This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Require Assistance

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello I'm pretty sure my computer has a bug and I was hoping someone can help me fix it? Also, I don't know if this is relevant but I upgraded my XP home edition to Pro, and its been slower. I also can't install security updates for some reason… Heres my HijackThis Log Logfile of HijackThis v1.99.1 Scan saved at 2:55:55 PM, on 1/4/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Comodo\Firewall\cmdagent.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Comodo\Firewall\CPF.exe C:\WINDOWS\stsystra.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp .exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc .exe C:\Program Files\Comodo\Firewall\CPF .exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\QdrPack\QdrPack11.exe C:\Program Files\QdrPack\QdrPack11 .exe C:\Program Files\3M\PSNLite\PsnLite.exe C:\PROGRA~1\3M\PSNLite\PSNGive.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\drwtsn32.exe C:\WINDOWS\system32\drwtsn32.exe C:\WINDOWS\explorer.exe C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE C:\Documents and Settings\Albert Lee\My Documents\Downloads\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local F3 - REG:win.ini: load=C:\WINDOWS\system32\ddcyv.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime O4 - HKLM\..\Run: [f848a003] rundll32.exe "C:\WINDOWS\system32\bqoylsmt.dll",b O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent .exe" –force_start_minimized O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [QdrModule11] "C:\Program Files\QdrModule\QdrModule11.exe" O4 - HKCU\..\Run: [QdrPack11] "C:\Program Files\QdrPack\QdrPack11.exe" O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: SQL Server (CSSQL05) (MSSQL$CSSQL05) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sCSSQL05 (file missing) O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe Appreciate the help!
Hello alrt and welcome back to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


A. Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.


B. Some trojans have a way of masking their presence from the HijackThis program when they recognise the name. I think that this is the case here because there are no 02 or 020 entries visible in your log.

Please locate the following file on your desktop: HijackThis.exe
Next, right click on the file and from the popup menu that appears, chose the RENAME option and rename the file Killer.exe.

From now on, when I ask you to start HijackThis, just click on the Killer.exe file.


C. Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • First, physically disconnect your computer from the internet.
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix.
  • Now you may reconnect your machine to the internet and post the logs

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
Hi, Ok so I changed Hijackthis to Killer and I have the list for installed programs, but when I tried to open the ComboFix link it allows to click save… and then nothing happens… Ad-Aware 2007 Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player 9 ActiveX Adobe Help Center 1.0 Adobe Photoshop CS2 Adobe Photoshop CS3 Adobe Reader 8.1.1 Adobe Stock Photos 1.0 AIM 6 Apple Software Update ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver avast! Antivirus BitTorrent 5.0.9 Bonjour Core for Windows Broadcom 440x 10/100 Integrated Controller CambridgeSoft Activation Client CambridgeSoft BioAssay 11.0 CambridgeSoft ChemBioOffice Ultra 2008 CambridgeSoft ChemScript 11.0 CambridgeSoft ENotebook 11.0 CambridgeSoft Inventory 11.0 Canon Camera Access Library Canon Camera Support Core Library Canon Camera Window DC_DV 5 for ZoomBrowser EX Canon Camera Window DC_DV 6 for ZoomBrowser EX Canon Camera Window DSLR 5 for ZoomBrowser EX Canon Camera Window MC 6 for ZoomBrowser EX Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon Utilities PhotoStitch 3.1 Canon ZoomBrowser EX (E) COMODO Firewall Pro Conexant HDA D110 MDC V.92 Modem DivX Codec DivX Content Uploader DivX Converter DivX Player DivX Web Player eMule Flipper Graph Control GOM Player HijackThis 1.99.1 Intel® PROSet/Wireless Software Internet Speed Monitor Java DB 10.2.2.0 Java™ 6 Update 2 Java™ 6 Update 3 Java™ SE Development Kit 6 Update 2 mCore mDriver mDrWiFi MestReC 4.7.0 mHlpDell Microsoft .NET Framework 2.0 Microsoft Office Professional Edition 2003 Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (CSSQL05) Microsoft SQL Server 2005 Tools Express Edition Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer mIWA mLogView mMHouse Mozilla Firefox (2.0.0.11) mPfMgr mPfWiz mProSafe mSCfg mSSO MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB933579) mWlsSafe mWMI mZConfig Post-it® Software Notes Lite PowerDVD 5.7 Python 2.5 QuickTime Rainlendar2 (remove only) RarZilla Free Unrar 2.00 Real Alternative 1.7.5 Ruckus Player Security Update for Microsoft .NET Framework 2.0 (KB928365) Security Update for Windows XP (KB923789) Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) SigmaTel Audio Starcraft VeohTV BETA Viewpoint Media Player Winamp Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04) Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10
Did you try downloading from BOTH links provided? I just successfully downloaded CF from both. The downloads both started off fast but took close to a minute to finish.
ComboFix 08-01-05.1 - Albert Lee 2008-01-04 20:12:00.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.578 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Albert Lee\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Albert Lee\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Albert Lee\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Alwil Software\Avast4\ashDisp .exe
C:\Program Files\BitTorrent\bittorrent .exe
C:\Program Files\BitTorrent\bittorrent .exe
C:\Program Files\BitTorrent\bittorrent .exe
C:\Program Files\BitTorrent\bittorrent .exe
C:\Program Files\BitTorrent\bittorrent .exe
C:\Program Files\BitTorrent\bittorrent .exe
C:\Program Files\BitTorrent\bittorrent .exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\QdrDrive9.dll
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dic.gz
C:\Program Files\QdrModule\kwd.gz
C:\Program Files\QdrModule\QdrModule11 .exe
C:\Program Files\QdrPack
C:\Program Files\QdrPack\dicts.gz
C:\Program Files\QdrPack\QdrPack11 .exe
C:\Program Files\QdrPack\QdrPack11.exe
C:\Program Files\QdrPack\trgts.gz
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\ctkvlgfx.dll
C:\WINDOWS\system32\ddcyv.exe
C:\WINDOWS\system32\dfxbsspt.dll
C:\WINDOWS\system32\favnxryx.dll
C:\WINDOWS\system32\hylqnplx.ini
C:\WINDOWS\system32\ikilnniv.dll
C:\WINDOWS\system32\IME\PINTLGNT\ImScInst .exe
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP .EXE
C:\WINDOWS\system32\jouimoxe.dll
C:\WINDOWS\system32\pqcypokx.ini
C:\WINDOWS\system32\qnpfrrxa.dll
C:\WINDOWS\system32\RCX2C.tmp
C:\WINDOWS\system32\RCX2F.tmp
C:\WINDOWS\system32\RCX30.tmp
C:\WINDOWS\system32\RCX35.tmp
C:\WINDOWS\system32\RCX36.tmp
C:\WINDOWS\system32\tpssbxfd.ini
C:\WINDOWS\system32\vycdd.ini
C:\WINDOWS\system32\vycdd.ini2
C:\WINDOWS\system32\wjypsqsp.dll
C:\WINDOWS\system32\xkopycqp.dll
C:\WINDOWS\system32\xlpnqlyh.dll
C:\WINDOWS\system32\xxyxyvw.dll

"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe" replaces infected copy of "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"C:\Program Files\Alwil Software\Avast4\ashDisp .exe" moved to QooBox
"C:\Program Files\BitTorrent\bittorrent		.exe" replaces infected copy of "C:\Program Files\BitTorrent\bittorrent.exe"
"C:\Program Files\Comodo\Firewall\CPF .exe" replaces infected copy of "C:\Program Files\Comodo\Firewall\CPF.exe"
"C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe" replaces infected copy of "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe"
"C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe" replaces infected copy of "C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe"
"C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe" replaces infected copy of "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
"C:\Program Files\QdrPack\QdrPack11 .exe" moved to QooBox
"C:\Program Files\QuickTime\QTTask		  .exe" replaces infected copy of "C:\Program Files\QuickTime\QTTask.exe"
"C:\Program Files\Winamp\winampa .exe" replaces infected copy of "C:\Program Files\Winamp\winampa.exe"
"C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE" moved to QooBox
"C:\WINDOWS\system32\ctfmon .exe" moved to QooBox
"C:\WINDOWS\system32\IME\PINTLGNT\ImScInst .exe" moved to QooBox
"C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP .EXE" moved to QooBox
.
.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.

2008-01-04 20:10 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-04 14:51 . 2008-01-04 14:51 1,043,800 –ahs—- C:\WINDOWS\system32\tmslyoqb.ini
2008-01-03 13:12 . 2008-01-03 13:15 1,038,364 –ahs—- C:\WINDOWS\system32\mmqxayuy.ini
2008-01-02 00:42 . 2008-01-02 00:42 1,031,139 –ahs—- C:\WINDOWS\system32\dxhftgfk.ini
2007-12-31 02:16 . 2007-12-31 02:17 d——– C:\Program Files\Real Alternative
2007-12-28 15:54 . 2007-12-28 15:54 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-28 15:54 . 2007-12-28 15:54 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-19 15:54 . 2007-12-19 15:54 6,032 –a—— C:\WirelessDiagLog.csv
2007-12-15 10:38 . 2008-01-04 20:19 d——– C:\Program Files\QuickTime
2007-12-15 10:38 . 2007-12-15 10:38 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-14 13:47 . 2006-02-28 07:00 811,064 –a—— C:\WINDOWS\system32\imjp81k.dll
2007-12-14 13:38 . 2007-12-14 13:38 13,668 –a—— C:\WINDOWS\system32\wpa.bak
2007-12-14 13:33 . 2006-02-28 07:00 456,704 –a–c— C:\WINDOWS\system32\dllcache\smtpsvc.dll
2007-12-14 13:32 . 2006-02-28 07:00 562,176 –a–c— C:\WINDOWS\system32\dllcache\fxsst.dll
2007-12-14 13:31 . 2006-02-28 07:00 2,134,528 –a–c— C:\WINDOWS\system32\dllcache\smtpsnap.dll
2007-12-14 13:30 . 2003-03-24 16:52 20,540 –a–c— C:\WINDOWS\system32\dllcache\admin.dll
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\WindowsShell.Manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\wuaucpl.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\sapi.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\nwc.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\ncpa.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 488 -rah—– C:\WINDOWS\system32\logonui.exe.manifest
2007-12-14 13:27 . 2006-02-28 07:00 16,384 –a–c— C:\WINDOWS\system32\dllcache\isignup.exe
2007-12-14 13:25 . 2006-02-28 07:00 358,912 –a–c— C:\WINDOWS\system32\dllcache\wmic.exe
2007-12-14 13:25 . 2006-02-28 07:00 92,672 –a–c— C:\WINDOWS\system32\dllcache\policman.dll
2007-12-14 08:04 . 2007-12-14 08:13 d——– C:\WINDOWS\ehome
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 01:19 ——— d—–w C:\Program Files\Winamp
2008-01-05 01:19 ——— d—–w C:\Program Files\BitTorrent
2008-01-05 01:03 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\BitTorrent
2008-01-04 22:55 ——— d—–w C:\Program Files\Starcraft
2008-01-02 07:27 ——— d—–w C:\Program Files\LimeWire
2008-01-02 04:30 ——— d—–w C:\Program Files\Rainlendar2
2007-12-19 21:39 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\LimeWire
2007-12-15 15:52 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\U3
2007-12-05 21:21 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\Ruckus Network
2007-12-04 14:56 93,264 —-a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 —-a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 —-a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 —-a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 —-a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-11-24 18:47 ——— d—–w C:\Program Files\AIM6
2007-11-24 18:46 ——— d—–w C:\Program Files\Viewpoint
2007-11-24 18:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-24 18:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-11-24 18:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-11-13 02:51 ——— d—–w C:\Program Files\Java
2007-11-11 23:31 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-11 23:30 ——— d—–w C:\Program Files\Veoh Networks
2007-11-10 01:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Comodo
2007-11-10 01:16 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\Comodo
2007-11-10 01:15 ——— d—–w C:\Program Files\Comodo
2007-11-09 18:39 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-11-09 18:34 ——— d—–w C:\Program Files\MestRe-C
2007-11-09 18:28 ——— d—–w C:\Program Files\ProWorks
2007-11-09 18:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\CambridgeSoft
2007-11-09 18:15 ——— d—–w C:\Program Files\CambridgeSoft
2007-11-09 03:58 ——— d—–w C:\Program Files\Apple Software Update
2007-11-09 03:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-10 18:18 21,393 —-a-w C:\WINDOWS\AegisP.sys
.
—-a-w		 1,298,432 2008-01-02 04:31:00  C:\Program Files\Rainlendar2\Rainlendar2 .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"Rainlendar2"="C:\Program Files\Rainlendar2\Rainlendar2.exe" [ ]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent .exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 07:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-04 20:02 132496]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2008-01-04 20:02 823296]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2008-01-04 20:02 974848]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-01-04 20:02 1115728]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-04 20:02 39792]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 16:30 282624 C:\WINDOWS\stsystra.exe]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2006-02-28 07:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2006-02-28 07:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2006-02-28 07:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2006-02-28 07:00 455168]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Post-itr Software Notes Lite.lnk - C:\Program Files\3M\PSNLite\PsnLite.exe [2004-10-15 13:26:54]

[HKLM\~\startupfolder\C:^Documents and Settings^Albert Lee^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Albert Lee\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-04 20:02 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2006-01-02 16:41 45056 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
–a—— 2008-01-04 20:02 43008 C:\Program Files\BitTorrent\bittorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
–a—— 2005-12-09 19:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-01-03 17:33 37376 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)

R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S2 MSSQL$CSSQL05;SQL Server (CSSQL05);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" [2007-02-10 09:29]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c709e89-9e18-11dc-9b4a-0015c51c645b}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-12-15 15:35:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 20:24:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-04 20:25:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-05 01:25:57
.
2008-01-04 08:00:36 — E O F —

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^




Logfile of HijackThis v1.99.1
Scan saved at 8:39:34 PM, on 1/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\Albert Lee\My Documents\Downloads\Firefox Setup 2.0.0.4.exe
C:\Documents and Settings\Albert Lee\My Documents\Downloads\Killer.exe
C:\DOCUME~1\ALBERT~1\LOCALS~1\Temp\7zS3.tmp\setup.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent .exe" –force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: SQL Server (CSSQL05) (MSSQL$CSSQL05) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sCSSQL05 (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
The tool has repaired a lot of the damage. We will repair some more and then evaluate what is left to do.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
File::
C:\WINDOWS\system32\tmslyoqb.ini
C:\WINDOWS\system32\mmqxayuy.ini
C:\WINDOWS\system32\dxhftgfk.ini
C:\WINDOWS\QTFont.qfn
C:\WINDOWS\QTFont.for

RenV::
—-a-w		 1,298,432 2008-01-02 04:31:00  C:\Program Files\Rainlendar2\Rainlendar2 .exe

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply after you re-enable all the programs that were disabled during the running of ComboFix:
  • Combofix.txt
  • A new HijackThis log.
Please take note:

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 08-01-05.1 - Albert Lee 2008-01-04 21:16:40.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.516 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Albert Lee\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\QTFont.for
C:\WINDOWS\QTFont.qfn
C:\WINDOWS\system32\dxhftgfk.ini
C:\WINDOWS\system32\mmqxayuy.ini
C:\WINDOWS\system32\tmslyoqb.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\QTFont.for
C:\WINDOWS\QTFont.qfn
C:\WINDOWS\system32\dxhftgfk.ini
C:\WINDOWS\system32\mmqxayuy.ini
C:\WINDOWS\system32\tmslyoqb.ini

.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.

2008-01-04 20:10 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-31 02:16 . 2007-12-31 02:17 d——– C:\Program Files\Real Alternative
2007-12-19 15:54 . 2007-12-19 15:54 6,032 –a—— C:\WirelessDiagLog.csv
2007-12-15 10:38 . 2008-01-04 20:19 d——– C:\Program Files\QuickTime
2007-12-15 10:38 . 2007-12-15 10:38 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-14 13:47 . 2006-02-28 07:00 811,064 –a—— C:\WINDOWS\system32\imjp81k.dll
2007-12-14 13:38 . 2007-12-14 13:38 13,668 –a—— C:\WINDOWS\system32\wpa.bak
2007-12-14 13:33 . 2006-02-28 07:00 456,704 –a–c— C:\WINDOWS\system32\dllcache\smtpsvc.dll
2007-12-14 13:32 . 2006-02-28 07:00 562,176 –a–c— C:\WINDOWS\system32\dllcache\fxsst.dll
2007-12-14 13:31 . 2006-02-28 07:00 2,134,528 –a–c— C:\WINDOWS\system32\dllcache\smtpsnap.dll
2007-12-14 13:30 . 2003-03-24 16:52 20,540 –a–c— C:\WINDOWS\system32\dllcache\admin.dll
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\WindowsShell.Manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\wuaucpl.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\sapi.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\nwc.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\ncpa.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 488 -rah—– C:\WINDOWS\system32\logonui.exe.manifest
2007-12-14 13:27 . 2006-02-28 07:00 16,384 –a–c— C:\WINDOWS\system32\dllcache\isignup.exe
2007-12-14 13:25 . 2006-02-28 07:00 358,912 –a–c— C:\WINDOWS\system32\dllcache\wmic.exe
2007-12-14 13:25 . 2006-02-28 07:00 92,672 –a–c— C:\WINDOWS\system32\dllcache\policman.dll
2007-12-14 08:04 . 2007-12-14 08:13 d——– C:\WINDOWS\ehome
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 02:16 ——— d—–w C:\Program Files\Rainlendar2
2008-01-05 01:19 ——— d—–w C:\Program Files\Winamp
2008-01-05 01:19 ——— d—–w C:\Program Files\BitTorrent
2008-01-05 01:03 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\BitTorrent
2008-01-04 22:55 ——— d—–w C:\Program Files\Starcraft
2008-01-02 07:27 ——— d—–w C:\Program Files\LimeWire
2007-12-19 21:39 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\LimeWire
2007-12-15 15:52 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\U3
2007-12-05 21:21 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\Ruckus Network
2007-12-04 14:56 93,264 —-a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 —-a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 —-a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 —-a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 —-a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 —-a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 —-a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-24 18:47 ——— d—–w C:\Program Files\AIM6
2007-11-24 18:46 ——— d—–w C:\Program Files\Viewpoint
2007-11-24 18:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-24 18:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-11-24 18:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-11-13 02:51 ——— d—–w C:\Program Files\Java
2007-11-11 23:31 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-11 23:30 ——— d—–w C:\Program Files\Veoh Networks
2007-11-10 01:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Comodo
2007-11-10 01:16 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\Comodo
2007-11-10 01:15 ——— d—–w C:\Program Files\Comodo
2007-11-09 18:39 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-11-09 18:34 ——— d—–w C:\Program Files\MestRe-C
2007-11-09 18:28 ——— d—–w C:\Program Files\ProWorks
2007-11-09 18:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\CambridgeSoft
2007-11-09 18:15 ——— d—–w C:\Program Files\CambridgeSoft
2007-11-09 03:58 ——— d—–w C:\Program Files\Apple Software Update
2007-11-09 03:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-27 01:30 116,152 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_10_25_20_11_24_small.dmp.zip
2007-10-15 17:48 120,927 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_10_15_12_46_26_small.dmp.zip
2007-10-10 18:18 21,393 —-a-w C:\WINDOWS\AegisP.sys
2007-08-22 18:48 116,099 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_08_22_11_43_08_small.dmp.zip
2007-08-22 18:48 113,162 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_08_22_10_23_54_small.dmp.zip
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"Rainlendar2"="C:\Program Files\Rainlendar2\Rainlendar2.exe" [2008-01-01 23:31 1298432]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent .exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 07:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-04 20:02 132496]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2008-01-04 20:02 823296]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2008-01-04 20:02 974848]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-01-04 20:02 1115728]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-04 20:02 39792]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 16:30 282624 C:\WINDOWS\stsystra.exe]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2006-02-28 07:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2006-02-28 07:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2006-02-28 07:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2006-02-28 07:00 455168]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Post-itr Software Notes Lite.lnk - C:\Program Files\3M\PSNLite\PsnLite.exe [2004-10-15 13:26:54]

[HKLM\~\startupfolder\C:^Documents and Settings^Albert Lee^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Albert Lee\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-04 20:02 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2006-01-02 16:41 45056 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
–a—— 2008-01-04 20:02 43008 C:\Program Files\BitTorrent\bittorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
–a—— 2005-12-09 19:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-01-03 17:33 37376 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)

R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S2 MSSQL$CSSQL05;SQL Server (CSSQL05);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" [2007-02-10 09:29]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c709e89-9e18-11dc-9b4a-0015c51c645b}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-12-15 15:35:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 21:18:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-04 21:18:45
ComboFix-quarantined-files.txt 2008-01-05 02:18:43
ComboFix2.txt 2008-01-05 01:25:59
.
2008-01-04 08:00:36 — E O F —


Hijackthis Log

Logfile of HijackThis v1.99.1
Scan saved at 9:20:51 PM, on 1/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Comodo\Firewall\cpf.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Albert Lee\My Documents\Downloads\Killer.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent .exe" –force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: SQL Server (CSSQL05) (MSSQL$CSSQL05) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sCSSQL05 (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
The tool did its job. Unfortunately, there are four of your programs that can not be repaired because no replacement files are available:

Please uninstall then reinstall the following programs:

Aim
BitTorrent
QuickTime
Avast

Some elements of the above programs may work but there are fatal problems with them all. Your Antivirus is of major concern right now. Be advised that file sharing is always dangerous.

Please perform the above and run ComboFix again, please


Trevuren
sure no problem

ComboFix 08-01-05.1 - Albert Lee 2008-01-08 15:16:41.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.540 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-08 to 2008-01-08 )))))))))))))))))))))))))))))))
.

2008-01-08 15:16 . 2008-01-08 15:16 d——– C:\WINDOWS\LastGood
2008-01-04 22:27 . 2008-01-04 22:27 d——– C:\Documents and Settings\Albert Lee\Application Data\acccore
2008-01-04 22:25 . 2008-01-04 22:26 d——– C:\Program Files\AIM6
2008-01-04 22:24 . 2008-01-04 22:24 d——– C:\Program Files\QuickTime
2008-01-04 22:24 . 2008-01-04 22:24 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-04 22:16 . 2008-01-04 22:16 d——– C:\Program Files\DNA
2008-01-04 22:16 . 2008-01-08 06:03 d——– C:\Documents and Settings\Albert Lee\Application Data\DNA
2008-01-04 22:10 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-04 22:10 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-04 22:10 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2008-01-04 22:10 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-04 22:10 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-04 22:10 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-04 22:10 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-04 22:10 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-04 20:10 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-31 02:16 . 2007-12-31 02:17 d——– C:\Program Files\Real Alternative
2007-12-19 15:54 . 2007-12-19 15:54 6,032 –a—— C:\WirelessDiagLog.csv
2007-12-14 13:47 . 2006-02-28 07:00 811,064 –a—— C:\WINDOWS\system32\imjp81k.dll
2007-12-14 13:38 . 2007-12-14 13:38 13,668 –a—— C:\WINDOWS\system32\wpa.bak
2007-12-14 13:33 . 2006-02-28 07:00 456,704 –a–c— C:\WINDOWS\system32\dllcache\smtpsvc.dll
2007-12-14 13:32 . 2006-02-28 07:00 562,176 –a–c— C:\WINDOWS\system32\dllcache\fxsst.dll
2007-12-14 13:31 . 2006-02-28 07:00 2,134,528 –a–c— C:\WINDOWS\system32\dllcache\smtpsnap.dll
2007-12-14 13:30 . 2003-03-24 16:52 20,540 –a–c— C:\WINDOWS\system32\dllcache\admin.dll
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\WindowsShell.Manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\wuaucpl.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\sapi.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\nwc.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 749 -rah—– C:\WINDOWS\system32\ncpa.cpl.manifest
2007-12-14 13:28 . 2007-12-14 13:28 488 -rah—– C:\WINDOWS\system32\logonui.exe.manifest
2007-12-14 13:27 . 2006-02-28 07:00 16,384 –a–c— C:\WINDOWS\system32\dllcache\isignup.exe
2007-12-14 13:25 . 2006-02-28 07:00 358,912 –a–c— C:\WINDOWS\system32\dllcache\wmic.exe
2007-12-14 13:25 . 2006-02-28 07:00 92,672 –a–c— C:\WINDOWS\system32\dllcache\policman.dll
2007-12-14 08:04 . 2007-12-14 08:13 d——– C:\WINDOWS\ehome
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-08 20:16 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\BitTorrent
2008-01-08 04:03 ——— d—–w C:\Program Files\Starcraft
2008-01-05 03:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-05 03:25 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-05 03:16 ——— d—–w C:\Program Files\BitTorrent
2008-01-05 03:06 ——— d—–w C:\Program Files\Rainlendar2
2008-01-05 03:02 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-05 01:19 ——— d—–w C:\Program Files\Winamp
2008-01-02 07:27 ——— d—–w C:\Program Files\LimeWire
2007-12-19 21:39 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\LimeWire
2007-12-15 15:52 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\U3
2007-12-05 21:21 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\Ruckus Network
2007-11-24 18:46 ——— d—–w C:\Program Files\Viewpoint
2007-11-24 18:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-11-13 02:51 ——— d—–w C:\Program Files\Java
2007-11-11 23:31 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-11 23:30 ——— d—–w C:\Program Files\Veoh Networks
2007-11-10 01:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Comodo
2007-11-10 01:16 ——— d—–w C:\Documents and Settings\Albert Lee\Application Data\Comodo
2007-11-10 01:15 ——— d—–w C:\Program Files\Comodo
2007-11-09 18:39 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-11-09 18:34 ——— d—–w C:\Program Files\MestRe-C
2007-11-09 18:28 ——— d—–w C:\Program Files\ProWorks
2007-11-09 18:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\CambridgeSoft
2007-11-09 18:15 ——— d—–w C:\Program Files\CambridgeSoft
2007-11-09 03:58 ——— d—–w C:\Program Files\Apple Software Update
2007-11-09 03:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-27 01:30 116,152 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_10_25_20_11_24_small.dmp.zip
2007-10-15 17:48 120,927 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_10_15_12_46_26_small.dmp.zip
2007-10-10 18:18 21,393 —-a-w C:\WINDOWS\AegisP.sys
2007-08-22 18:48 116,099 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_08_22_11_43_08_small.dmp.zip
2007-08-22 18:48 113,162 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_08_22_10_23_54_small.dmp.zip
.

((((((((((((((((((((((((((((( snapshot@2008-01-04_20.25.44.09 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-24 18:46:21 38,428 —-a-w C:\WINDOWS\Downloaded Program Files\unagiuninst.exe
+ 2008-01-05 03:26:11 38,428 —-a-w C:\WINDOWS\Downloaded Program Files\unagiuninst.exe
+ 2008-01-05 03:03:53 262,144 —-a-w C:\WINDOWS\system32\config\systemprofile\NtUser.dat
- 2007-06-11 17:34:00 2,115,816 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2007-11-21 00:52:38 2,884,992 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
- 2007-06-11 17:34:00 190,696 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2007-11-21 00:52:40 218,496 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-01-07 00:37:58 70,264 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-01-08 20:14:16 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_660.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Rainlendar2"="C:\Program Files\Rainlendar2\Rainlendar2.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 07:00 15360]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-01-04 22:16 290112]
"Aim6"="" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-04 20:02 132496]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2008-01-04 20:02 823296]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2008-01-04 20:02 974848]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-04 20:02 39792]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 16:30 282624 C:\WINDOWS\stsystra.exe]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2006-02-28 07:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2006-02-28 07:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2006-02-28 07:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2006-02-28 07:00 455168]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Post-itr Software Notes Lite.lnk - C:\Program Files\3M\PSNLite\PsnLite.exe [2004-10-15 13:26:54]

[HKLM\~\startupfolder\C:^Documents and Settings^Albert Lee^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Albert Lee\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-04 20:02 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2006-01-02 16:41 45056 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
–a—— 2007-11-27 17:45 588080 C:\Program Files\BitTorrent\bittorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
–a—— 2005-12-09 19:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-01-03 17:33 37376 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)

R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S2 MSSQL$CSSQL05;SQL Server (CSSQL05);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" [2007-02-10 09:29]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c709e89-9e18-11dc-9b4a-0015c51c645b}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-01-05 15:35:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-08 15:20:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-08 15:20:37
ComboFix-quarantined-files.txt 2008-01-08 20:20:34
ComboFix2.txt 2008-01-05 02:18:46
ComboFix3.txt 2008-01-05 01:25:59
.
2008-01-08 08:00:39 — E O F —






Logfile of HijackThis v1.99.1
Scan saved at 3:22:06 PM, on 1/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Albert Lee\My Documents\Downloads\Killer.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: SQL Server (CSSQL05) (MSSQL$CSSQL05) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sCSSQL05 (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
A. Launch Notepad, and copy/paste everything in the codebox below into the new document, including the word REGEDIT4. Go up to "File Save As" and click the drop-down box to change the "Save As Type" to "All Files" and save it to your desktop as fixme.reg.

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Rainlendar2"=-
"Aim6"=-


Locate fixme.reg on your Desktop. It should look like this [external image: Posted Image]. Double-click on it. You will receive a prompt similar to: "Do you wish to merge the information into the registry?". Answer Yes and wait for a message to appear similar to Merged Successfully.

Restart your computer.


B. Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Choose "Global" from the frop down box at the top of the page.
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log
I hope you are well and not experiencing any difficulties carrying out my last set of instructions. If you are, do not hesitate to ask for further explanations. If however, your problem has been solved or you no longer require our assistance, please advise us accordingly and we will archive your topic.

Trevuren
I'm sorry! This scan took quite some time so I had to make sure I had enough time!

Logfile of HijackThis v1.99.1
Scan saved at 12:57:49 AM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Documents and Settings\Albert Lee\My Documents\Downloads\Killer.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: SQL Server (CSSQL05) (MSSQL$CSSQL05) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sCSSQL05 (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, January 14, 2008 12:56:58 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 14/01/2008
Kaspersky Anti-Virus database records: 510271
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 67002
Number of viruses found: 6
Number of infected objects: 193
Number of suspicious objects: 0
Duration of the scan process: 01:38:12

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Albert Lee\Application Data\3M\PSNotes\PSNData Object is locked skipped
C:\Documents and Settings\Albert Lee\Application Data\Mozilla\Firefox\Profiles\zg7n5rql.default\cert8.db Object is locked skipped
C:\Documents and Settings\Albert Lee\Application Data\Mozilla\Firefox\Profiles\zg7n5rql.default\history.dat Object is locked skipped
C:\Documents and Settings\Albert Lee\Application Data\Mozilla\Firefox\Profiles\zg7n5rql.default\key3.db Object is locked skipped
C:\Documents and Settings\Albert Lee\Application Data\Mozilla\Firefox\Profiles\zg7n5rql.default\parent.lock Object is locked skipped
C:\Documents and Settings\Albert Lee\Application Data\Mozilla\Firefox\Profiles\zg7n5rql.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Albert Lee\Application Data\Mozilla\Firefox\Profiles\zg7n5rql.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Albert Lee\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Albert Lee\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Albert Lee\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Albert Lee\Local Settings\Application Data\Mozilla\Firefox\Profiles\zg7n5rql.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Albert Lee\Local Settings\Application Data\Mozilla\Firefox\Profiles\zg7n5rql.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Albert Lee\Local Settings\Application Data\Mozilla\Firefox\Profiles\zg7n5rql.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Albert Lee\Local Settings\Application Data\Mozilla\Firefox\Profiles\zg7n5rql.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Albert Lee\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Albert Lee\Local Settings\Temp\~DFCDF7.tmp Object is locked skipped
C:\Documents and Settings\Albert Lee\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Albert Lee\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Albert Lee\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\QooBox\Quarantine\C\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\BitTorrent\bittorrent .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\BitTorrent\bittorrent .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\BitTorrent\bittorrent .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\BitTorrent\bittorrent .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\BitTorrent\bittorrent .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\BitTorrent\bittorrent .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\BitTorrent\bittorrent .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\BitTorrent\bittorrent.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Comodo\Firewall\CPF.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Intel\Wireless\Bin\ifrmewrk.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\ISM\ism.exe.vir Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_03\bin\jusched.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QdrPack\QdrPack11.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\QTTask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\QTTask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\QTTask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\QTTask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\QTTask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\QTTask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\QTTask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\QTTask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\QTTask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Winamp\winampa.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcyv.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\dfxbsspt.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX2C.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX2F.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX30.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX35.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX36.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xkopycqp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xlpnqlyh.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\QooBox\Quarantine\catchme2008-01-04_202401.54.zip/xxyxyvw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.clz skipped
C:\QooBox\Quarantine\catchme2008-01-04_202401.54.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002954.exe Infected: Trojan-Downloader.Win32.Osel.bx skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002955.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002963.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002967.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002968.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002969.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002970.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002971.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002972.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002976.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002977.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002978.EXE Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002979.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0002980.EXE Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0003960.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0003964.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0003966.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0003967.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0003968.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0003969.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0003970.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP37\A0003972.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP38\A0004004.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP38\A0004009.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP38\A0004013.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP38\A0004015.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP38\A0004017.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP38\A0004018.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP38\A0004019.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP38\A0004020.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP38\A0004021.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP38\A0004022.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0004056.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0004057.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005004.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005005.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005014.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005016.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005017.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005018.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005019.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005021.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005024.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005032.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005043.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP39\A0005057.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005094.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005095.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005096.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005097.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005098.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005099.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005100.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005101.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005107.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005108.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005119.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005126.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005129.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005130.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005131.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005132.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005133.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005134.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005135.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005136.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005143.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005145.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005162.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005334.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005341.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005342.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005344.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005345.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005346.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005347.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005348.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005349.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005354.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005374.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005382.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005389.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005391.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005392.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005393.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005394.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005395.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005396.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005397.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005402.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005420.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005435.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005438.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005439.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005440.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005441.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005442.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005443.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005444.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005445.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP40\A0005478.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP41\A0006431.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP41\A0006432.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP41\A0006439.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP41\A0006442.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP41\A0006443.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP41\A0006444.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP41\A0006445.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP41\A0006446.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP41\A0006450.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP41\A0006454.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006488.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006501.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006502.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006505.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006507.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006510.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006512.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006534.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006554.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dks skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006555.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP42\A0006556.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006574.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006576.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006582.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006583.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006594.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006595.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006596.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006597.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006598.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006599.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006600.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006601.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006602.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006603.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006604.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006605.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006606.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006607.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006608.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006609.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006610.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006611.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006612.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006613.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006614.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006615.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006616.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006620.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006621.exe Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006629.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.clz skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP43\A0006635.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6ABF04FD-4995-4F0F-BAC4-6D10105662A5}\RP57\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ime\imjp8_1\imjpmig.exe.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\IME\PINTLGNT\imscinst.exe.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\WINDOWS\system32\IME\TINTLGNT\tintsetp.exe.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_66c.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\ime\imjp8_1\imjpmig.exe.tmp
C:\WINDOWS\system32\IME\PINTLGNT\imscinst.exe.tmp
C:\WINDOWS\system32\IME\TINTLGNT\tintsetp.exe.tmp
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Next, re-enable all the programs that you disabled prior to running ComboFix.

8. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please also tell me how your system is running. If all is OK, we will proceed with the final cleanup procedures

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI