This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help ! Can't seem to get rid of !

86 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Trojan?, Malware? back door virus? Can't seem to clean, can anyone help?
Attached is Hijack This:

Logfile of HijackThis v1.99.1
Scan saved at 12:45:08 PM, on 11/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\PROGRA~1\VISION~1\ONETOU~2.EXE
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
C:\Program Files\SecCenter\scprot4.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\Common Files\AOL\1152415670\EE\aolsoftware.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\dwwin.exe
C:\Documents and Settings\Renee Loiselle\Desktop\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
F3 - REG:win.ini: load=
F3 - REG:win.ini: run=
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~1\ONETOU~2.EXE
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [BOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
O4 - HKLM\..\Run: [SC2] C:\Program Files\SecCenter\scprot4.exe
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\printer.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - Startup: Check for OneTouch Updates.lnk = C:\Program Files\Visioneer OneTouch\WiseUpdt.exe
O4 - Startup: findfast.exe
O4 - Global Startup: autorun.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLaunc…iveLauncher.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1154124762625
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{C505CB0A-29F6-4582-8058-8E08509316EC}: NameServer = 71.243.0.12 71.250.0.12
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Program Files\Norman\Nvc\BIN\nipsvc.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Rename HijackThis
There is a possibility an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to: C:\Program Files\HijackThis\HijackThis.exe

Right-click on HijackThis.exe & select Rename to hello.exe and post back a new Hijackthis log.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
First Thank You so much for answering my post, I am soooooooo appreciative! I will follow your instructions explicitly, and if we can get my machine back to normal, I will donate weekly. lol.

New HijackThis.exe after being renamed hello.exe. It was located in C:\Documents and Settings\my name\Desktop:



Logfile of HijackThis v1.99.1
Scan saved at 5:41:32 PM, on 11/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\PROGRA~1\VISION~1\ONETOU~2.EXE
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
C:\Program Files\SecCenter\scprot4.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\Common Files\AOL\1152415670\EE\aolsoftware.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\NOTEPAD.EXE
C:\Program Files\Common Files\AOL\1152415670\EE\anotify.exe
C:\Documents and Settings\Renee Loiselle\Desktop\hello.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
F3 - REG:win.ini: load=
F3 - REG:win.ini: run=
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {200D0AAD-71B1-51C9-DDB0-092BA4662A54} - C:\Program Files\Qekbrqbk\bsxlgesz.dll
O2 - BHO: {0197773e-46a9-3b98-46e4-4b090f25a546} - {645a52f0-90b4-4e64-89b3-9a64e3777910} - C:\WINDOWS\system32\tjckgrif.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {A7E8657A-BF4F-4C73-843D-A63BE01437B5} - C:\WINDOWS\system32\geeba.dll
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - C:\Program Files\E404 Helper\e404.v5.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~1\ONETOU~2.EXE
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [BOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
O4 - HKLM\..\Run: [SC2] C:\Program Files\SecCenter\scprot4.exe
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\printer.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - Startup: Check for OneTouch Updates.lnk = C:\Program Files\Visioneer OneTouch\WiseUpdt.exe
O4 - Startup: findfast.exe
O4 - Global Startup: autorun.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLaunc…iveLauncher.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1154124762625
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{C505CB0A-29F6-4582-8058-8E08509316EC}: NameServer = 71.243.0.12 71.250.0.12
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winhoq32 - C:\WINDOWS\SYSTEM32\winhoq32.dll
O20 - Winlogon Notify: winwea32 - C:\WINDOWS\SYSTEM32\winwea32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Program Files\Norman\Nvc\BIN\nipsvc.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)



Uninstall List per your instructions:

Acer GridVista
Adobe Flash Player 9 ActiveX
Adobe Reader 8.1.1
Adobe Shockwave Player
AOL Coach Version 2.0(Build:20041026.5 en)
AOL Deskbar
AOL Toolbar 5.0
AOL Uninstaller (Choose which Products to Remove)
AOL You've Got Pictures Screensaver
aspi
AVG Anti-Spyware 7.5
BOClean
Broadband Support Center
CCHelp
CCScore
Drivers Install For Linksys Easylink Advisor
ESSAdpt
ESSANUP
ESSBrwr
ESSCAM
ESSCDBK
ESScore
ESSCT
ESSgui
ESShelp
ESSini
ESSPCD
ESSTUTOR
ESSvpaht
ESSvpot
HijackThis 1.99.1
HLPCCTR
HLPIndex
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB926239)
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Kodak EasyShare software
KODAK Picture CD Volume 2 Issue 4
Linksys EasyLink Advisor 1.6 (0033)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Professional Edition 2003
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Notifier
OneTouch Version 3.0
OTOY
OTtBP
PaperPort 7.0
PCDLNCH
QuickTime
QuickTime for Windows (32-bit)
Reader Rabbit's Preschool
RealPlayer Basic
Seagate DiscWizard
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB943460)
SFR
SFR2
UHS Reader (Version 6.01)
Update for Windows XP (KB894391)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
VCAMCEN
Verizon Online
Verizon Online Consumer DSL 6.1
Viewpoint Media Player
Virtools 3D Life Player
Virtual Earth 3D (Beta)
Virtual Makeover
WildTangent Web Driver
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinZip 11.1
~ Ran a SmitFraudfix while trying to clean, it as follows: SmitFraudFix v2.253 Scan done at 19:30:51.01, Thu 11/15/2007 Run from C:\Documents and Settings\Renee Loiselle\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Comodo\CBOClean\BOCORE.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\PROGRA~1\VISION~1\ONETOU~2.EXE C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe C:\PROGRA~1\Comodo\CBOClean\BOC425.exe C:\Program Files\SecCenter\scprot4.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\Program Files\AOL 9.0\waol.exe C:\Program Files\Common Files\AOL\1152415670\EE\aolsoftware.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\AOL 9.0\shellmon.exe C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\dwwin.exe C:\WINDOWS\NOTEPAD.EXE C:\PROGRA~1\WINZIP\winzip32.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS C:\WINDOWS\shell.exe FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\printer.exe FOUND ! C:\WINDOWS\system32\spoolvs.exe FOUND ! C:\WINDOWS\system32\components\flx?.dll FOUND ! C:\WINDOWS\system32\components\flx??.dll FOUND ! C:\WINDOWS\system32\components\flx???.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Renee Loiselle »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Renee Loiselle\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu C:\DOCUME~1\RENEEL~1\STARTM~1\Programs\Startup\findfast.exe FOUND ! C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\autorun.exe FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\RENEEL~1\FAVORI~1 C:\DOCUME~1\RENEEL~1\FAVORI~1\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "fairydom"=" " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "coursings"="{f8d02387-789a-4c0f-a1d8-8a93f33ee4df}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "hubbsi"="{7b1eeccd-0a6d-4ad5-8ac1-4af5722b3885}" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: WAN (PPP/SLIP) Interface DNS Server Search Order: 71.243.0.12 DNS Server Search Order: 71.250.0.12 HKLM\SYSTEM\CCS\Services\Tcpip\..\{C505CB0A-29F6-4582-8058-8E08509316EC}: NameServer=71.243.0.12 71.250.0.12 HKLM\SYSTEM\CS2\Services\Tcpip\..\{C505CB0A-29F6-4582-8058-8E08509316EC}: NameServer=71.243.0.12 71.250.0.12 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Ran again, not quite sure if the first one completed? SmitFraudFix v2.253 Scan done at 20:17:46.07, Thu 11/15/2007 Run from C:\Documents and Settings\Renee Loiselle\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "fairydom"=" " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "coursings"="{f8d02387-789a-4c0f-a1d8-8a93f33ee4df}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "hubbsi"="{7b1eeccd-0a6d-4ad5-8ac1-4af5722b3885}" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix S!Ri's WS2Fix: LSP not Found. »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\shell.exe Deleted C:\WINDOWS\system32\printer.exe Deleted C:\WINDOWS\system32\spoolvs.exe Deleted C:\WINDOWS\system32\components\flx?.dll Deleted C:\WINDOWS\system32\components\flx??.dll Deleted C:\DOCUME~1\RENEEL~1\STARTM~1\Programs\Startup\findfast.exe Deleted C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\autorun.exe Deleted C:\DOCUME~1\RENEEL~1\FAVORI~1\Antivirus Test Online.url Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: WAN (PPP/SLIP) Interface DNS Server Search Order: 71.243.0.12 DNS Server Search Order: 71.250.0.12 HKLM\SYSTEM\CCS\Services\Tcpip\..\{C505CB0A-29F6-4582-8058-8E08509316EC}: NameServer=71.243.0.12 71.250.0.12 HKLM\SYSTEM\CS2\Services\Tcpip\..\{C505CB0A-29F6-4582-8058-8E08509316EC}: NameServer=71.243.0.12 71.250.0.12 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
Hi

I know you would like to get clean asap, but self fixing can be confusing for poor me. I take it you ran Smitfraudfix from Option 1 first then Option 2?


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.


Download and Save ComboFix
  • Download this file from below:

    Here
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
SDFix: Version 1.114

Run by [removed] on Fri 11/16/2007 at 08:55 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\Program Files\hlpsrv.exe - Deleted
C:\WINDOWS\system32\csrs.exe - Deleted
C:\WINDOWS\system32\firewall.exe - Deleted
C:\WINDOWS\system32\spoolsvc.exe - Deleted
C:\WINDOWS\system32\winamp.exe - Deleted


Folder C:\Program Files\E404 Helper - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-16 09:15:12
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"\\??\\C:\\WINDOWS\\system32\\winlogon.exe"="\\??\\C:\\WINDOWS\\system32\\winlogon.exe:*:enabled:@shell32.dll,-1"
"C:\\Program Files\\xloader10181.exe"="C:\\Program Files\\xloader10181.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\printer.exe"="C:\\WINDOWS\\system32\\printer.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\spoolvs.exe"="C:\\WINDOWS\\system32\\spoolvs.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\shell.exe"="C:\\WINDOWS\\shell.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Renee Loiselle\\Start Menu\\Programs\\Startup\\findfast.exe"="C:\\Documents and Settings\\Renee Loiselle\\Start Menu\\Programs\\Startup\\findfast.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\autorun.exe"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\autorun.exe:*:Enabled:@xpsp2res.dll,-22019"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\xloader10181.exe"="C:\\Program Files\\xloader10181.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\printer.exe"="C:\\WINDOWS\\system32\\printer.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\spoolvs.exe"="C:\\WINDOWS\\system32\\spoolvs.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\shell.exe"="C:\\WINDOWS\\shell.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Renee Loiselle\\Start Menu\\Programs\\Startup\\findfast.exe"="C:\\Documents and Settings\\Renee Loiselle\\Start Menu\\Programs\\Startup\\findfast.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\autorun.exe"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\autorun.exe:*:Enabled:@xpsp2res.dll,-22019"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Thu 30 Nov 2006 4 A..H. — "C:\WINDOWS\uccspecb.sys"
Wed 18 Apr 2007 46,640 A..H. — "C:\Program Files\AOL 9.0\AOLphx.exe"
Wed 18 Apr 2007 54,832 A..H. — "C:\Program Files\AOL 9.0\AOLphxex.exe"
Wed 18 Apr 2007 33,328 A..H. — "C:\Program Files\AOL 9.0\rbm.exe"
Wed 13 Oct 2004 1,701,376 A..H. — "C:\Program Files\Messenger\msmsgs.exe"
Wed 4 Aug 2004 67,584 A.SH. — "C:\Program Files\Outlook Express\msimn.exe"
Sat 10 Nov 2007 446,542 ..SH. — "C:\WINDOWS\system32\abeeg.bak1"
Thu 15 Nov 2007 446,527 ..SH. — "C:\WINDOWS\system32\abeeg.bak2"
Thu 15 Nov 2007 20,768 ..SH. — "C:\WINDOWS\system32\mnuvsdqn.dllbox"
Sat 12 May 2007 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 9 May 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 17 Oct 2007 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\8361ae28fcfac79271825a6b2935fdb6\BITA9.tmp"
Mon 23 Jul 2007 96,072 …H. — "C:\Program Files\Common Files\AOL\TopSpeed\3.0\WBUnins.exe"
Fri 14 Sep 2007 8 A..H. — "C:\Documents and Settings\All Users\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Fri 14 Sep 2007 8 A..H. — "C:\Documents and Settings\All Users\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Fri 14 Sep 2007 8 A..H. — "C:\Documents and Settings\All Users\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
Fri 14 Sep 2007 8 A..H. — "C:\Documents and Settings\Renee Loiselle\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Fri 14 Sep 2007 8 A..H. — "C:\Documents and Settings\Renee Loiselle\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"

Finished!
ComboFix 07-11-08.1 - Renee Loiselle 2007-11-16 9:53:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.121 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\.protected
C:\Documents and Settings\All Users\Application Data.\zatcxmjw.dll
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\All Users\Start Menu\Programs.\Ultimate Defender
C:\Documents and Settings\All Users\Start Menu\Programs.\Ultimate Defender\Ultimate Defender Uninstall.lnk
C:\Documents and Settings\All Users\Start Menu\Programs.\Ultimate Defender\Ultimate Defender.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected
C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender\Ultimate Defender Uninstall.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender\Ultimate Defender.lnk
C:\Documents and Settings\Renee Loiselle\Application Data.\Ultimate Defender
C:\Documents and Settings\Renee Loiselle\Application Data.\Ultimate Defender\logs\1195213802.log
C:\Documents and Settings\Renee Loiselle\Application Data\Ultimate Defender\logs\1195213802.log
C:\Documents and Settings\Renee Loiselle\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Renee Loiselle\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Renee Loiselle\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Renee Loiselle\Start Menu\Programs\Startup\.protected
C:\Program Files\3269.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\Program Files\ucleaner_setup.exe
C:\Program Files\Ultimate Cleaner
C:\Program Files\Ultimate Defender
C:\Program Files\Ultimate Defender\program.info
C:\Program Files\Ultimate Defender\UltimateDefender.db
C:\Program Files\Ultimate Defender\UltimateDefender.exe
C:\Program Files\Ultimate Defender\UltimateDefender.pkg
C:\Program Files\Ultimate Defender\Uninstall.exe
C:\WINDOWS\.protected
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\abeeg.bak1
C:\WINDOWS\system32\abeeg.bak2
C:\WINDOWS\system32\abeeg.ini
C:\WINDOWS\system32\components
C:\WINDOWS\system32\drivers\etc\.protected
C:\WINDOWS\system32\fibagbia
C:\WINDOWS\system32\fibagbia\bg1.gif
C:\WINDOWS\system32\fibagbia\bgtop.gif
C:\WINDOWS\system32\fibagbia\bottom1.gif
C:\WINDOWS\system32\fibagbia\essentials.gif
C:\WINDOWS\system32\fibagbia\fibagbia1.exe
C:\WINDOWS\system32\fibagbia\fibagbia2.exe
C:\WINDOWS\system32\fibagbia\fibagbia3.exe
C:\WINDOWS\system32\fibagbia\icon1.ico
C:\WINDOWS\system32\fibagbia\install1.gif
C:\WINDOWS\system32\fibagbia\left1.gif
C:\WINDOWS\system32\fibagbia\li.gif
C:\WINDOWS\system32\fibagbia\logo.gif
C:\WINDOWS\system32\fibagbia\main.htm
C:\WINDOWS\system32\fibagbia\mainframe.htm
C:\WINDOWS\system32\fibagbia\reinstall1.gif
C:\WINDOWS\system32\fibagbia\right1.gif
C:\WINDOWS\system32\fibagbia\s1.htm
C:\WINDOWS\system32\fibagbia\s2.htm
C:\WINDOWS\system32\fibagbia\s3.htm
C:\WINDOWS\system32\fibagbia\SMTop1.gif
C:\WINDOWS\system32\fibagbia\SMTop2.gif
C:\WINDOWS\system32\fibagbia\SMTop3.gif
C:\WINDOWS\system32\fibagbia\SMTop4.gif
C:\WINDOWS\system32\fibagbia\soft1_off.gif
C:\WINDOWS\system32\fibagbia\soft1_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft1_on.gif
C:\WINDOWS\system32\fibagbia\soft1_on_ext.gif
C:\WINDOWS\system32\fibagbia\soft2_off.gif
C:\WINDOWS\system32\fibagbia\soft2_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft2_on.gif
C:\WINDOWS\system32\fibagbia\soft2_on_ext.gif
C:\WINDOWS\system32\fibagbia\soft3_off.gif
C:\WINDOWS\system32\fibagbia\soft3_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft3_on.gif
C:\WINDOWS\system32\fibagbia\soft3_on_ext.gif
C:\WINDOWS\system32\fibagbia\softbottom_off.gif
C:\WINDOWS\system32\fibagbia\softbottom_on.gif
C:\WINDOWS\system32\fibagbia\softleft_off.gif
C:\WINDOWS\system32\fibagbia\softleft_on.gif
C:\WINDOWS\system32\fibagbia\top1.gif
C:\WINDOWS\system32\fibagbia\top2.gif
C:\WINDOWS\system32\fibagbia\turnoff1.gif
C:\WINDOWS\system32\fibagbia\turnon1.gif
C:\WINDOWS\system32\geeba.dll
C:\WINDOWS\system32\isass.exe
C:\WINDOWS\system32\mnuvsdqn.dllbox
C:\WINDOWS\system32\ssembl~1
C:\WINDOWS\system32\ssembl~1\?ssembly\
C:\WINDOWS\system32\winhoq32.dll
C:\WINDOWS\system32\winwea32.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_NWSAPAGENT
——-\NwSapAgent


((((((((((((((((((((((((( Files Created from 2007-10-16 to 2007-11-16 )))))))))))))))))))))))))))))))
.

2007-11-16 09:52 58,368 –a—— C:\WINDOWS\NirCmd.exe
2007-11-16 09:26 81,984 –a—— C:\WINDOWS\system32\mcsvjxhj.dll
2007-11-16 09:23 85,056 –a—— C:\WINDOWS\system32\agxdvnma.dll
2007-11-16 08:54 d——– C:\WINDOWS\ERUNT
2007-11-15 19:31 3,462 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-15 09:19 d——– C:\VundoFix Backups
2007-11-15 09:12 79,936 –a—— C:\WINDOWS\system32\tjckgrif.dll
2007-11-15 09:09 85,056 –a—— C:\WINDOWS\system32\lthcwgnv.dll
2007-11-14 09:10 79,424 –a—— C:\WINDOWS\system32\jeoeoubq.dll
2007-11-14 09:07 85,056 –a—— C:\WINDOWS\system32\lxpnamqn.dll
2007-11-14 03:00 d——– C:\c57117a9cd66be78a498213d1341
2007-11-13 21:34 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-13 18:31 d——– C:\Documents and Settings\Renee Loiselle\Application Data\AdwareAlert
2007-11-13 18:25 20,480 ——— C:\Program Files\xloader10181.exe
2007-11-13 18:16 d——– C:\Program Files\rizmxabe
2007-11-13 18:16 d——– C:\Program Files\Qekbrqbk
2007-11-13 18:16 36,352 –a—— C:\WINDOWS\system32\jkkjjgh.dll
2007-11-13 11:24 d——– C:\Program Files\Comodo
2007-11-13 11:24 242,688 –a—— C:\WINDOWS\UNBOC.EXE
2007-11-13 11:24 208,896 –a—— C:\WINDOWS\CMDLIC.DLL
2007-11-13 09:16 80,448 –a—— C:\WINDOWS\system32\ptrrqqfs.dll
2007-11-13 09:13 88,128 –a—— C:\WINDOWS\system32\baqjfpcm.dll
2007-11-13 09:10 144,480 –a—— C:\WINDOWS\system32\vmdbpxrg.dll
2007-11-13 04:24 31,622 –a—— C:\WINDOWS\system32\ifvnptyk.exe
2007-11-12 22:48 d——– C:\Program Files\Virtual Earth 3D
2007-11-12 09:12 81,472 –a—— C:\WINDOWS\system32\tctisssh.dll
2007-11-11 20:26 d——– C:\e16f3d14460a32527faa
2007-11-11 09:06 79,936 –a—— C:\WINDOWS\system32\mwvhqyqr.dll
2007-11-11 04:10 2,432 –a—— C:\WINDOWS\system32\unpr.sys
2007-11-10 19:04 285,184 –a—— C:\WINDOWS\system32\LexBceS.exe
2007-11-10 19:04 201,728 –a—— C:\WINDOWS\system32\Lexp2p32.dll
2007-11-10 19:04 190,976 –a—— C:\WINDOWS\system32\lexlmpm.dll
2007-11-10 19:04 176,128 –a—— C:\WINDOWS\system32\Lexpps.exe
2007-11-10 19:04 175,104 –a—— C:\WINDOWS\system32\lex2kusb.dll
2007-11-10 19:04 135,168 –a—— C:\WINDOWS\system32\LexBce.dll
2007-11-10 19:04 79,872 –a—— C:\WINDOWS\system32\lex_psu.exe
2007-11-10 19:04 55,808 –a—— C:\WINDOWS\system32\Lexunst1.exe
2007-11-10 19:04 41,472 –a—— C:\WINDOWS\system32\ldeei.dll
2007-11-10 09:09 81,472 –a—— C:\WINDOWS\system32\ucvimryo.dll
2007-11-09 09:14 77,888 –a—— C:\WINDOWS\system32\mhynwqpc.dll
2007-11-09 09:11 88,128 –a—— C:\WINDOWS\system32\sxnonqay.dll
2007-11-08 09:08 86,080 –a—— C:\WINDOWS\system32\lodvpcac.dll
2007-11-07 09:11 79,936 –a—— C:\WINDOWS\system32\xqhcupsp.dll
2007-11-07 09:08 86,080 –a—— C:\WINDOWS\system32\fabmydeg.dll
2007-11-05 22:42 1,430,048 –a—— C:\WINDOWS\system32\AutoPartNt.exe
2007-11-05 22:36 d——– C:\Documents and Settings\All Users\Application Data\Seagate
2007-11-02 11:00 d——– C:\WINDOWS\SHELLNEW
2007-11-02 10:45 452,096 –a—— C:\WINDOWS\system32\fxsapi.dll
2007-11-02 10:45 452,096 –a–c— C:\WINDOWS\system32\dllcache\fxsapi.dll
2007-10-27 12:15 d——– C:\Program Files\Common Files\Wise Installation Wizard

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 20:31 ——— d—–w C:\Program Files\Linksys EasyLink Advisor
2007-11-10 22:04 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-11-07 04:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-10-07 01:54 392,320 —-a-w C:\WINDOWS\system32\drivers\timntr.sys
2007-10-07 01:54 32,768 —-a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
2007-10-07 01:54 120,992 —-a-w C:\WINDOWS\system32\drivers\snapman.sys
2007-10-07 01:54 ——— d—–w C:\Program Files\Common Files\Seagate
2007-10-07 01:53 ——— d—–w C:\Program Files\Seagate
2007-10-01 03:35 ——— d—–w C:\Program Files\BMCentral
2007-10-01 02:48 9,728 —-a-w C:\WINDOWS\_MSRSTRT.EXE
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2001-07-12 12:09 61,440 -c–a-w C:\WINDOWS\inf\i386\onetUSD.dll
2001-06-05 12:11 32,768 -c–a-w C:\WINDOWS\inf\i386\Wiamicro.dll
2001-05-14 14:19 51,984 -c–a-w C:\WINDOWS\inf\i386\Wiafbdrv.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{200D0AAD-71B1-51C9-DDB0-092BA4662A54}]
2007-11-13 18:16 114688 –a—— C:\Program Files\Qekbrqbk\bsxlgesz.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c6c481bc-33a4-4224-8c93-1da1276222ea}]
2007-11-16 09:26 81984 –a—— C:\WINDOWS\system32\mcsvjxhj.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50]
"HostManager"="C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe" [2007-04-12 16:23]
"Motive SmartBridge"="C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe" [2006-07-08 23:13]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-08 22:30]
"OneTouch Monitor"="C:\PROGRA~1\VISION~1\ONETOU~2.EXE" [2001-07-12 07:08]
"DiscWizardMonitor.exe"="C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2007-04-19 21:24]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [2007-04-19 21:38]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 21:29]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe" [2000-03-08 12:09]
"e8d3404c"="C:\WINDOWS\system32\agxdvnma.dll" [2007-11-16 09:23]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPWebCap"="C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe" [2000-09-06 11:14]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 17:16]
"AdwareAlert"="C:\Program Files\AdwareAlert\AdwareAlert.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-12-13 14:28:04]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-08-03 11:10:00]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 nwprovau relog_ap C:\WINDOWS\system32\geeba.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Broadband Support Center.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Broadband Support Center.lnk
backup=C:\WINDOWS\pss\Broadband Support Center.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c9c08cc.exe]
C:\WINDOWS\System32\c9c08cc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailScan]
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
C:\Program Files\mcafee.com\antivirus\oasclnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sscRun]
C:\Program Files\Common Files\AOL\1152415670\ee\services\sscFirewallPlugin\ver1_205_1_1\SSCRun.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aolavupd"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"SCardSvr"=3 (0x3)
"SCardDrv"=3 (0x3)

R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R0 UNPR;UNPR;C:\WINDOWS\system32\unpr.sys
R2 elagopro;GoProto Protocol Driver for LELA;C:\WINDOWS\system32\DRIVERS\elagopro.sys
R2 elaunidr;UniDriver for LELA;C:\WINDOWS\system32\DRIVERS\elaunidr.sys
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
S3 BOCDRIVE;BOClean Kernel Monitor.;\??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 08:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-16 10:01:53
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-16 10:04:25 - machine was rebooted
.
— E O F —
Hi

Run Smitfraudfix
Open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.


Then run Combofix again and post the new log it produces. Make sure to run Combo after Smitfraudfix.
Hi Scotty, Here is the rapport.txt along with the combofix report, let me know your thoughts, A big thanks in advance. Renee

ComboFix 07-11-08.1 - Renee Loiselle 2007-11-16 9:53:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.121 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\.protected
C:\Documents and Settings\All Users\Application Data.\zatcxmjw.dll
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\All Users\Start Menu\Programs.\Ultimate Defender
C:\Documents and Settings\All Users\Start Menu\Programs.\Ultimate Defender\Ultimate Defender Uninstall.lnk
C:\Documents and Settings\All Users\Start Menu\Programs.\Ultimate Defender\Ultimate Defender.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected
C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender\Ultimate Defender Uninstall.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender\Ultimate Defender.lnk
C:\Documents and Settings\Renee Loiselle\Application Data.\Ultimate Defender
C:\Documents and Settings\Renee Loiselle\Application Data.\Ultimate Defender\logs\1195213802.log
C:\Documents and Settings\Renee Loiselle\Application Data\Ultimate Defender\logs\1195213802.log
C:\Documents and Settings\Renee Loiselle\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Renee Loiselle\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Renee Loiselle\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Renee Loiselle\Start Menu\Programs\Startup\.protected
C:\Program Files\3269.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\Program Files\ucleaner_setup.exe
C:\Program Files\Ultimate Cleaner
C:\Program Files\Ultimate Defender
C:\Program Files\Ultimate Defender\program.info
C:\Program Files\Ultimate Defender\UltimateDefender.db
C:\Program Files\Ultimate Defender\UltimateDefender.exe
C:\Program Files\Ultimate Defender\UltimateDefender.pkg
C:\Program Files\Ultimate Defender\Uninstall.exe
C:\WINDOWS\.protected
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\abeeg.bak1
C:\WINDOWS\system32\abeeg.bak2
C:\WINDOWS\system32\abeeg.ini
C:\WINDOWS\system32\components
C:\WINDOWS\system32\drivers\etc\.protected
C:\WINDOWS\system32\fibagbia
C:\WINDOWS\system32\fibagbia\bg1.gif
C:\WINDOWS\system32\fibagbia\bgtop.gif
C:\WINDOWS\system32\fibagbia\bottom1.gif
C:\WINDOWS\system32\fibagbia\essentials.gif
C:\WINDOWS\system32\fibagbia\fibagbia1.exe
C:\WINDOWS\system32\fibagbia\fibagbia2.exe
C:\WINDOWS\system32\fibagbia\fibagbia3.exe
C:\WINDOWS\system32\fibagbia\icon1.ico
C:\WINDOWS\system32\fibagbia\install1.gif
C:\WINDOWS\system32\fibagbia\left1.gif
C:\WINDOWS\system32\fibagbia\li.gif
C:\WINDOWS\system32\fibagbia\logo.gif
C:\WINDOWS\system32\fibagbia\main.htm
C:\WINDOWS\system32\fibagbia\mainframe.htm
C:\WINDOWS\system32\fibagbia\reinstall1.gif
C:\WINDOWS\system32\fibagbia\right1.gif
C:\WINDOWS\system32\fibagbia\s1.htm
C:\WINDOWS\system32\fibagbia\s2.htm
C:\WINDOWS\system32\fibagbia\s3.htm
C:\WINDOWS\system32\fibagbia\SMTop1.gif
C:\WINDOWS\system32\fibagbia\SMTop2.gif
C:\WINDOWS\system32\fibagbia\SMTop3.gif
C:\WINDOWS\system32\fibagbia\SMTop4.gif
C:\WINDOWS\system32\fibagbia\soft1_off.gif
C:\WINDOWS\system32\fibagbia\soft1_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft1_on.gif
C:\WINDOWS\system32\fibagbia\soft1_on_ext.gif
C:\WINDOWS\system32\fibagbia\soft2_off.gif
C:\WINDOWS\system32\fibagbia\soft2_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft2_on.gif
C:\WINDOWS\system32\fibagbia\soft2_on_ext.gif
C:\WINDOWS\system32\fibagbia\soft3_off.gif
C:\WINDOWS\system32\fibagbia\soft3_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft3_on.gif
C:\WINDOWS\system32\fibagbia\soft3_on_ext.gif
C:\WINDOWS\system32\fibagbia\softbottom_off.gif
C:\WINDOWS\system32\fibagbia\softbottom_on.gif
C:\WINDOWS\system32\fibagbia\softleft_off.gif
C:\WINDOWS\system32\fibagbia\softleft_on.gif
C:\WINDOWS\system32\fibagbia\top1.gif
C:\WINDOWS\system32\fibagbia\top2.gif
C:\WINDOWS\system32\fibagbia\turnoff1.gif
C:\WINDOWS\system32\fibagbia\turnon1.gif
C:\WINDOWS\system32\geeba.dll
C:\WINDOWS\system32\isass.exe
C:\WINDOWS\system32\mnuvsdqn.dllbox
C:\WINDOWS\system32\ssembl~1
C:\WINDOWS\system32\ssembl~1\?ssembly\
C:\WINDOWS\system32\winhoq32.dll
C:\WINDOWS\system32\winwea32.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_NWSAPAGENT
——-\NwSapAgent


((((((((((((((((((((((((( Files Created from 2007-10-16 to 2007-11-16 )))))))))))))))))))))))))))))))
.

2007-11-16 09:52 58,368 –a—— C:\WINDOWS\NirCmd.exe
2007-11-16 09:26 81,984 –a—— C:\WINDOWS\system32\mcsvjxhj.dll
2007-11-16 09:23 85,056 –a—— C:\WINDOWS\system32\agxdvnma.dll
2007-11-16 08:54 d——– C:\WINDOWS\ERUNT
2007-11-15 19:31 3,462 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-15 09:19 d——– C:\VundoFix Backups
2007-11-15 09:12 79,936 –a—— C:\WINDOWS\system32\tjckgrif.dll
2007-11-15 09:09 85,056 –a—— C:\WINDOWS\system32\lthcwgnv.dll
2007-11-14 09:10 79,424 –a—— C:\WINDOWS\system32\jeoeoubq.dll
2007-11-14 09:07 85,056 –a—— C:\WINDOWS\system32\lxpnamqn.dll
2007-11-14 03:00 d——– C:\c57117a9cd66be78a498213d1341
2007-11-13 21:34 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-13 18:31 d——– C:\Documents and Settings\Renee Loiselle\Application Data\AdwareAlert
2007-11-13 18:25 20,480 ——— C:\Program Files\xloader10181.exe
2007-11-13 18:16 d——– C:\Program Files\rizmxabe
2007-11-13 18:16 d——– C:\Program Files\Qekbrqbk
2007-11-13 18:16 36,352 –a—— C:\WINDOWS\system32\jkkjjgh.dll
2007-11-13 11:24 d——– C:\Program Files\Comodo
2007-11-13 11:24 242,688 –a—— C:\WINDOWS\UNBOC.EXE
2007-11-13 11:24 208,896 –a—— C:\WINDOWS\CMDLIC.DLL
2007-11-13 09:16 80,448 –a—— C:\WINDOWS\system32\ptrrqqfs.dll
2007-11-13 09:13 88,128 –a—— C:\WINDOWS\system32\baqjfpcm.dll
2007-11-13 09:10 144,480 –a—— C:\WINDOWS\system32\vmdbpxrg.dll
2007-11-13 04:24 31,622 –a—— C:\WINDOWS\system32\ifvnptyk.exe
2007-11-12 22:48 d——– C:\Program Files\Virtual Earth 3D
2007-11-12 09:12 81,472 –a—— C:\WINDOWS\system32\tctisssh.dll
2007-11-11 20:26 d——– C:\e16f3d14460a32527faa
2007-11-11 09:06 79,936 –a—— C:\WINDOWS\system32\mwvhqyqr.dll
2007-11-11 04:10 2,432 –a—— C:\WINDOWS\system32\unpr.sys
2007-11-10 19:04 285,184 –a—— C:\WINDOWS\system32\LexBceS.exe
2007-11-10 19:04 201,728 –a—— C:\WINDOWS\system32\Lexp2p32.dll
2007-11-10 19:04 190,976 –a—— C:\WINDOWS\system32\lexlmpm.dll
2007-11-10 19:04 176,128 –a—— C:\WINDOWS\system32\Lexpps.exe
2007-11-10 19:04 175,104 –a—— C:\WINDOWS\system32\lex2kusb.dll
2007-11-10 19:04 135,168 –a—— C:\WINDOWS\system32\LexBce.dll
2007-11-10 19:04 79,872 –a—— C:\WINDOWS\system32\lex_psu.exe
2007-11-10 19:04 55,808 –a—— C:\WINDOWS\system32\Lexunst1.exe
2007-11-10 19:04 41,472 –a—— C:\WINDOWS\system32\ldeei.dll
2007-11-10 09:09 81,472 –a—— C:\WINDOWS\system32\ucvimryo.dll
2007-11-09 09:14 77,888 –a—— C:\WINDOWS\system32\mhynwqpc.dll
2007-11-09 09:11 88,128 –a—— C:\WINDOWS\system32\sxnonqay.dll
2007-11-08 09:08 86,080 –a—— C:\WINDOWS\system32\lodvpcac.dll
2007-11-07 09:11 79,936 –a—— C:\WINDOWS\system32\xqhcupsp.dll
2007-11-07 09:08 86,080 –a—— C:\WINDOWS\system32\fabmydeg.dll
2007-11-05 22:42 1,430,048 –a—— C:\WINDOWS\system32\AutoPartNt.exe
2007-11-05 22:36 d——– C:\Documents and Settings\All Users\Application Data\Seagate
2007-11-02 11:00 d——– C:\WINDOWS\SHELLNEW
2007-11-02 10:45 452,096 –a—— C:\WINDOWS\system32\fxsapi.dll
2007-11-02 10:45 452,096 –a–c— C:\WINDOWS\system32\dllcache\fxsapi.dll
2007-10-27 12:15 d——– C:\Program Files\Common Files\Wise Installation Wizard

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 20:31 ——— d—–w C:\Program Files\Linksys EasyLink Advisor
2007-11-10 22:04 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-11-07 04:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-10-07 01:54 392,320 —-a-w C:\WINDOWS\system32\drivers\timntr.sys
2007-10-07 01:54 32,768 —-a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
2007-10-07 01:54 120,992 —-a-w C:\WINDOWS\system32\drivers\snapman.sys
2007-10-07 01:54 ——— d—–w C:\Program Files\Common Files\Seagate
2007-10-07 01:53 ——— d—–w C:\Program Files\Seagate
2007-10-01 03:35 ——— d—–w C:\Program Files\BMCentral
2007-10-01 02:48 9,728 —-a-w C:\WINDOWS\_MSRSTRT.EXE
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2001-07-12 12:09 61,440 -c–a-w C:\WINDOWS\inf\i386\onetUSD.dll
2001-06-05 12:11 32,768 -c–a-w C:\WINDOWS\inf\i386\Wiamicro.dll
2001-05-14 14:19 51,984 -c–a-w C:\WINDOWS\inf\i386\Wiafbdrv.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{200D0AAD-71B1-51C9-DDB0-092BA4662A54}]
2007-11-13 18:16 114688 –a—— C:\Program Files\Qekbrqbk\bsxlgesz.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c6c481bc-33a4-4224-8c93-1da1276222ea}]
2007-11-16 09:26 81984 –a—— C:\WINDOWS\system32\mcsvjxhj.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50]
"HostManager"="C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe" [2007-04-12 16:23]
"Motive SmartBridge"="C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe" [2006-07-08 23:13]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-08 22:30]
"OneTouch Monitor"="C:\PROGRA~1\VISION~1\ONETOU~2.EXE" [2001-07-12 07:08]
"DiscWizardMonitor.exe"="C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2007-04-19 21:24]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [2007-04-19 21:38]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 21:29]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe" [2000-03-08 12:09]
"e8d3404c"="C:\WINDOWS\system32\agxdvnma.dll" [2007-11-16 09:23]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPWebCap"="C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe" [2000-09-06 11:14]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 17:16]
"AdwareAlert"="C:\Program Files\AdwareAlert\AdwareAlert.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-12-13 14:28:04]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-08-03 11:10:00]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 nwprovau relog_ap C:\WINDOWS\system32\geeba.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Broadband Support Center.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Broadband Support Center.lnk
backup=C:\WINDOWS\pss\Broadband Support Center.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c9c08cc.exe]
C:\WINDOWS\System32\c9c08cc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailScan]
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
C:\Program Files\mcafee.com\antivirus\oasclnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sscRun]
C:\Program Files\Common Files\AOL\1152415670\ee\services\sscFirewallPlugin\ver1_205_1_1\SSCRun.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aolavupd"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"SCardSvr"=3 (0x3)
"SCardDrv"=3 (0x3)

R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R0 UNPR;UNPR;C:\WINDOWS\system32\unpr.sys
R2 elagopro;GoProto Protocol Driver for LELA;C:\WINDOWS\system32\DRIVERS\elagopro.sys
R2 elaunidr;UniDriver for LELA;C:\WINDOWS\system32\DRIVERS\elaunidr.sys
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
S3 BOCDRIVE;BOClean Kernel Monitor.;\??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 08:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-16 10:01:53
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-16 10:04:25 - machine was rebooted
.
— E O F —
Hi

Sorry for the delay, but I had to query about the lsa reg key. :(

Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\Program Files\xloader10181.exe
Click Send.
Please post the results of this scan to this thread.


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\mcsvjxhj.dll 
C:\WINDOWS\system32\agxdvnma.dll
C:\WINDOWS\system32\tjckgrif.dll
C:\WINDOWS\system32\lthcwgnv.dll
C:\WINDOWS\system32\jeoeoubq.dll
C:\WINDOWS\system32\lxpnamqn.dll
C:\WINDOWS\system32\jkkjjgh.dll
C:\WINDOWS\system32\ptrrqqfs.dll
C:\WINDOWS\system32\baqjfpcm.dll
C:\WINDOWS\system32\vmdbpxrg.dll
C:\WINDOWS\system32\ifvnptyk.exe
C:\WINDOWS\system32\tctisssh.dll
C:\WINDOWS\system32\mwvhqyqr.dll
C:\WINDOWS\system32\unpr.sys
C:\WINDOWS\system32\ucvimryo.dll
C:\WINDOWS\system32\mhynwqpc.dll
C:\WINDOWS\system32\sxnonqay.dll
C:\WINDOWS\system32\lodvpcac.dll
C:\WINDOWS\system32\xqhcupsp.dll
C:\WINDOWS\system32\fabmydeg.dll
C:\WINDOWS\system32\geeba.dll
C:\WINDOWS\System32\c9c08cc.exe

Folder::
C:\Program Files\rizmxabe
C:\Program Files\Qekbrqbk
C:\Vundofix
C:\VundoFix Backups

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{200D0AAD-71B1-51C9-DDB0-092BA4662A54}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c6c481bc-33a4-4224-8c93-1da1276222ea}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"e8d3404c"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c9c08cc.exe]

Driver::
UNPR

DirLook::
C:\e16f3d14460a32527faa
C:\c57117a9cd66be78a498213d1341

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (excluding the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
Scotty, Here are the results of the scan from Virustotal, please tell me that those aren'e all virus's I have ? Sincerely, Renee6 Will post new combofix with cfsript and hijack log next.
File xloader10181.exe_ received on 11.18.2007 23:39:43 (CET) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 24/32 (75%) Loading server information… Your file is queued in position: 2. Estimated start time is between 40 and 57 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2007.11.17.0 2007.11.16 - AntiVir 7.6.0.34 2007.11.18 W32/Virut.AX Authentium 4.93.8 2007.11.17 W32/Splendor.7116 Avast 4.7.1074.0 2007.11.18 Win32:Virtob AVG 7.5.0.503 2007.11.18 Win32/Virut BitDefender 7.2 2007.11.18 Win32.Virtob.BQ CAT-QuickHeal 9.00 2007.11.17 W32.Virut.Z ClamAV 0.91.2 2007.11.18 W32.Virut-17 DrWeb 4.44.0.09170 2007.11.18 Win32.Virut.30 eSafe 7.0.15.0 2007.11.14 suspicious Trojan/Worm eTrust-Vet 31.2.5304 2007.11.17 Win32/Virut.7115 Ewido 4.0 2007.11.18 - FileAdvisor 1 2007.11.18 - Fortinet 3.11.0.0 2007.11.18 - F-Prot 4.4.2.54 2007.11.18 W32/Blocker-based!Maximus F-Secure 6.70.13030.0 2007.11.18 Virus.Win32.Virut.av Ikarus T3.1.1.12 2007.11.18 Trojan-Downloader.Win32.Xuma Kaspersky 7.0.0.125 2007.11.18 Virus.Win32.Virut.av McAfee 5165 2007.11.16 W32/Virut.gen.a Microsoft 1.3007 2007.11.18 Virus:Win32/Virut.AC NOD32v2 2665 2007.11.17 Win32/Virut.AV Norman 5.80.02 2007.11.16 W32/Renos.JS Panda 9.0.0.4 2007.11.18 - Prevx1 V2 2007.11.18 - Rising 20.18.61.00 2007.11.18 Win32.Virut.ak Sophos 4.23.0 2007.11.18 - Sunbelt 2.2.907.0 2007.11.17 VIPRE.Suspicious Symantec 10 2007.11.18 W32.Virut.W TheHacker 6.2.9.133 2007.11.17 - VBA32 3.12.2.5 2007.11.16 Trojan-Downloader.Win32.Agent.eus VirusBuster 4.3.26:9 2007.11.18 Win32.Virut.Gen.4 Webwasher-Gateway 6.0.1 2007.11.18 Win32.Virut.AX Additional information File size: 20480 bytes MD5: 493d72081b54a2687e1d03a8b122bf11 SHA1: 1d93c57c2f53e4365527bb44899bace95c3a0762 packers: UPX Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics. ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
Scotty, Ran again for good measure, 78.13% completed this time.

File xloader10181.exe_ received on 11.19.2007 00:35:51 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED


Result: 25/32 (78.13%)
Loading server information…
Your file is queued in position: 1.
Estimated start time is between 37 and 52 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:


Antivirus Version Last Update Result
AhnLab-V3 2007.11.17.0 2007.11.16 -
AntiVir 7.6.0.34 2007.11.18 W32/Virut.AX
Authentium 4.93.8 2007.11.17 W32/Splendor.7116
Avast 4.7.1074.0 2007.11.18 Win32:Virtob
AVG 7.5.0.503 2007.11.18 Win32/Virut
BitDefender 7.2 2007.11.18 Win32.Virtob.BQ
CAT-QuickHeal 9.00 2007.11.17 W32.Virut.Z
ClamAV 0.91.2 2007.11.19 W32.Virut-17
DrWeb 4.44.0.09170 2007.11.18 Win32.Virut.30
eSafe 7.0.15.0 2007.11.14 suspicious Trojan/Worm
eTrust-Vet 31.2.5304 2007.11.17 Win32/Virut.7115
Ewido 4.0 2007.11.18 -
FileAdvisor 1 2007.11.19 -
Fortinet 3.11.0.0 2007.11.18 -
F-Prot 4.4.2.54 2007.11.18 W32/Blocker-based!Maximus
F-Secure 6.70.13030.0 2007.11.18 Virus.Win32.Virut.av
Ikarus T3.1.1.12 2007.11.18 Trojan-Downloader.Win32.Xuma
Kaspersky 7.0.0.125 2007.11.19 Virus.Win32.Virut.av
McAfee 5165 2007.11.16 W32/Virut.gen.a
Microsoft 1.3007 2007.11.19 Virus:Win32/Virut.AC
NOD32v2 2665 2007.11.17 Win32/Virut.AV
Norman 5.80.02 2007.11.16 W32/Renos.JS
Panda 9.0.0.4 2007.11.18 -
Prevx1 V2 2007.11.19 W32.PEINFECTOR.GEN
Rising 20.18.61.00 2007.11.18 Win32.Virut.ak
Sophos 4.23.0 2007.11.18 -
Sunbelt 2.2.907.0 2007.11.17 VIPRE.Suspicious
Symantec 10 2007.11.18 W32.Virut.W
TheHacker 6.2.9.133 2007.11.17 -
VBA32 3.12.2.5 2007.11.16 Trojan-Downloader.Win32.Agent.eus
VirusBuster 4.3.26:9 2007.11.18 Win32.Virut.Gen.4
Webwasher-Gateway 6.0.1 2007.11.18 Win32.Virut.AX
Additional information
File size: 20480 bytes
MD5: 493d72081b54a2687e1d03a8b122bf11
SHA1: 1d93c57c2f53e4365527bb44899bace95c3a0762
packers: UPX
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PX5…7478E0038D0C111
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI