This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Security/System alert messages

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Friends,

I am facing an issue from Yesterday..Tried to clean with Spysweeper and McAFee..but nothing helps..
A yellow flashing triangle in the system tray showing a message "Security Alert: spyware found" and System Alert : Trojan-Spy.win32@mx"(Getting many similar messages). Also seeing icons for Online Security Guide and Live Safety Center on the desktop. Seeing posts from others for same issues and great support from you experts. Can you please help me to solve this.

Here is my HiJack Log file

Logfile of HijackThis v1.99.1
Scan saved at 09:19:41, on 18/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\McAfee\Common Framework\FrameworkService.exe
D:\Program Files\McAfee\Common Framework\UdaterUI.exe
D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
D:\Program Files\McAfee\Common Framework\McTray.exe
D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
D:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
D:\Program Files\Mozilla Firefox\firefox.exe
d:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
d:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virginmedia.com/welcome
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\vcctuysc.dll
O4 - HKLM\..\Run: [ShStatEXE] "D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SpySweeper] D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - D:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

Thanks in advance
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.


Rename HijackThis
There is a possibility an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to: C:\Program Files\HijackThis\HijackThis.exe

Right-click on HijackThis.exe & select Rename to hello.exe and post back a new Hijackthis log.




Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
Scotty,

Thanks for your help and efforts in resolving my issue.

Here are my new HijackThis log and uninstall list

Logfile of HijackThis v1.99.1
Scan saved at 17:06:18, on 19/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\McAfee\Common Framework\FrameworkService.exe
D:\Program Files\McAfee\Common Framework\McTray.exe
D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\BKV\Desktop\Hello.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virginmedia.com/welcome
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {0DD98BA3-25B7-4913-88AF-CFBDB28DA4CE} - C:\WINDOWS\system32\ljjhebb.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: (no name) - {A65DE98B-66A6-4C9F-B1BC-85C378BF6464} - C:\WINDOWS\system32\opnkk.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\vcctuysc.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\vcctuysc.dll
O4 - HKLM\..\Run: [ShStatEXE] "D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "d:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ljjhebb - C:\WINDOWS\SYSTEM32\ljjhebb.dll
O20 - Winlogon Notify: vcctuysc - C:\WINDOWS\SYSTEM32\vcctuysc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - D:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

Uninstall List :

Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe ExtendScript Toolkit 2
Adobe Flash Player ActiveX
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Photoshop CS3
Adobe Setup
Adobe Setup
Adobe Shockwave Player
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
DivX Web Player
Font Fitting Room Deluxe
Hijackthis 1.99.1
HijackThis 1.99.1
Java™ 6 Update 3
McAfee VirusScan Enterprise
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Mozilla Firefox (2.0.0.9)
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
PDF Settings
Real Alternative 1.60
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB943460)
Skype™ 3.6
Spy Sweeper
Spybot - Search & Destroy
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
WinRAR archiver
Yahoo! Messenger

Thanks….
Hi

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.


Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your next reply
Hi,

After running the VundoFix.exe, the flashing icon in the system tray has gone(no system/security alert messages), the security tool bar in Internet explorer has gone..

Here is the Vundofix.txt content


VundoFix V6.6.2

Checking Java version…

Scan started at 07:12:32 20/11/2007

Listing files found while scanning….

C:\WINDOWS\system32\vcctuysc.dll

VundoFix V6.6.2

Checking Java version…

Scan started at 16:20:45 20/11/2007

Listing files found while scanning….

C:\windows\system32\awacowxq.dll
C:\windows\system32\ilnpo.ini
C:\windows\system32\ilnpo.ini2
C:\windows\system32\kknpo.ini
C:\windows\system32\kknpo.ini2
C:\windows\system32\opnkk.dll
C:\windows\system32\opnli.dll
C:\WINDOWS\system32\vcctuysc.dll
C:\windows\system32\vcctuysc.dllbox

Beginning removal…

Attempting to delete C:\windows\system32\awacowxq.dll
C:\windows\system32\awacowxq.dll Has been deleted!

Attempting to delete C:\windows\system32\ilnpo.ini
C:\windows\system32\ilnpo.ini Has been deleted!

Attempting to delete C:\windows\system32\ilnpo.ini2
C:\windows\system32\ilnpo.ini2 Has been deleted!

Attempting to delete C:\windows\system32\kknpo.ini
C:\windows\system32\kknpo.ini Has been deleted!

Attempting to delete C:\windows\system32\kknpo.ini2
C:\windows\system32\kknpo.ini2 Has been deleted!

Attempting to delete C:\windows\system32\opnkk.dll
C:\windows\system32\opnkk.dll Has been deleted!

Attempting to delete C:\windows\system32\opnli.dll
C:\windows\system32\opnli.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vcctuysc.dll
C:\WINDOWS\system32\vcctuysc.dll Has been deleted!

Attempting to delete C:\windows\system32\vcctuysc.dllbox
C:\windows\system32\vcctuysc.dllbox Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.6.2

Checking Java version…

Scan started at 18:27:04 20/11/2007

Listing files found while scanning….

——————————————————————–

Hee are the results od DSS.exe

main.txt
———–
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-11-20 18:37:42
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
16: 2007-11-20 18:37:57 UTC - RP16 - Deckard's System Scanner Restore Point
15: 2007-11-20 16:55:43 UTC - RP15 - Software Distribution Service 3.0
14: 2007-11-18 10:19:55 UTC - RP14 - Shockwave Player
13: 2007-11-18 09:26:25 UTC - RP13 - Installed Java™ 6 Update 3
12: 2007-11-17 09:22:44 UTC - RP12 - Last known good configuration


– First Restore Point –
1: 2007-11-17 09:22:16 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 256 MiB (512 MiB recommended).


– HijackThis (run as BKV.exe) ————————————————-

Unable to find log (file not found); running clone.
– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-11-20 18:40:13
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\McAfee\Common Framework\FrameworkService.exe
D:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\McAfee\Common Framework\Mctray.exe
D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
D:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
D:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Webroot\Spy Sweeper\ssu.exe
C:\Documents and Settings\BKV\Desktop\dss.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virginmedia.com/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {0DD98BA3-25B7-4913-88AF-CFBDB28DA4CE} - C:\WINDOWS\system32\ljjhebb.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5EE4CBC3-5065-4940-9769-1E7E56E5C075} - (no file)
O2 - BHO: (no name) - {5F20F889-A2A8-43CB-BBC7-058BA6A17EFE} - C:\WINDOWS\system32\ljhgh.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files\McAfee\VirusScan Enterprise\ScriptCl.dll
O2 - BHO: (no name) - {D6FB5CEB-8469-489C-AE3E-817DFC03894B} - C:\WINDOWS\system32\opnkk.dll (file missing)
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [ShStatEXE] "D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "d:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O20 - Winlogon Notify: ljjhebb - C:\WINDOWS\system32\ljjhebb.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - D:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - D:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


–
End of file - 6563 bytes

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

All drivers whitelisted.


– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ——————–

S3 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe"
Hi Could you run Vundofix again? Let's see how much we can remove before switching to manually removing the baddie files. :thumbup: Remember to post the new log it creates.
Hi , I have run the Vundofix again..It says "no infected files were found" Here is the log file content ———————— VundoFix V6.6.2 Checking Java version… Scan started at 06:56:17 21/11/2007 Listing files found while scanning…. No infected files were found —————————- Thanks for your great help..
Scotty,

Here is the new log of DSS.
There has no extra.txt come up..
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-11-21 16:37:25
Computer is in Normal Mode.
——————————————————————————–

Percentage of Memory in Use: 76% (more than 75%).
Total Physical Memory: 256 MiB (512 MiB recommended).


– HijackThis (run as BKV.exe) ————————————————-

Unable to find log (file not found); running clone.
– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-11-21 16:37:46
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\McAfee\Common Framework\FrameworkService.exe
D:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\McAfee\Common Framework\Mctray.exe
D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
D:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
D:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
C:\Documents and Settings\BKV\Desktop\dss.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virginmedia.com/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {0DD98BA3-25B7-4913-88AF-CFBDB28DA4CE} - C:\WINDOWS\system32\ljjhebb.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5EE4CBC3-5065-4940-9769-1E7E56E5C075} - (no file)
O2 - BHO: (no name) - {5F20F889-A2A8-43CB-BBC7-058BA6A17EFE} - C:\WINDOWS\system32\ljhgh.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files\McAfee\VirusScan Enterprise\ScriptCl.dll
O2 - BHO: (no name) - {D6FB5CEB-8469-489C-AE3E-817DFC03894B} - C:\WINDOWS\system32\opnkk.dll (file missing)
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [ShStatEXE] "D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O20 - Winlogon Notify: ljjhebb - C:\WINDOWS\system32\ljjhebb.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - D:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - D:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


–
End of file - 6069 bytes

– Files created between 2007-10-21 and 2007-11-21 —————————–

2007-11-20 22:29:49 0 d——– C:\Documents and Settings\BKV\Application Data\Tiffen
2007-11-20 19:25:51 41910596 –a—— C:\backup-201107.reg
2007-11-20 16:55:02 6529 –ahs—- C:\WINDOWS\system32\hghjl.ini2
2007-11-20 07:25:36 85056 –a—— C:\WINDOWS\system32\kjenbjrs.dll
2007-11-20 07:12:32 0 d——– C:\VundoFix Backups
2007-11-19 07:24:34 85056 –a—— C:\WINDOWS\system32\gmbjfxle.dll
2007-11-18 12:13:06 0 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-18 09:33:03 0 d——– C:\WINDOWS\Sun
2007-11-18 09:33:03 0 d——– C:\Documents and Settings\BKV\Application Data\Sun
2007-11-18 09:27:37 0 d——– C:\Program Files\Java
2007-11-18 09:26:40 0 d——– C:\Program Files\Common Files\Java
2007-11-17 23:07:08 0 d–hs—- C:\UGA6P
2007-11-17 23:05:57 0 d——– C:\Documents and Settings\BKV\Application Data\BestsellerAntivirus
2007-11-17 23:05:56 0 dr——- C:\Documents and Settings\All Users\Application Data\SalesMonitor
2007-11-17 22:40:55 85056 –a—— C:\WINDOWS\system32\vptpowms.dll
2007-11-17 22:12:11 1408 –a—— C:\WINDOWS\mozver.dat
2007-11-17 22:09:09 0 –a—— C:\WINDOWS\nsreg.dat
2007-11-17 22:08:57 0 d——– C:\Documents and Settings\BKV\Application Data\Mozilla
2007-11-17 14:22:03 0 d——– C:\Documents and Settings\LocalService\Application Data\Webroot
2007-11-17 14:20:42 0 d——– C:\Documents and Settings\All Users\Application Data\Webroot
2007-11-17 14:19:03 0 d——– C:\Documents and Settings\BKV\Application Data\Webroot
2007-11-17 11:45:51 0 d——– C:\Documents and Settings\BKV\Application Data\skypePM
2007-11-17 11:45:51 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-17 11:43:44 0 d——– C:\Documents and Settings\BKV\Application Data\Skype
2007-11-17 11:40:04 0 d——– C:\Program Files\Skype
2007-11-17 11:39:56 0 d——– C:\Program Files\Common Files\Skype
2007-11-17 11:39:01 0 d——– C:\Documents and Settings\All Users\Application Data\Skype
2007-11-17 10:04:44 0 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-17 08:43:41 0 d——– C:\Documents and Settings\BKV\Application Data\Systweak
2007-11-17 08:42:59 35328 –a—— C:\WINDOWS\system32\ljjhebb.dll
2007-11-17 08:42:23 0 d——– C:\WINDOWS\system32\rMa14yy
2007-11-17 08:42:23 0 d——– C:\Temp
2007-11-16 21:59:32 0 d——– C:\Documents and Settings\BKV\Application Data\Font Fitting Room Deluxe
2007-11-15 19:24:54 0 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-11-15 12:23:07 0 d——– C:\Documents and Settings\All Users\Application Data\Adobe
2007-11-15 12:18:52 0 d——– C:\Program Files\Bonjour
2007-11-15 12:17:19 0 d——– C:\Documents and Settings\BKV\Application Data\Adobe
2007-11-15 11:42:32 0 d——– C:\Program Files\Common Files\Macrovision Shared
2007-11-15 11:38:45 0 d——– C:\Program Files\Common Files\Adobe
2007-11-15 10:06:36 0 d——– C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-15 10:04:11 0 d——– C:\Program Files\Yahoo!
2007-11-15 00:11:34 1474560 –a—— C:\BOOTIMG.BIN
2007-11-15 00:11:34 2048 –a—— C:\BOOTCAT.BIN
2007-11-15 00:10:09 0 d–hs—- C:\System Volume Information
2007-11-14 21:05:20 0 d——– C:\Documents and Settings\BKV\Application Data\Media Player Classic
2007-11-14 21:04:10 0 d——– C:\Documents and Settings\BKV\Application Data\Real
2007-11-14 21:04:10 0 d——– C:\Documents and Settings\All Users\Application Data\Real
2007-11-14 19:26:02 0 d——– C:\Program Files\MSXML 6.0
2007-11-14 19:25:04 0 d——– C:\Program Files\MSXML 4.0
2007-11-14 19:21:56 0 d–h—– C:\WINDOWS\$hf_mig$
2007-11-14 19:18:15 0 d——– C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2007-11-14 19:13:09 0 d—s—- C:\Documents and Settings\BKV\UserData
2007-11-14 18:07:42 0 d——– C:\Documents and Settings\BKV\Application Data\Macromedia
2007-11-14 18:04:28 0 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-14 17:47:11 0 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-11-14 17:41:53 0 d——– C:\Program Files\Common Files\Motive
2007-11-14 17:41:02 306688 –a—— C:\WINDOWS\IsUninst.exe
Hi

Download and Save ComboFix
  • Download this file from below:

    Here
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Hi,

Please find the Combofix and HijackThis log files..

ComboFix 07-11-19.3 - BKV 2007-11-22 17:20:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.76 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\BKV\Application Data\BestsellerAntivirus
C:\Documents and Settings\BKV\Application Data\BestsellerAntivirus\avtasks.dat
C:\Documents and Settings\BKV\Application Data\BestsellerAntivirus\Logs\av.log
C:\Documents and Settings\BKV\Application Data\BestsellerAntivirus\Logs\ga6Support.log
C:\Documents and Settings\BKV\Application Data\BestsellerAntivirus\Logs\update.log
C:\Documents and Settings\BKV\Application Data\BestsellerAntivirus\PGE.dat
C:\Documents and Settings\BKV\Favorites\Online Security Guide.lnk
C:\UGA6P
C:\WINDOWS\system32\pac.txt

.
((((((((((((((((((((((((( Files Created from 2007-10-22 to 2007-11-22 )))))))))))))))))))))))))))))))
.

2007-11-20 22:29 d——– C:\Documents and Settings\BKV\Application Data\Tiffen
2007-11-20 22:22 1,024 –a—— C:\WINDOWS\system32\bzgv0nu.tgz
2007-11-20 19:25 41,910,596 –a—— C:\backup-201107.reg
2007-11-20 16:55 6,529 –ahs—- C:\WINDOWS\system32\hghjl.ini2
2007-11-20 16:55 6,529 –ahs—- C:\WINDOWS\system32\hghjl.ini
2007-11-20 07:25 85,056 –a—— C:\WINDOWS\system32\kjenbjrs.dll
2007-11-20 07:25 294 —hs—- C:\WINDOWS\system32\srjbnejk.ini
2007-11-20 07:12 d——– C:\VundoFix Backups
2007-11-19 07:24 677,141 —hs—- C:\WINDOWS\system32\elxfjbmg.ini
2007-11-19 07:24 85,056 –a—— C:\WINDOWS\system32\gmbjfxle.dll
2007-11-18 12:13 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-18 09:33 d——– C:\WINDOWS\Sun
2007-11-18 09:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2007-11-18 09:28 5,387 –a—— C:\WINDOWS\system32\jupdate-1.6.0_03-b05.log
2007-11-18 09:27 d——– C:\Program Files\Java
2007-11-18 09:26 d——– C:\Program Files\Common Files\Java
2007-11-17 23:17 20,280 –a—— C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2007-11-17 23:16 1,526,072 –a—— C:\WINDOWS\WRSetup.dll
2007-11-17 22:57 1,060,864 –a—— C:\WINDOWS\system32\mfc71.dll
2007-11-17 22:57 89,088 –a—— C:\WINDOWS\system32\atl71.dll
2007-11-17 22:57 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-11-17 22:41 354 —hs—- C:\WINDOWS\system32\smwoptpv.ini
2007-11-17 22:40 85,056 –a—— C:\WINDOWS\system32\vptpowms.dll
2007-11-17 22:12 1,408 –a—— C:\WINDOWS\mozver.dat
2007-11-17 22:09 0 –a—— C:\WINDOWS\nsreg.dat
2007-11-17 14:22 d——– C:\Documents and Settings\LocalService\Application Data\Webroot
2007-11-17 14:21 163,640 –a—— C:\WINDOWS\system32\drivers\ssidrv.sys
2007-11-17 14:21 23,864 –a—— C:\WINDOWS\system32\drivers\sskbfd.sys
2007-11-17 14:21 21,816 –a—— C:\WINDOWS\system32\drivers\sshrmd.sys
2007-11-17 14:20 d——– C:\Documents and Settings\All Users\Application Data\Webroot
2007-11-17 14:19 d——– C:\Documents and Settings\BKV\Application Data\Webroot
2007-11-17 11:45 d——– C:\Documents and Settings\BKV\Application Data\skypePM
2007-11-17 11:45 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-17 11:43 d——– C:\Documents and Settings\BKV\Application Data\Skype
2007-11-17 11:40 d——– C:\Program Files\Skype
2007-11-17 11:39 d——– C:\Program Files\Common Files\Skype
2007-11-17 11:39 d——– C:\Documents and Settings\All Users\Application Data\Skype
2007-11-17 10:04 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-17 08:43 d——– C:\Documents and Settings\BKV\Application Data\Systweak
2007-11-17 08:42 d——– C:\WINDOWS\system32\rMa14yy
2007-11-17 08:42 d——– C:\Temp\abW9
2007-11-17 08:42 d——– C:\Temp
2007-11-17 08:42 35,328 –a—— C:\WINDOWS\system32\ljjhebb.dll
2007-11-16 21:59 d——– C:\Documents and Settings\BKV\Application Data\Font Fitting Room Deluxe
2007-11-15 19:25 26,496 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-15 19:24 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-11-15 12:43 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-11-15 12:43 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-11-15 12:43 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-11-15 12:42 6,058,496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-11-15 12:42 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-11-15 12:42 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-11-15 12:42 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-11-15 12:42 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2007-11-15 12:42 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-11-15 12:18 d——– C:\Program Files\Bonjour
2007-11-15 11:42 d——– C:\Program Files\Common Files\Macrovision Shared
2007-11-15 11:38 d——– C:\Program Files\Common Files\Adobe
2007-11-15 10:06 d——– C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-15 10:04 d——– C:\Program Files\Yahoo!
2007-11-15 00:11 1,474,560 –a—— C:\BOOTIMG.BIN
2007-11-15 00:11 2,048 –a—— C:\BOOTCAT.BIN
2007-11-14 21:05 d——– C:\Documents and Settings\BKV\Application Data\Media Player Classic
2007-11-14 19:26 d——– C:\Program Files\MSXML 6.0
2007-11-14 19:26 127,648 –a—— C:\WINDOWS\system32\TZLog.log
2007-11-14 19:25 d——– C:\Program Files\MSXML 4.0
2007-11-14 19:24 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-11-14 19:21 d–h—– C:\WINDOWS\$hf_mig$
2007-11-14 19:13 d—s—- C:\Documents and Settings\BKV\UserData
2007-11-14 18:04 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-14 17:41 d——– C:\Program Files\Common Files\Motive
2007-11-14 17:41 306,688 –a—— C:\WINDOWS\IsUninst.exe
2007-11-14 17:40 6,345 -ra—— C:\WINDOWS\system32\DevMngr.vxd
2007-11-14 17:33 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-14 17:30 d——– C:\WINDOWS\35C03C043F1F42C2A989A757EE691F65.TMP
2007-11-14 17:25 d——– C:\Program Files\Common Files\McAfee
2007-11-14 17:25 d——– C:\Program Files\Common Files\Cisco Systems
2007-11-14 17:25 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2007-11-14 17:25 1,495,552 –a—— C:\WINDOWS\system32\epoPGPsdk.dll
2007-11-14 17:25 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2007-11-14 17:25 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2007-11-14 17:25 171,240 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2007-11-14 17:25 72,712 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-11-14 17:25 64,168 –a—— C:\WINDOWS\system32\drivers\mfeapfk.sys
2007-11-14 17:25 52,200 –a—— C:\WINDOWS\system32\drivers\mfetdik.sys
2007-11-14 17:25 34,184 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2007-11-14 17:25 280 –a—— C:\WINDOWS\system32\epoPGPsdk.dll.sig

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 16:46 ——— d—–w C:\Program Files\microsoft frontpage
2007-11-14 16:38 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-10-20 00:56 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0DD98BA3-25B7-4913-88AF-CFBDB28DA4CE}]
2007-11-17 08:43 35328 –a—— C:\WINDOWS\system32\ljjhebb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5EE4CBC3-5065-4940-9769-1E7E56E5C075}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5F20F889-A2A8-43CB-BBC7-058BA6A17EFE}]
C:\WINDOWS\system32\ljhgh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D6FB5CEB-8469-489C-AE3E-817DFC03894B}]
C:\WINDOWS\system32\opnkk.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"Yahoo! Pager"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-08-13 20:50]
"McAfeeUpdaterUI"="D:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 11:27]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"SpySweeper"="D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 16:40]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56]

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{0DD98BA3-25B7-4913-88AF-CFBDB28DA4CE}"= C:\WINDOWS\system32\ljjhebb.dll [2007-11-17 08:43 35328]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhebb]
ljjhebb.dll 2007-11-17 08:43 35328 C:\WINDOWS\system32\ljjhebb.dll

R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\WINDOWS\system32\Drivers\SSFS0BB9.SYS
R1 mfetdik;McAfee Inc.;C:\WINDOWS\system32\drivers\mfetdik.sys
R3 mfeapfk;McAfee Inc.;C:\WINDOWS\system32\drivers\mfeapfk.sys

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-22 17:26:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-22 17:28:17
.
— E O F —
————————————————————————————————————————————————————————–

Logfile of HijackThis v1.99.1
Scan saved at 17:30:38, on 22/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\McAfee\Common Framework\FrameworkService.exe
D:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\McAfee\Common Framework\McTray.exe
D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\BKV\Desktop\Hello.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virginmedia.com/welcome
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {0DD98BA3-25B7-4913-88AF-CFBDB28DA4CE} - C:\WINDOWS\system32\ljjhebb.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5EE4CBC3-5065-4940-9769-1E7E56E5C075} - (no file)
O2 - BHO: (no name) - {5F20F889-A2A8-43CB-BBC7-058BA6A17EFE} - C:\WINDOWS\system32\ljhgh.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: (no name) - {D6FB5CEB-8469-489C-AE3E-817DFC03894B} - C:\WINDOWS\system32\opnkk.dll (file missing)
O4 - HKLM\..\Run: [ShStatEXE] "D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ljjhebb - C:\WINDOWS\SYSTEM32\ljjhebb.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - D:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

————————————————————————————————————————————————————————–
Thanks..
Hi

Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\WINDOWS\system32\bzgv0nu.tgz
Click Send.
Please post the results of this scan to this thread.

Do the same for these files:
C:\backup-201107.reg
C:\WINDOWS\system32\mfc71.dll



Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\hghjl.ini2 
C:\WINDOWS\system32\hghjl.ini
C:\WINDOWS\system32\kjenbjrs.dll
C:\WINDOWS\system32\srjbnejk.ini
C:\VundoFix Backups
C:\WINDOWS\system32\elxfjbmg.ini
C:\WINDOWS\system32\gmbjfxle.dll
C:\WINDOWS\system32\smwoptpv.ini
C:\WINDOWS\system32\vptpowms.dll
C:\WINDOWS\system32\ljjhebb.dll

Folder::
C:\VundoFix Backups
C:\WINDOWS\system32\rMa14yy
C:\Temp\abW9

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0DD98BA3-25B7-4913-88AF-CFBDB28DA4CE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5EE4CBC3-5065-4940-9769-1E7E56E5C075}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5F20F889-A2A8-43CB-BBC7-058BA6A17EFE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D6FB5CEB-8469-489C-AE3E-817DFC03894B}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhebb]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
Hi
Thanks for your efforts,
Well, the file C:\backup-201107.reg is created by me. It is an exported file of the registry on 20th.

results from http://www.virustotal.com/en/indexf.html

1)for C:\WINDOWS\system32\bzgv0nu.tgz

File bzgv0nu.tgz received on 11.23.2007 21:14:02 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 0/32 (0%)
Loading server information…
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:

Antivirus Version Last Update Result
AhnLab-V3 2007.11.24.0 2007.11.23 -
AntiVir 7.6.0.34 2007.11.23 -
Authentium 4.93.8 2007.11.21 -
Avast 4.7.1074.0 2007.11.23 -
AVG 7.5.0.503 2007.11.23 -
BitDefender 7.2 2007.11.23 -
CAT-QuickHeal 9.00 2007.11.23 -
ClamAV 0.91.2 2007.11.23 -
DrWeb 4.44.0.09170 2007.11.23 -
eSafe 7.0.15.0 2007.11.21 -
eTrust-Vet 31.3.5318 2007.11.23 -
Ewido 4.0 2007.11.23 -
FileAdvisor 1 2007.11.23 -
Fortinet 3.14.0.0 2007.11.23 -
F-Prot 4.4.2.54 2007.11.23 -
F-Secure 6.70.13030.0 2007.11.23 -
Ikarus T3.1.1.12 2007.11.23 -
Kaspersky 7.0.0.125 2007.11.21 -
McAfee 5169 2007.11.22 -
Microsoft 1.3007 2007.11.23 -
NOD32v2 2682 2007.11.23 -
Norman 5.80.02 2007.11.23 -
Panda 9.0.0.4 2007.11.23 -
Prevx1 V2 2007.11.23 -
Rising 20.19.42.00 2007.11.23 -
Sophos 4.23.0 2007.11.23 -
Sunbelt 2.2.907.0 2007.11.22 -
Symantec 10 2007.11.23 -
TheHacker 6.2.9.139 2007.11.23 -
VBA32 3.12.2.5 2007.11.23 -
VirusBuster 4.3.26:9 2007.11.23 -
Webwasher-Gateway 6.0.1 2007.11.23 -
Additional information
File size: 1024 bytes
MD5: 458e6f4c3def03a7a6ccd02e5b286fac
SHA1: f7cf086a7c75dea9a6406e0f506552a3488d61c2

———————————————————–
for C:\WINDOWS\system32\mfc71.dll

File mfc71.dll received on 11.23.2007 21:18:43 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 0/32 (0%)
Loading server information…
Your file is queued in position: 9.
Estimated start time is between 66 and 95 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:

Antivirus Version Last Update Result
AhnLab-V3 2007.11.24.0 2007.11.23 -
AntiVir 7.6.0.34 2007.11.23 -
Authentium 4.93.8 2007.11.21 -
Avast 4.7.1074.0 2007.11.23 -
AVG 7.5.0.503 2007.11.23 -
BitDefender 7.2 2007.11.23 -
CAT-QuickHeal 9.00 2007.11.23 -
ClamAV 0.91.2 2007.11.23 -
DrWeb 4.44.0.09170 2007.11.23 -
eSafe 7.0.15.0 2007.11.21 -
eTrust-Vet 31.3.5318 2007.11.23 -
Ewido 4.0 2007.11.23 -
FileAdvisor 1 2007.11.23 -
Fortinet 3.14.0.0 2007.11.23 -
F-Prot 4.4.2.54 2007.11.23 -
F-Secure 6.70.13030.0 2007.11.23 -
Ikarus T3.1.1.12 2007.11.23 -
Kaspersky 7.0.0.125 2007.11.21 -
McAfee 5169 2007.11.22 -
Microsoft 1.3007 2007.11.23 -
NOD32v2 2682 2007.11.23 -
Norman 5.80.02 2007.11.23 -
Panda 9.0.0.4 2007.11.23 -
Prevx1 V2 2007.11.23 -
Rising 20.19.42.00 2007.11.23 -
Sophos 4.23.0 2007.11.23 -
Sunbelt 2.2.907.0 2007.11.22 -
Symantec 10 2007.11.23 -
TheHacker 6.2.9.139 2007.11.23 -
VBA32 3.12.2.5 2007.11.23 -
VirusBuster 4.3.26:9 2007.11.23 -
Webwasher-Gateway 6.0.1 2007.11.23 -
Additional information
File size: 1060864 bytes
MD5: f35a584e947a5b401feb0fe01db4a0d7
SHA1: 664dc99e78261a43d876311931694b6ef87cc8b9

————————————————
New HijackThis log

Logfile of HijackThis v1.99.1
Scan saved at 20:10:10, on 23/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\McAfee\Common Framework\FrameworkService.exe
D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
D:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\PowerISO\PWRISOVM.EXE
D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\BKV\Desktop\BKV.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virginmedia.com/welcome
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O4 - HKLM\..\Run: [ShStatEXE] "D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] "D:\Program Files\PowerISO\PWRISOVM.EXE"
O4 - HKLM\..\Run: [SpySweeper] "D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - D:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

———————————————————————————-

New ComboFix Log

ComboFix 07-11-19.3 - BKV 2007-11-23 19:51:43.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.50 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\BKV\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\VundoFix Backups
C:\WINDOWS\system32\elxfjbmg.ini
C:\WINDOWS\system32\gmbjfxle.dll
C:\WINDOWS\system32\hghjl.ini
C:\WINDOWS\system32\hghjl.ini2
C:\WINDOWS\system32\kjenbjrs.dll
C:\WINDOWS\system32\ljjhebb.dll
C:\WINDOWS\system32\smwoptpv.ini
C:\WINDOWS\system32\srjbnejk.ini
C:\WINDOWS\system32\vptpowms.dll
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp\abW9
C:\VundoFix Backups
C:\VundoFix Backups\awacowxq.dll.bad
C:\VundoFix Backups\ilnpo.ini.bad
C:\VundoFix Backups\ilnpo.ini2.bad
C:\VundoFix Backups\kknpo.ini.bad
C:\VundoFix Backups\kknpo.ini2.bad
C:\VundoFix Backups\opnkk.dll.bad
C:\VundoFix Backups\opnli.dll.bad
C:\VundoFix Backups\vcctuysc.dll.bad
C:\VundoFix Backups\vcctuysc.dllbox.bad
C:\WINDOWS\system32\elxfjbmg.ini
C:\WINDOWS\system32\gmbjfxle.dll
C:\WINDOWS\system32\hghjl.ini
C:\WINDOWS\system32\hghjl.ini2
C:\WINDOWS\system32\kjenbjrs.dll
C:\WINDOWS\system32\ljjhebb.dll
C:\WINDOWS\system32\rMa14yy
C:\WINDOWS\system32\smwoptpv.ini
C:\WINDOWS\system32\srjbnejk.ini
C:\WINDOWS\system32\vptpowms.dll

.
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.

2007-11-20 22:29 d——– C:\Documents and Settings\BKV\Application Data\Tiffen
2007-11-20 19:25 41,910,596 –a—— C:\backup-201107.reg
2007-11-18 12:13 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-18 09:33 d——– C:\WINDOWS\Sun
2007-11-18 09:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2007-11-18 09:28 5,387 –a—— C:\WINDOWS\system32\jupdate-1.6.0_03-b05.log
2007-11-18 09:27 d——– C:\Program Files\Java
2007-11-18 09:26 d——– C:\Program Files\Common Files\Java
2007-11-17 23:16 1,526,072 –a—— C:\WINDOWS\WRSetup.dll
2007-11-17 22:57 1,060,864 –a—— C:\WINDOWS\system32\mfc71.dll
2007-11-17 22:57 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-11-17 22:12 1,408 –a—— C:\WINDOWS\mozver.dat
2007-11-17 22:09 0 –a—— C:\WINDOWS\nsreg.dat
2007-11-17 14:22 d——– C:\Documents and Settings\LocalService\Application Data\Webroot
2007-11-17 14:20 d——– C:\Documents and Settings\All Users\Application Data\Webroot
2007-11-17 14:19 d——– C:\Documents and Settings\BKV\Application Data\Webroot
2007-11-17 11:45 d——– C:\Documents and Settings\BKV\Application Data\skypePM
2007-11-17 11:45 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-17 11:43 d——– C:\Documents and Settings\BKV\Application Data\Skype
2007-11-17 11:40 d——– C:\Program Files\Skype
2007-11-17 11:39 d——– C:\Program Files\Common Files\Skype
2007-11-17 11:39 d——– C:\Documents and Settings\All Users\Application Data\Skype
2007-11-17 10:04 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-17 08:43 d——– C:\Documents and Settings\BKV\Application Data\Systweak
2007-11-17 08:42 d——– C:\Temp
2007-11-16 21:59 d——– C:\Documents and Settings\BKV\Application Data\Font Fitting Room Deluxe
2007-11-15 19:25 26,496 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-15 19:24 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-11-15 12:43 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-11-15 12:43 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-11-15 12:43 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-11-15 12:42 6,058,496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-11-15 12:42 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-11-15 12:42 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-11-15 12:42 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-11-15 12:42 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2007-11-15 12:42 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-11-15 12:18 d——– C:\Program Files\Bonjour
2007-11-15 11:42 d——– C:\Program Files\Common Files\Macrovision Shared
2007-11-15 11:38 d——– C:\Program Files\Common Files\Adobe
2007-11-15 10:06 d——– C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-15 10:04 d——– C:\Program Files\Yahoo!
2007-11-15 00:11 1,474,560 –a—— C:\BOOTIMG.BIN
2007-11-15 00:11 2,048 –a—— C:\BOOTCAT.BIN
2007-11-14 21:05 d——– C:\Documents and Settings\BKV\Application Data\Media Player Classic
2007-11-14 19:26 d——– C:\Program Files\MSXML 6.0
2007-11-14 19:26 127,648 –a—— C:\WINDOWS\system32\TZLog.log
2007-11-14 19:25 d——– C:\Program Files\MSXML 4.0
2007-11-14 19:24 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-11-14 19:21 d–h—– C:\WINDOWS\$hf_mig$
2007-11-14 19:13 d—s—- C:\Documents and Settings\BKV\UserData
2007-11-14 18:04 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-14 17:41 d——– C:\Program Files\Common Files\Motive
2007-11-14 17:41 306,688 –a—— C:\WINDOWS\IsUninst.exe
2007-11-14 17:33 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-14 17:30 d——– C:\WINDOWS\35C03C043F1F42C2A989A757EE691F65.TMP
2007-11-14 17:25 d——– C:\Program Files\Common Files\McAfee
2007-11-14 17:25 d——– C:\Program Files\Common Files\Cisco Systems
2007-11-14 17:25 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2007-11-14 17:25 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2007-11-14 17:25 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2007-11-14 17:25 171,240 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2007-11-14 17:25 72,712 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-11-14 17:25 64,168 –a—— C:\WINDOWS\system32\drivers\mfeapfk.sys
2007-11-14 17:25 34,184 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 16:46 ——— d—–w C:\Program Files\microsoft frontpage
2007-11-14 16:38 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-10-20 00:56 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-10-01 16:24 23,864 —-a-w C:\WINDOWS\system32\drivers\sskbfd.sys
2007-10-01 16:24 21,816 —-a-w C:\WINDOWS\system32\drivers\sshrmd.sys
2007-10-01 16:24 20,280 —-a-w C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2007-10-01 16:24 163,640 —-a-w C:\WINDOWS\system32\drivers\ssidrv.sys
.

((((((((((((((((((((((((((((( snapshot@2007-11-22_17.26.45.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-08-07 00:15:07 33,052 —-a-w C:\WINDOWS\system32\drivers\scdemu.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"Yahoo! Pager"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-08-13 20:50]
"McAfeeUpdaterUI"="D:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 11:27]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"PWRISOVM.EXE"="D:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 00:05]
"SpySweeper"="D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 16:40]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56]

R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\WINDOWS\system32\Drivers\SSFS0BB9.SYS
R1 mfetdik;McAfee Inc.;C:\WINDOWS\system32\drivers\mfetdik.sys
R3 mfeapfk;McAfee Inc.;C:\WINDOWS\system32\drivers\mfeapfk.sys

.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-23 20:05:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-23 20:09:07 - machine was rebooted
C:\ComboFix2.txt … 2007-11-22 17:28
.
— E O F —
———————————————————————————————————————————————————
Hi

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete.
Scotty, Sorry for getting back with a delay. Here is the scan result. ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Sunday, November 25, 2007 7:45:37 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 25/11/2007 Kaspersky Anti-Virus database records: 465163 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ Scan Statistics: Total number of scanned objects: 60682 Number of viruses found: 7 Number of infected objects: 40 Number of suspicious objects: 0 Duration of the scan process: 04:01:30 Infected Object Name / Virus Name / Last Action C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\mofugclq.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\NI.UGA6P_0001_N122M2210\setup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\qrjatydi.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\rhvqsuwb.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\urclqecd.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\vntmrykt.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\~uga6psetup.exe/file14 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\~uga6psetup.exe/file20 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\~uga6psetup.exe/file34 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\~uga6psetup.exe/file36 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped C:\Deckard\System Scanner\20071120184656\backup\DOCUME~1\BKV\LOCALS~1\Temp\~uga6psetup.exe Inno: infected - 4 skipped C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\Agent_ABC-8D600C823AB.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\PrdMgr_ABC-8D600C823AB.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\AccessProtectionLog.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\BufferOverflowProtectionLog.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\OnAccessScanLog.txt Object is locked skipped C:\Documents and Settings\BKV\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\cert8.db Object is locked skipped C:\Documents and Settings\BKV\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\history.dat Object is locked skipped C:\Documents and Settings\BKV\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\key3.db Object is locked skipped C:\Documents and Settings\BKV\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\parent.lock Object is locked skipped C:\Documents and Settings\BKV\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\search.sqlite Object is locked skipped C:\Documents and Settings\BKV\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\BKV\Application Data\Webroot\Spy Sweeper\Logs\071125012119.ses Object is locked skipped C:\Documents and Settings\BKV\Cookies\index.dat Object is locked skipped C:\Documents and Settings\BKV\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\BKV\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\BKV\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\BKV\Local Settings\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\Cache\D0FAEFC2d01 Object is locked skipped C:\Documents and Settings\BKV\Local Settings\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\BKV\Local Settings\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\BKV\Local Settings\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\BKV\Local Settings\Application Data\Mozilla\Firefox\Profiles\a9uhyjdv.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\BKV\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\BKV\Local Settings\History\History.IE5\MSHist012007112520071126\index.dat Object is locked skipped C:\Documents and Settings\BKV\Local Settings\Temp\NAILogs\UpdaterUI_ABC-8D600C823AB.log Object is locked skipped C:\Documents and Settings\BKV\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\BKV\NTUSER.DAT Object is locked skipped C:\Documents and Settings\BKV\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS00078CE1-91A5-45BA-B530-214101C0899F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS01861553-053A-4347-AE7F-17F46F779BA6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS05927372-AAE4-4284-99A3-A96958B7ED17.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS05A066B8-A47B-439B-81A8-EC68DD5A42DD.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS07CF4730-D7D9-4858-93EA-F2EC4C76437B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0A0C51CA-C4AB-45EB-8475-B85945B3C417.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0A22E301-1626-4CEC-8F03-AE12B67CBCFA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0BD3F6CD-4210-4A4E-A8B1-527927B39F11.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0CD82749-8411-40D2-AFA3-9595B82A97FC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0E9EBBCD-BB27-4338-83D6-719232C156DC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS127308D6-DBDD-4122-A7C9-CC5752CD718E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS13BD18C6-CA63-4500-B797-3A6E360FB6AD.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS185FFBFC-3B5E-4506-9EAD-782263D650B6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS189ED761-646B-4AF8-A9BC-659F78C64EA9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1CFED549-DE4A-4588-ABFB-9944B5D19208.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS24E7FAD6-CBD7-4705-8113-1EEA6A4D7A28.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS272960F4-DF2F-47A8-B03F-AB5CAB4A5353.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2811EDF8-EF2F-458E-B283-051704E0BA71.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2A839A60-927E-41B4-81C6-C1B6BBF68292.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2DD4E2A1-7CE0-442A-8CF3-AA506BF3BA50.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2E112258-3F2D-425B-A3EF-07B331680267.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS33D3B70D-C5C7-492C-BB93-A1FE24562CDE.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS348ADA2A-A6AC-43EF-B7F3-03D1948071E3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3D05E10C-35B0-4648-B317-7800D866626C.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3D604DD1-787F-4CD2-8E9E-1AFFEEED6667.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3D90C481-113C-430F-BE7D-389125CB2806.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3E80175C-5364-47BC-A628-83C0F9ACD57B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS43D2D89F-8041-465A-955F-E079A5C6358B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS45872CB1-B78A-4D52-A53D-148A44086C53.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS45F6D07D-9554-4951-B340-0CCFF370A434.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5E6C7AEB-722A-4D31-80AE-F6D366C6C713.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5E8A64BD-C1EA-4718-97A1-23F16F8DD089.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5EB6342C-483B-4823-88DD-B1D84C735F7E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5F7F83E4-874B-40E6-86B3-0C3CE2B15B6C.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5F9F19FC-285E-48BE-BC50-7ABE8A7B4713.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS639FCE3E-92C2-44EB-A234-D224784F70C4.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS64135650-320D-4F96-AB9F-9C2353F7C323.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS645349CC-67C4-4634-93B5-7F4FE431176E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6B2054F3-30CC-48C2-8723-E86A22573333.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6DA90825-1560-4E0B-933D-0792315CA72A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6FD4B2E7-895E-4164-9BE2-4D352961EFA4.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS701CE031-2E6A-499A-BCB7-AC6346C35852.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS73DFC9C2-B76A-420B-A950-920F55036009.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7A45D603-960B-4C78-953E-E23394A781EE.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7BD2F24F-16AA-4C94-9DA3-C02E5BEB7E23.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7C049012-3B5A-4B48-89F8-A7216FC07756.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7D983F61-4F54-4ABA-A272-354509845D5A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7F06008B-1950-4CBA-BC36-1F089188A950.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS813DF42C-0335-4A99-AD7C-86E82CCCA2D0.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS874DC1F7-C564-4B63-AFCF-8CF3D7B09AEF.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS87DD959D-4177-4323-84A1-9E72DCFEFD0F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS89EA7919-C36D-4262-940D-2024BA33A054.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8D6C3C1F-5617-4C08-B7BE-9A68001E845F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8E24C813-DFC0-44BF-B7E2-3C27572B0DD7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS904276E2-7444-4327-A0F6-CCF1D490ABF8.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS923FF7EE-6601-4E91-9175-95111D4D5997.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS95559050-47D9-4B2D-A897-8464A9345A41.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9ABCA288-625A-4ADC-A5A5-21358D042419.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9B56ACFC-9896-4354-A8A4-23AE3A5CB1BA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA053A4E5-CE64-4CF3-9B60-7FB40E3D8108.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA35A3666-9B98-4631-93F6-232C4DDD81F8.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA590FEF5-B8B6-4619-B9F0-9AC1D0F6901D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA8257EB3-B5A4-44AE-8A3F-009EF72E2202.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAB55B2BC-323B-4D87-97C6-F5E89B106BDE.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB1CF7640-5A68-4F62-B761-BA49A0C4B1A9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB1EBA817-E39D-4B4D-8A1C-22CE89BF055F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB2D82058-8288-42FE-9B35-8AD1BF558935.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB3D2565C-D2A2-4BB1-A804-CAF090C0C144.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBA438B3F-E8C5-4C76-991B-AF01F8A5791A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC17270E8-3CF4-4BFE-88B5-F4F56A3EB1A9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC4C0EE7F-A088-446D-8208-910802A599AA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC53E3A2A-D7A4-4FC6-99F4-F4ED9F217B0D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC57AC371-97CB-4846-BFD8-E5A6E5EE070C.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCB206FDB-6278-4870-9863-9C3048318D07.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCFF02708-86AF-401C-BA9A-70DBE1568BF5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD950E9B4-3398-4575-AB18-E91D3C087FF7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDF4DB805-143E-4B10-B378-F19EB5DCE9DE.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0EF9684-7241-4299-9D0D-763125F4CBE7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE8C33C13-BB86-450C-BE72-FDA6A4CC45F8.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEA502CA3-E8A7-436E-A3CD-B8B19CA56CFF.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEA759E19-9E7E-4EE3-9EBE-14FAB2C2B085.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSED75D30B-5EE2-447B-9D27-ABAE46A22C1F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEE3AC2C9-2E20-45C5-BBC9-D588A18553D5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF0951E5C-10D7-4B11-BEF6-98B63F04D397.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF1209A80-41E7-42BF-AE23-66168B7180F2.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF303490A-B08E-467C-850B-DF16C8BE5CB6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF7C4B087-9896-41DB-9E96-763693F43923.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF8B6B345-0207-4235-9A23-0F64FE6866DB.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFDCCE2A5-A95C-4D63-A260-4386CC78B0E1.tmp Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\qoobox\Quarantine\C\WINDOWS\system32\gmbjfxle.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\qoobox\Quarantine\C\WINDOWS\system32\kjenbjrs.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\qoobox\Quarantine\C\WINDOWS\system32\vptpowms.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\qoobox\Quarantine\catchme2007-11-23_200440.09.zip/ljjhebb.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ati skipped C:\qoobox\Quarantine\catchme2007-11-23_200440.09.zip ZIP: infected - 1 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{4829854F-8DDA-4FC6-88A0-E9DE4063E196}\RP22\A0009921.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\System Volume Information\_restore{4829854F-8DDA-4FC6-88A0-E9DE4063E196}\RP22\A0009923.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\System Volume Information\_restore{4829854F-8DDA-4FC6-88A0-E9DE4063E196}\RP22\A0009926.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\System Volume Information\_restore{4829854F-8DDA-4FC6-88A0-E9DE4063E196}\RP24\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped D:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped D:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped D:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped D:\System Volume Information\_restore{4829854F-8DDA-4FC6-88A0-E9DE4063E196}\RP24\change.log Object is locked skipped H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped H:\System Volume Information\_restore{4829854F-8DDA-4FC6-88A0-E9DE4063E196}\RP21\A0009862.exe/install.exe/data0007/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{4829854F-8DDA-4FC6-88A0-E9DE4063E196}\RP21\A0009862.exe/install.exe/data0007 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{4829854F-8DDA-4FC6-88A0-E9DE4063E196}\RP21\A0009862.exe/install.exe Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{4829854F-8DDA-4FC6-88A0-E9DE4063E196}\RP21\A0009862.exe ZIP: infected - 3 skipped H:\System Volume Information\_restore{64418BF6-331A-43FA-9D88-BE1673023502}\RP3\A0002149.exe/data.rar/integrate.exe Infected: Backdoor.Win32.Bifrose.aij skipped H:\System Volume Information\_restore{64418BF6-331A-43FA-9D88-BE1673023502}\RP3\A0002149.exe/data.rar Infected: Backdoor.Win32.Bifrose.aij skipped H:\System Volume Information\_restore{64418BF6-331A-43FA-9D88-BE1673023502}\RP3\A0002149.exe RarSFX: infected - 2 skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP38\A0007951.exe/data0007/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP38\A0007951.exe/data0007 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP38\A0007951.exe NSIS: infected - 2 skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP39\A0007957.exe/install.exe/data0007/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP39\A0007957.exe/install.exe/data0007 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP39\A0007957.exe/install.exe Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP39\A0007957.exe ZIP: infected - 3 skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP61\A0011019.exe/data0007/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP61\A0011019.exe/data0007 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP61\A0011019.exe NSIS: infected - 2 skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP62\A0011022.exe/install.exe/data0007/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP62\A0011022.exe/install.exe/data0007 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP62\A0011022.exe/install.exe Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped H:\System Volume Information\_restore{9FB8190E-6C3B-4FA8-B34B-C271369BC13B}\RP62\A0011022.exe ZIP: infected - 3 skipped Scan process completed. ——————————————————————————————– Thanks, Vel

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI