
2007-10-23 00:05 d——– C:\Program Files\FLV Player
2007-10-23 00:05 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\GetRightToGo
2007-10-23 00:05 411,248 –a—— C:\Program Files\FLV PlayerRCSetup.exe
2007-10-22 23:36 d——– C:\Program Files\Orbitdownloader
2007-10-22 23:36 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Orbit
2007-10-22 23:32 d——– C:\WINDOWS\FLV Player
2007-10-22 23:21 0 –a—— C:\WINDOWS\nsreg.dat
2007-10-22 23:08 d——– C:\Program Files\AviSynth 2.5
2007-10-22 22:58 d——– C:\Program Files\eRightSoft
2007-10-22 22:58 163,328 -r-hs—- C:\WINDOWS\system32\flvDX.dll
2007-10-22 22:58 31,232 -r-hs—- C:\WINDOWS\system32\msfDX.dll
2007-10-22 21:47 d——– C:\Downloads
2007-10-22 20:25 d——– C:\VAZ_BACKUP
2007-10-20 21:04 d——– C:\Documents and Settings\All Users\Application Data\vsosdk
2007-10-20 20:00 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2007-10-20 18:46 d——– C:\Program Files\FriendBlasterPro
2007-10-20 18:15 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Apple Computer
2007-10-20 18:14 d——– C:\Program Files\iTunes
2007-10-20 18:14 d——– C:\Program Files\iPod
2007-10-20 18:13 d——– C:\Program Files\QuickTime
2007-10-20 18:13 d——– C:\Program Files\Common Files\Apple
2007-10-20 18:13 d——– C:\Program Files\Apple Software Update
2007-10-20 18:13 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-20 18:13 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-10-20 05:40 50 –a—— C:\WINDOWS\system32\BRIDF04A.dat
2007-10-20 05:28 d——– C:\Program Files\Brother
2007-10-20 05:26 d——– C:\Documents and Settings\All Users\Application Data\Brother
2007-10-20 04:59 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-10-20 04:59 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-10-20 04:59 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-10-20 04:59 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-10-20 00:19 18,816 –a—— C:\WINDOWS\system32\drivers\dvd43llh.sys
2007-10-19 21:00 d——– C:\WINDOWS\Sun
2007-10-19 18:06 d——– C:\Program Files\dvd43
2007-10-19 17:52 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\Vso
2007-10-19 17:52 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
2007-10-19 17:52 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-10-19 17:52 47,360 –a—— C:\Documents and Settings\Klaus Kavindele\Application Data\pcouffin.sys
2007-10-18 18:02 d——– C:\Documents and Settings\Klaus Kavindele\Contacts
2007-10-18 18:00 d——– C:\Program Files\MSN Messenger
2007-10-18 17:39 6,058,496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-18 15:20 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-18 11:13 d——– C:\Program Files\MSXML 4.0
2007-10-18 09:04 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-10-18 06:14 d——– C:\Documents and Settings\NetworkService\Application Data\Intel
2007-10-18 05:27 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\1ClickDVDCopy
2007-10-18 04:54 d——– C:\Documents and Settings\All Users\Application Data\SlySoft
2007-10-18 04:31 d——– C:\Program Files\vso
2007-10-18 04:01 d——– C:\Documents and Settings\Klaus Kavindele\Shared
2007-10-18 04:01 d——– C:\Documents and Settings\Klaus Kavindele\Incomplete
2007-10-18 04:01 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\LimeWire
2007-10-18 03:51 d——– C:\Program Files\Common Files\Java
2007-10-18 03:42 d——– C:\Program Files\iMesh Applications
2007-10-18 03:42 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\iMesh
2007-10-18 00:52 d——– C:\Documents and Settings\Klaus Kavindele\Application Data\1clickPro
2007-10-18 00:23 d——– C:\Program Files\ffdshow

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-27 21:15 0 —-a-w C:\WINDOWS\system32\drivers\ASPI2K.ADP
2007-10-16 05:11 ——— d—–w C:\Program Files\microsoft frontpage
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-14 01:54 413,696 —-a-w C:\WINDOWS\system32\vbscript.dll
2007-08-14 01:54 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
2007-08-14 01:45 78,336 —-a-w C:\WINDOWS\system32\ieencode.dll
2007-08-14 01:44 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-14 01:39 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
2007-08-14 01:39 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
2007-08-14 01:36 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
2007-08-14 01:32 45,568 —-a-w C:\WINDOWS\system32\mshta.exe
2007-08-14 01:01 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
2007-08-13 18:42 17,408 —-a-w C:\WINDOWS\system32\corpol.dll
2006-05-03 09:06:54 163,328 –sh–r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 –sh–r C:\WINDOWS\system32\msfDX.dll
.

((((((((((((((((((((((((((((( snapshot@2007-11-06_12.32.24.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 12:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 15:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 15:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-07 20:02]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-03-17 13:34]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-05 00:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-12-12 18:31]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 08:07]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-03 04:50]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 21:34 C:\WINDOWS\SOUNDMAN.EXE]
"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2003-05-12 21:28]
"HotkeyApp"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2003-10-03 16:11]
"CtrlVol"="C:\Program Files\Launch Manager\CtrlVol.exe" [2003-09-16 21:28]
"LMgrPanelICON"="C:\Program Files\Launch Manager\PanelICON.exe" [2003-09-24 23:37]
"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2003-09-12 22:24]
"AVManager"="C:\Program Files\Wistron\AVManager\AVManager.exe" [2003-10-17 09:41]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 08:11]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-31 00:43]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-30 20:29]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-02 12:16:07]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

R1 Hotkey;Hotkey;C:\WINDOWS\system32\drivers\Hotkey.sys
R2 BBFat.VxD;BlueBird DSP API;C:\WINDOWS\system32\Drivers\BBFat.sys
S1 Wbutton;Wbutton;C:\WINDOWS\system32\drivers\Wbutton.sys
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\Drivers\BrScnUsb.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-06 09:07:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-02 17:38:32 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-07 21:02:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-07 21:04:31
C:\ComboFix2.txt … 2007-11-07 07:51
C:\ComboFix3.txt … 2007-11-06 12:33
.
— E O F —


—————————————————————————————————————————————
—————————————————————————————————————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:10:31 PM, on 11/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrPanelICON] C:\Program Files\Launch Manager\PanelICON.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 11057 bytes
Hi

If you do not wish to keep the Kaspersky Online Scanner as an extra virus scanning tool, you can remove it through Add/Remove Programs.

This is my usual speech for when you are clean, which you appear to be.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.

    [external image: Posted Image]
  • When shown the disclaimer, Select "2"

Here are some free programs I recommend, although you will not need them all.

Spybot Search and Destroy
Download it from here . Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here

Install Spyware Guard
Download it from here
Find here the tutorial on how to use Spyware Guard here

Install SpyWare Blaster
Download it from here
Find here the tutorial on how to use Spyware Blaster here

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here


Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"


Follow this list and your potential for being infected again will reduce dramatically.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI