This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected with trojans of the win32 varity

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Umm maybe it was hooked up to my wireless router and I could access it with my laptop and the printers through it. But I've had it disconnected from the network and internet for awhile. do you want me to run the VundoFix now that it's running faster?
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
Hi

No need for Vundofix. We can use Combofix to nuke the baddies. I run Vundofix first to give me less work later. ;) You have one of the latest Vundo infections, I now know, that Vundofix isnt effective against.
I asked that question because this
Remote Administrator Service (r_server)
is a legit process but possibly strange to be on a home pc. I will leave it be as it could be part of another application.

Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

Folder::
C:\SDFix
C:\VundoFix Backups

RenV::
—-a-w		   313,472 2008-01-07 02:55:21  C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
—-a-w		 1,368,064 2008-01-07 02:54:28  C:\Program Files\Analog Devices\SoundMAX\SMax4PNP .exe
—-a-w		   396,316 2008-01-11 15:07:53  C:\Program Files\AtomTime Pro\AtomTime .EXE
—-a-w			73,728 2008-01-11 15:13:50  C:\Program Files\CloneCD\CloneCDTray .exe
—-a-w			45,056 2008-01-11 15:08:00  C:\Program Files\CloneCD\ElbyCheck .exe
—-a-w		   185,784 2008-01-11 15:14:01  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w		   462,336 2008-01-12 04:08:23  C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader .exe
—-a-w		   171,448 2008-01-07 02:55:17  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
—-a-w		   278,528 2008-01-11 15:13:55  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w			83,608 2008-01-11 15:13:52  C:\Program Files\Java\jre1.6.0_01\bin\jusched .exe
—-a-w			61,440 2008-01-12 04:08:24  C:\Program Files\LIVEUPDATE\LiveUpdate .exe
—-a-w		   892,928 2008-01-07 08:52:28  C:\Program Files\Logitech\iTouch\iTouch .exe
—-a-w			53,248 2008-01-12 04:08:25  C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask .exe
—-a-w		   278,528 2008-01-07 02:55:07  C:\Program Files\RAM Boost Pro\RAMBoostPro .exe
—-a-w		 1,179,648 2008-01-07 08:52:03  C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc .exe
—-a-w			32,768 2008-01-11 15:13:48  C:\Program Files\VCOM\SystemSuite\MemCheck .exe
—-a-w		   589,824 2008-01-11 06:47:46  C:\Program Files\VIA\RAID\raid_tool .exe
—-a-w			27,648 2008-01-11 15:07:57  C:\Program Files\WinFax\WFXSWTCH .exe
—-a-w		   155,648 2008-01-11 15:13:46  C:\WINDOWS\system32\NeroCheck .exe
—-a-w			98,304 2008-01-11 15:13:52  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIACA .EXE
—-a-w			99,840 2008-01-12 04:08:25  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2H1 .EXE

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smbt"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayaxus]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
It's been on my PC since I got it. My dad put WindowsXp Professional as the operating system since that was what he had and he built it. Which is probably why it is there even though it is a home PC. I've never used it.
Just so you know I am using my laptop and a jumpdrive to put things on my desktop.

ComboFix 08-01-18.5 - Sage 2008-01-20 11:36:15.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.929 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Sage\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\RegDACL.exe
C:\SDFix\apps\regedit.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\beep.sys
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\beep.sys
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\SecurityProviders.reg
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\srv2bk.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\winsec.reg
C:\SDFix\apps\zip.exe
C:\SDFix\backups\attrib.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\backups.zip
C:\SDFix\backups\find.exe
C:\SDFix\backups\findstr.exe
C:\SDFix\backups\HOSTS
C:\SDFix\backups\regedit.exe
C:\SDFix\catchme.exe
C:\SDFix\dummy.exe
C:\SDFix\dummy.sys
C:\SDFix\Report.txt
C:\SDFix\RunThis.bat
C:\SDFix\SDFIX_ReadMe_Online.url
C:\VundoFix Backups

.
((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.

2008-01-20 11:01 . 2004-08-03 23:00 260,272 –a—— C:\cmldr
2008-01-20 11:01 . 2006-05-17 16:45 211 –a—— C:\Boot.bak
2008-01-20 06:54 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-19 12:00 . 2008-01-19 12:00 d——– C:\WINDOWS\ERUNT
2008-01-11 19:25 . 2008-01-11 20:32 91,492 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-01-11 19:25 . 2008-01-11 20:32 85,860 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-01-11 19:19 . 2008-01-11 19:19 d——– C:\Program Files\Kaspersky Lab
2008-01-11 19:19 . 2008-01-19 12:59 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-11 19:18 . 2008-01-20 11:38 1,867,296 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-11 19:18 . 2008-01-20 07:05 27,548 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-11 19:18 . 2008-01-20 11:38 18,976 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-11 19:18 . 2008-01-20 07:05 2,468 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-11 19:13 . 2008-01-11 19:13 d——– C:\kav
2008-01-11 04:30 . 2008-01-11 04:30 d——– C:\Documents and Settings\Sage\Application Data\EPSON
2008-01-10 21:16 . 2008-01-11 03:15 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-10 21:07 . 2008-01-10 21:07 d——– C:\Program Files\Bonjour
2008-01-10 20:42 . 2008-01-10 20:42 d——– C:\Program Files\Common Files\Macrovision Shared
2008-01-06 18:54 . 2008-01-11 07:13 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2008-01-06 02:51 . 2006-04-20 03:51 359,808 ——— C:\WINDOWS\system32\drivers\tcpip.sys.ORIGINAL
2008-01-06 02:51 . 2006-04-20 03:51 359,808 —–c— C:\WINDOWS\system32\dllcache\tcpip.sys.ORIGINAL
2008-01-06 02:50 . 2008-01-15 17:59 d——– C:\Downloads
2008-01-06 02:50 . 2008-01-06 02:50 2,560 –a—— C:\WINDOWS\system32\bitcometres.dll
2008-01-06 02:48 . 2008-01-10 21:51 d——– C:\Program Files\BitComet
2008-01-02 21:44 . 2008-01-02 21:44 d——– C:\Program Files\STOIK Imaging
2008-01-02 21:44 . 2008-01-02 21:44 d——– C:\Documents and Settings\Sage\Application Data\STOIK
2007-12-28 13:01 . 2007-12-28 13:01 d——– C:\Documents and Settings\Sage\Application Data\iWin
2007-12-28 13:00 . 2008-01-06 08:24 d——– C:\Program Files\iWin.com
2007-12-28 13:00 . 2008-01-06 08:19 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 12:54 . 2007-12-28 12:54 d——– C:\Documents and Settings\All Users\Application Data\iWin Games
2007-12-25 06:48 . 2008-01-06 08:25 d——– C:\Program Files\JewelQuest_at
2007-12-23 10:58 . 2007-12-23 10:58 d——– C:\Documents and Settings\All Users\Application Data\Simple Star
2007-12-21 23:15 . 2007-12-21 23:15 d——– C:\Documents and Settings\All Users\Application Data\Nero

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 19:36 ——— d—–w C:\Program Files\WinFax
2008-01-20 19:36 ——— d—–w C:\Program Files\RAM Boost Pro
2008-01-20 19:36 ——— d—–w C:\Program Files\LIVEUPDATE
2008-01-20 19:36 ——— d—–w C:\Program Files\iTunes
2008-01-20 19:36 ——— d—–w C:\Program Files\CloneCD
2008-01-20 19:36 ——— d—–w C:\Program Files\AtomTime Pro
2008-01-20 15:07 ——— d—–w C:\Program Files\YPOPs
2008-01-20 15:03 ——— d—–w C:\Program Files\QuickTime
2008-01-11 16:34 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2008-01-11 14:15 ——— d—–w C:\Program Files\SmartDraw 2008
2008-01-11 06:17 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-11 04:53 ——— d—–w C:\Program Files\Trillian
2008-01-07 04:11 ——— d—–w C:\Documents and Settings\Sage\Application Data\Corel
2008-01-07 04:08 4,184 ——w C:\WINDOWS\system32\KGyGaAvL.sys
2008-01-06 16:57 359,808 ——w C:\WINDOWS\system32\drivers\tcpip.sys
2008-01-06 16:26 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-25 11:25 ——— d—–w C:\Documents and Settings\Sage\Application Data\Nero
2007-12-23 20:12 ——— d—–w C:\Program Files\Common Files\Simple Star Shared
2007-12-16 16:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\Simple Star Shared
2007-12-11 06:57 ——— d—–w C:\Documents and Settings\Sage\Application Data\ZoomBrowser EX
2007-12-11 06:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2006-06-15 06:05 53,760 —-a-w C:\Program Files\vacs.doc
2006-06-14 07:31 369,607 —-a-w C:\Program Files\easymtu.zip
2006-05-30 07:31 12,754,672 —-a-w C:\Program Files\MP10Setup.exe
.

((((((((((((((((((((((((((((( snapshot@2008-01-20_ 7.10.57.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-20 14:55:01 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-20 19:36:08 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-20 14:55:01 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-20 19:36:08 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-20 14:55:01 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-20 19:36:08 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-20 14:55:01 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-20 19:36:08 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-20 14:55:01 14,290,944 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
+ 2008-01-20 19:36:09 14,290,944 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
- 2008-01-20 14:55:01 163,840 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-20 19:36:09 163,840 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-11 15:13:52 98,304 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIACA.EXE
+ 2008-01-12 04:08:25 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2H1.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RAM Boost Pro"="C:\Program Files\RAM Boost Pro\RAMBoostPro.exe" [2008-01-06 18:55 278528]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-06 18:55 171448]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2008-01-06 18:55 313472]
"Nero PhotoShow Media Manager"="C:\PROGRA~1\Nero\PHOTOS~1\data\Xtras\MSSYSM~1.EXE" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-09 03:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-03-12 17:33 147456 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2008-01-06 18:54 1368064]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4 .exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2008-01-11 07:13 155648]
"Fix-It AV"="C:\PROGRA~1\VCOM\SYSTEM~1\MemCheck.exe" [2008-01-11 07:13 32768]
"AtomTime"="C:\Program Files\AtomTime Pro\AtomTime.EXE" [2008-01-11 07:07 396316]
"WFXSwtch"="C:\PROGRA~1\WinFax\WFXSWTCH.exe" [2008-01-11 07:07 27648]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-09-10 15:03 45568 C:\WINDOWS\system32\WFXSNT40.EXE]
"CloneCDElbyCDFL"="C:\Program Files\CloneCD\ElbyCheck.exe" [2008-01-11 07:08 45056]
"CloneCDTray"="C:\Program Files\CloneCD\CloneCDTray.exe" [2008-01-11 07:13 73728]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2008-01-11 07:13 83608]
"EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-01-11 07:13 98304]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-11 07:13 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-11 07:14 185784]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe" [2008-01-11 20:08 462336]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2008-01-07 00:52 892928]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 01:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2008-01-11 20:08 53248]
"Openwares LiveUpdate"="C:\Program Files\LiveUpdate\LiveUpdate.exe" [2008-01-11 20:08 61440]
"EPSON Stylus Photo R200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.exe" [2008-01-11 20:08 99840]
"RaidTool"="C:\Program Files\VIA\RAID\raid_tool.exe" [2008-01-10 22:47 589824]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="C:\PROGRA~1\ICQLite\ICQLite.exe" [ ]

C:\Documents and Settings\Sage\Start Menu\Programs\Startup\
AcomData PushButton Manager.lnk - C:\Documents and Settings\Sage\Application Data\Microsoft\Installer\{3EB255B0-0707-4A8E-8044-B4B51A36CEDA}\_124305e.exe [2007-03-06 00:49:57]
Anapod Manager.lnk - C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe [2006-12-04 22:15:34]
YPOPs.lnk - C:\Program Files\YPOPs\YPOPs.exe [2007-01-25 23:55:59]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-07-28 17:44:57]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 21:07:32]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= C:\Program Files\WinFax\WfxSeh32.Dll [1998-07-27 03:54 38400]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
–a—— 2008-01-10 22:47 589824 C:\Program Files\VIA\RAID\raid_tool.exe

R0 Defrag32b;Defrag32Boot;C:\WINDOWS\system32\drivers\Defrag32b.sys [2005-11-22 10:33]
R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys [2005-04-28 03:22]
R2 Defrag32;Defrag32;C:\WINDOWS\system32\drivers\Defrag32.sys [2005-11-22 10:33]
R2 PDSched;PDScheduler;"C:\Program Files\Raxco\PerfectDisk\PDSched.exe" [2005-11-29 10:16]
R2 r_server;Remote Administrator Service;"C:\WINDOWS\system32\r_server.exe" [2004-06-16 05:59]
R2 wfxsvc;WinFax PRO;C:\WINDOWS\system32\WFXSVC.EXE [2000-09-28 22:58]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 11:38:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-20 11:39:32
ComboFix-quarantined-files.txt 2008-01-20 19:39:07
ComboFix2.txt 2008-01-20 15:11:25
.
2008-01-07 09:07:15 — E O F —


HijackThis

Logfile of HijackThis v1.99.1
Scan saved at 11:55:44 AM, on 1/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\r_server.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\WinFax\WFXMOD32.EXE
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\VCOM\SYSTEM~1\mxtask.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Initio\AcomData PushButton Manager v1.10\inihid_xp.exe
C:\Program Files\YPOPs\YPOPs.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\iseeu.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netflix.com/MemberHome
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4 .exe" /tray
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\VCOM\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [AtomTime] "C:\Program Files\AtomTime Pro\AtomTime.EXE"
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\WinFax\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB002" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [RAM Boost Pro] C:\Program Files\RAM Boost Pro\RAMBoostPro.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\PHOTOS~1\data\Xtras\MSSYSM~1.EXE
O4 - Startup: AcomData PushButton Manager.lnk = ?
O4 - Startup: Anapod Manager.lnk = C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
O4 - Startup: YPOPs.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4056/ftp…302/Coupons.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
O23 - Service: SystemSuite Task Manager - Avanquest Publishing USA, Inc. - C:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
Hello I wont remove the program just yet but I will stop the service running to save it running every time you start your computer. Let me know if it causes a problem. One of the problems you had was a file infector that infected the start up files of numerous programs so it can spread each time you reboot the computer. The problem we have here is Quicktime and Kaspersky Anti-virus. The infected files have been replaced with the good ones, but it has left orphaned registry keys. Before I proceed, do you still have the kaspersky installation disc or did you download from the Internet?
Hi



Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=-

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete. This includes your anti-virus. Once you have installed the Scanner, and the updated definitions, you can disconnect from the Internet.Re-enable the anti-virus before reconnecting to the Internet.

In your next reply post:
Kaspersky report
ComboFix.txt
New HJT log taken after the above scan has run
ComboFix Log:

ComboFix 08-01-18.5 - Sage 2008-01-21 8:35:17.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.888 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Sage\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-20 11:01 . 2004-08-03 23:00 260,272 –a—— C:\cmldr
2008-01-20 11:01 . 2006-05-17 16:45 211 –a—— C:\Boot.bak
2008-01-20 06:54 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-19 12:00 . 2008-01-19 12:00 d——– C:\WINDOWS\ERUNT
2008-01-11 19:25 . 2008-01-11 20:32 91,492 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-01-11 19:25 . 2008-01-11 20:32 85,860 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-01-11 19:19 . 2008-01-11 19:19 d——– C:\Program Files\Kaspersky Lab
2008-01-11 19:19 . 2008-01-19 12:59 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-11 19:18 . 2008-01-21 08:36 1,888,800 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-11 19:18 . 2008-01-20 07:05 27,548 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-11 19:18 . 2008-01-21 08:36 20,512 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-11 19:18 . 2008-01-20 07:05 2,468 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-11 19:13 . 2008-01-11 19:13 d——– C:\kav
2008-01-11 04:30 . 2008-01-11 04:30 d——– C:\Documents and Settings\Sage\Application Data\EPSON
2008-01-10 21:16 . 2008-01-11 03:15 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-10 21:07 . 2008-01-10 21:07 d——– C:\Program Files\Bonjour
2008-01-10 20:42 . 2008-01-10 20:42 d——– C:\Program Files\Common Files\Macrovision Shared
2008-01-06 18:54 . 2008-01-11 07:13 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2008-01-06 02:51 . 2006-04-20 03:51 359,808 ——— C:\WINDOWS\system32\drivers\tcpip.sys.ORIGINAL
2008-01-06 02:51 . 2006-04-20 03:51 359,808 —–c— C:\WINDOWS\system32\dllcache\tcpip.sys.ORIGINAL
2008-01-06 02:50 . 2008-01-15 17:59 d——– C:\Downloads
2008-01-06 02:50 . 2008-01-06 02:50 2,560 –a—— C:\WINDOWS\system32\bitcometres.dll
2008-01-06 02:48 . 2008-01-10 21:51 d——– C:\Program Files\BitComet
2008-01-02 21:44 . 2008-01-02 21:44 d——– C:\Program Files\STOIK Imaging
2008-01-02 21:44 . 2008-01-02 21:44 d——– C:\Documents and Settings\Sage\Application Data\STOIK
2007-12-28 13:01 . 2007-12-28 13:01 d——– C:\Documents and Settings\Sage\Application Data\iWin
2007-12-28 13:00 . 2008-01-06 08:24 d——– C:\Program Files\iWin.com
2007-12-28 13:00 . 2008-01-06 08:19 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 12:54 . 2007-12-28 12:54 d——– C:\Documents and Settings\All Users\Application Data\iWin Games
2007-12-25 06:48 . 2008-01-06 08:25 d——– C:\Program Files\JewelQuest_at
2007-12-23 10:58 . 2007-12-23 10:58 d——– C:\Documents and Settings\All Users\Application Data\Simple Star
2007-12-21 23:15 . 2007-12-21 23:15 d——– C:\Documents and Settings\All Users\Application Data\Nero

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 19:36 ——— d—–w C:\Program Files\WinFax
2008-01-20 19:36 ——— d—–w C:\Program Files\RAM Boost Pro
2008-01-20 19:36 ——— d—–w C:\Program Files\LIVEUPDATE
2008-01-20 19:36 ——— d—–w C:\Program Files\iTunes
2008-01-20 19:36 ——— d—–w C:\Program Files\CloneCD
2008-01-20 19:36 ——— d—–w C:\Program Files\AtomTime Pro
2008-01-20 15:07 ——— d—–w C:\Program Files\YPOPs
2008-01-20 15:03 ——— d—–w C:\Program Files\QuickTime
2008-01-11 16:34 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2008-01-11 14:15 ——— d—–w C:\Program Files\SmartDraw 2008
2008-01-11 06:17 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-11 04:53 ——— d—–w C:\Program Files\Trillian
2008-01-07 04:11 ——— d—–w C:\Documents and Settings\Sage\Application Data\Corel
2008-01-07 04:08 4,184 ——w C:\WINDOWS\system32\KGyGaAvL.sys
2008-01-06 16:57 359,808 ——w C:\WINDOWS\system32\drivers\tcpip.sys
2008-01-06 16:26 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-25 11:25 ——— d—–w C:\Documents and Settings\Sage\Application Data\Nero
2007-12-23 20:12 ——— d—–w C:\Program Files\Common Files\Simple Star Shared
2007-12-16 16:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\Simple Star Shared
2007-12-11 06:57 ——— d—–w C:\Documents and Settings\Sage\Application Data\ZoomBrowser EX
2007-12-11 06:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2006-06-15 06:05 53,760 —-a-w C:\Program Files\vacs.doc
2006-06-14 07:31 369,607 —-a-w C:\Program Files\easymtu.zip
2006-05-30 07:31 12,754,672 —-a-w C:\Program Files\MP10Setup.exe
.

((((((((((((((((((((((((((((( snapshot@2008-01-20_ 7.10.57.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-20 14:55:01 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-21 16:34:56 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-20 14:55:01 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-21 16:34:56 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-20 14:55:01 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-21 16:34:56 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-20 14:55:01 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-21 16:34:57 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-20 14:55:01 14,290,944 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
+ 2008-01-21 16:34:57 14,290,944 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
- 2008-01-20 14:55:01 163,840 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-21 16:34:57 163,840 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-11 15:13:52 98,304 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIACA.EXE
+ 2008-01-12 04:08:25 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2H1.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RAM Boost Pro"="C:\Program Files\RAM Boost Pro\RAMBoostPro.exe" [2008-01-06 18:55 278528]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-06 18:55 171448]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2008-01-06 18:55 313472]
"Nero PhotoShow Media Manager"="C:\PROGRA~1\Nero\PHOTOS~1\data\Xtras\MSSYSM~1.EXE" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-09 03:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-03-12 17:33 147456 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2008-01-06 18:54 1368064]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4 .exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2008-01-11 07:13 155648]
"Fix-It AV"="C:\PROGRA~1\VCOM\SYSTEM~1\MemCheck.exe" [2008-01-11 07:13 32768]
"AtomTime"="C:\Program Files\AtomTime Pro\AtomTime.EXE" [2008-01-11 07:07 396316]
"WFXSwtch"="C:\PROGRA~1\WinFax\WFXSWTCH.exe" [2008-01-11 07:07 27648]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-09-10 15:03 45568 C:\WINDOWS\system32\WFXSNT40.EXE]
"CloneCDElbyCDFL"="C:\Program Files\CloneCD\ElbyCheck.exe" [2008-01-11 07:08 45056]
"CloneCDTray"="C:\Program Files\CloneCD\CloneCDTray.exe" [2008-01-11 07:13 73728]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2008-01-11 07:13 83608]
"EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-01-11 07:13 98304]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-11 07:13 278528]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-11 07:14 185784]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe" [2008-01-11 20:08 462336]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2008-01-07 00:52 892928]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 01:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2008-01-11 20:08 53248]
"Openwares LiveUpdate"="C:\Program Files\LiveUpdate\LiveUpdate.exe" [2008-01-11 20:08 61440]
"EPSON Stylus Photo R200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.exe" [2008-01-11 20:08 99840]
"RaidTool"="C:\Program Files\VIA\RAID\raid_tool.exe" [2008-01-10 22:47 589824]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="C:\PROGRA~1\ICQLite\ICQLite.exe" [ ]

C:\Documents and Settings\Sage\Start Menu\Programs\Startup\
AcomData PushButton Manager.lnk - C:\Documents and Settings\Sage\Application Data\Microsoft\Installer\{3EB255B0-0707-4A8E-8044-B4B51A36CEDA}\_124305e.exe [2007-03-06 00:49:57]
Anapod Manager.lnk - C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe [2006-12-04 22:15:34]
YPOPs.lnk - C:\Program Files\YPOPs\YPOPs.exe [2007-01-25 23:55:59]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-07-28 17:44:57]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 21:07:32]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= C:\Program Files\WinFax\WfxSeh32.Dll [1998-07-27 03:54 38400]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
–a—— 2008-01-10 22:47 589824 C:\Program Files\VIA\RAID\raid_tool.exe

R0 Defrag32b;Defrag32Boot;C:\WINDOWS\system32\drivers\Defrag32b.sys [2005-11-22 10:33]
R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys [2005-04-28 03:22]
R2 Defrag32;Defrag32;C:\WINDOWS\system32\drivers\Defrag32.sys [2005-11-22 10:33]
R2 PDSched;PDScheduler;"C:\Program Files\Raxco\PerfectDisk\PDSched.exe" [2005-11-29 10:16]
R2 r_server;Remote Administrator Service;"C:\WINDOWS\system32\r_server.exe" [2004-06-16 05:59]
R2 wfxsvc;WinFax PRO;C:\WINDOWS\system32\WFXSVC.EXE [2000-09-28 22:58]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-21 08:36:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
.
Completion time: 2008-01-21 8:38:04
ComboFix-quarantined-files.txt 2008-01-21 16:37:42
ComboFix2.txt 2008-01-20 19:39:34
ComboFix3.txt 2008-01-20 15:11:25
.
2008-01-07 09:07:15 — E O F —

Scan Log:

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, January 21, 2008 11:20:34 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/01/2008
Kaspersky Anti-Virus database records: 525897
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\

Scan Statistics:
Total number of scanned objects: 119897
Number of viruses found: 10
Number of infected objects: 101
Number of suspicious objects: 0
Duration of the scan process: 01:33:01

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Sage\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Sage\Desktop\Program exe Files\Nero Photoshow Deluxe 5\nero_photoshow_deluxe_5_setup.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\Sage\Desktop\Program exe Files\Nero Photoshow Deluxe 5\nero_photoshow_deluxe_5_setup.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Sage\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Sage\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Sage\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Sage\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Sage\ntuser.dat Object is locked skipped
C:\Documents and Settings\Sage\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Data\master.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Data\mastlog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Data\model.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Data\modellog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Data\tempdb.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Data\templog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\LOG\ERRORLOG Object is locked skipped
C:\Program Files\Radmin\raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\Program Files\Radmin\radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped
C:\Program Files\Radmin\r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped
C:\Program Files\VCOM\SystemSuite\MXFwIMMF.dat Object is locked skipped
C:\Program Files\VCOM\SystemSuite\MXFwTMMF.dat Object is locked skipped
C:\Program Files\VCOM\SystemSuite\rawlog.log Object is locked skipped
C:\Program Files\VCOM\SystemSuite\seclog.log Object is locked skipped
C:\Program Files\VCOM\SystemSuite\syslog.log Object is locked skipped
C:\Program Files\VCOM\SystemSuite\tralog.log Object is locked skipped
C:\Program Files\VCOM\SystemSuite\VSS4DF2F.012 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Program Files\VCOM\SystemSuite\VSS4DF2F.013 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Program Files\VCOM\SystemSuite\VSS4DG1N.01E Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Program Files\VCOM\SystemSuite\VSS4DM0V.01J Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Program Files\VCOM\SystemSuite\VSS4DNFF.018 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Program Files\VCOM\SystemSuite\VSSBEDEN.015 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Program Files\VCOM\SystemSuite\VSSBEDEN.016 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Program Files\WinFax\Data\Status.WFD Object is locked skipped
C:\Program Files\WinFax\Data\Status.WFF Object is locked skipped
C:\Program Files\WinFax\Data\Status.WFG Object is locked skipped
C:\Program Files\WinFax\Data\Status.WFR Object is locked skipped
C:\Program Files\WinFax\Data\Status.WFX Object is locked skipped
C:\Program Files\WinFax\Data\Status2.WFD Object is locked skipped
C:\Program Files\WinFax\Data\Status2.WFG Object is locked skipped
C:\Program Files\WinFax\Data\Status2.WFX Object is locked skipped
C:\Program Files\WinFax\Data\Status3.WFD Object is locked skipped
C:\Program Files\WinFax\Data\Status3.WFG Object is locked skipped
C:\Program Files\WinFax\Data\Status3.WFX Object is locked skipped
C:\Program Files\WinFax\Data\StatusS.WFD Object is locked skipped
C:\Program Files\WinFax\Data\StatusS.WFG Object is locked skipped
C:\Program Files\WinFax\Data\StatusS.WFX Object is locked skipped
C:\Program Files\YPOPs\ypops.log Object is locked skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcya.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\catchme2008-01-20_ 70753.07.zip/avp.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\catchme2008-01-20_ 70753.07.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043571.dll Infected: not-a-virus:AdWare.Win32.AdMedia.g skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043602.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043602.exe/WISE0017.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043602.exe WiseSFX: infected - 2 skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043602.exe WiseSFXDropper: infected - 2 skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043610.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043610.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043616.exe/data0000.bin/data0007 Infected: not-a-virus:AdWare.Win32.AdMedia.g skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043616.exe/data0000.bin Infected: not-a-virus:AdWare.Win32.AdMedia.g skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043616.exe EmbeddedEXE: infected - 2 skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP509\A0043662.exe Infected: Trojan-Downloader.Win32.Agent.gwh skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043683.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043685.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043686.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043691.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043693.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043694.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043695.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043696.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043697.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043698.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043699.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043700.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043701.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043702.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043703.EXE Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043704.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043705.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043706.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043707.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043708.EXE Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043709.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043710.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043711.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043712.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043713.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043714.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043715.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043716.EXE Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043717.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043718.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043721.exe Infected: Trojan-Downloader.Win32.Agent.gwh skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP510\A0043765.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043766.exe Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043770.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043771.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043772.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043773.EXE Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043774.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043775.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043776.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043777.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043778.EXE Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043779.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043781.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043782.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043783.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043784.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043785.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043786.EXE Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043787.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043788.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043916.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043942.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP511\A0043942.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP521\A0052496.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP521\A0052497.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP521\A0052498.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP521\A0052503.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP521\A0052506.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP522\A0052536.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP523\A0052571.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP524\A0052573.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP524\A0052594.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP524\A0052595.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP524\A0052596.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP524\A0052597.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP524\A0052598.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP524\A0052605.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP527\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{FEF45E77-F8C7-4EC7-AB2C-5762C9BF9EFA}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\WINDOWS\system32\r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.22 skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_770.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{2C739B56-B7F6-485C-B24F-24794B964165}\RP527\change.log Object is locked skipped

Scan process completed.


HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 11:22:05 AM, on 1/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\r_server.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\WinFax\WFXMOD32.EXE
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\VCOM\SYSTEM~1\mxtask.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Initio\AcomData PushButton Manager v1.10\inihid_xp.exe
C:\Program Files\YPOPs\YPOPs.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\iseeu.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netflix.com/MemberHome
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4 .exe" /tray
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\VCOM\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [AtomTime] "C:\Program Files\AtomTime Pro\AtomTime.EXE"
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\WinFax\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB002" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [RAM Boost Pro] C:\Program Files\RAM Boost Pro\RAMBoostPro.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\PHOTOS~1\data\Xtras\MSSYSM~1.EXE
O4 - Startup: AcomData PushButton Manager.lnk = ?
O4 - Startup: Anapod Manager.lnk = C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
O4 - Startup: YPOPs.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4056/ftp…302/Coupons.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
O23 - Service: SystemSuite Task Manager - Avanquest Publishing USA, Inc. - C:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
I have System Suite 6 on there but I never renewed the subscription so I haven't gotten any pattern updates on it in a year. I thought I had turned the virus portion of it off. I know the firewall still turns on. I'll go and check those programs for you is there anything in particular that I should be looking for?
I can't get Kaspersky to open at all. I was able to open QuickTime and it seemed like ti would work. Was there anything in particular that I should be trying to use with them?
Hi The problem with this infection is that some files cannot be replaced, mainly in anti-virus programs. Is Kaspersky a free version or paid for?
Hi

Instead of paying for an anti-virus you can get just as good protection from the free versions. I personally use AVG
http://free.grisoft.com/doc/download-free-…-virus/us/frt/0

I would remove Kaspersky first, of course. And dont think because it is the free version you will be less protected. It just doesnt have all the extras of a paid version.
As you dont subscribe to VCOM anymore I have a feeling you will not recieve any updates to the firewall, so that should be removed also. I will recommend a good free firewall once I have ensured you are clean. Remove VCOM before proceeding with the next step.



Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\Documents and Settings\Sage\Desktop\Program exe Files\Nero Photoshow Deluxe 5\nero_photoshow_deluxe_5_setup.exe
C:\WINDOWS\system32\r_server.exe

Folder::
C:\Program Files\Radmin
C:\Program Files\VCOM

Driver::
r_server;Remote Administrator Service

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI