This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] dropper agent and more?

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I just inherited this old computer, and have been wading through spyware and viruses for a week now trying to make it suitable.

AVG detects dropper.agent.dgo,trojan.agent.aoy, and lowzones.dm. Also some files beginning with "not-a-virus". Unfortunately, when I go to quarantine these files, AVG shuts down.

I seem to recall Panda detecting QDRloader

I have been getting IE pop ups for some kind of spyware remover/cleaner. I've really tried to clean this stuff myself (spybot, adaware, spywareblaster, etc) but it is just too much. Thank you to whoever may look at this and help.

Here's the Hijack This log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:26:40 PM, on 1/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\xcnmorfb.exe
C:\Documents and Settings\Philip Bardin\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\MCUPDA~1.EXE
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [licli] li.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [d4fe97e3] rundll32.exe "C:\WINDOWS\system32\qipjquxw.dll",b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\xcnmorfb.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O24 - Desktop Component 0: (no name) - http://thumbp1.mail.re2.yahoo.com/tn?sid=2…5&fid=Inbox
O24 - Desktop Component 1: (no name) - http://www.heavenlycelebrities.com/Pics/kr…istin53_jpg.jpg

–
End of file - 5452 bytes
Hello, and welcome to the forum.

My name is Simon V., and I'll be glad to help you with your computer problems.

Step 1

Please download and install CCleaner.

Open CCleaner. On the Windows tab, leave the default options alone.

  • On the Applications tab, check (tick) all the boxes except Saved Form Information. This will remove all your saved passwords if you leave this box checked.
  • Click on the Run Cleaner button at the bottom right hand corner.
  • When the cleaner has completed, click Tools in the Left Pane.
  • Verify that Uninstall is highlighted in color, or click on it.
  • In the lower right, click Save to Text File.
  • Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
  • You can leave the filename as install.txt.
  • Click Save, then exit Ccleaner.

Step 2

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Post the log from ComboFix (C:\Combofix.txt) when you've accomplished that, along with a new HijackThis log and the CCleaner Uninstall List (install.txt).
Thank you for taking time to look over this. combo, hijack, install

ComboFix 08-01-20.1 - Philip Bardin 2008-01-20 17:30:50.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.100 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\SYSTEM32\bcbeg.ini
C:\WINDOWS\SYSTEM32\bcbeg.ini2
C:\WINDOWS\system32\gebcb.dll
C:\WINDOWS\system32\gebcb.exe
C:\WINDOWS\system32\qipjquxw.dll
C:\WINDOWS\system32\sjovvjgn.dll
C:\WINDOWS\SYSTEM32\vnqcyxtf.ini
C:\WINDOWS\SYSTEM32\wxuqjpiq.ini
C:\WINDOWS\system32\xqiqkrja.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat . . . . failed to delete
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat . . . . failed to delete

—– Unknown downloads made by BITS: —-
http://80.93.59.108

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.

2008-01-20 17:38 . 2008-01-20 17:38 336,384 ——— C:\WINDOWS\SYSTEM32\gebcb.dll
2008-01-20 17:22 . 2004-08-03 23:00 260,272 –a—— C:\cmldr
2008-01-20 17:22 . 2008-01-14 23:58 211 –a—— C:\Boot.bak
2008-01-20 01:29 . 2008-01-20 01:29 d——– C:\Program Files\CCleaner
2008-01-18 18:53 . 2008-01-18 18:53 d——– C:\Documents and Settings\Guest.BARDIN58\Application Data\Talkback
2008-01-18 18:50 . 2004-11-04 19:10 d——– C:\Documents and Settings\Guest.BARDIN58\Application Data\Jasc Software Inc
2008-01-17 10:59 . 2008-01-17 10:59 d——– C:\Documents and Settings\LocalService\Application Data\Talkback
2008-01-15 23:30 . 2007-06-08 09:44 8,576 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\rwbelwjxghvp.sys
2008-01-15 19:38 . 2008-01-16 00:17 d——– C:\WINDOWS\SYSTEM32\ActiveScan
2008-01-15 19:38 . 2008-01-15 19:38 30,590 –a—— C:\WINDOWS\SYSTEM32\pavas.ico
2008-01-15 19:38 . 2008-01-15 19:38 2,550 –a—— C:\WINDOWS\SYSTEM32\Uninstall.ico
2008-01-15 19:38 . 2008-01-15 19:38 1,406 –a—— C:\WINDOWS\SYSTEM32\Help.ico
2008-01-15 19:30 . 2008-01-15 19:30 d——– C:\Documents and Settings\Philip Bardin\Application Data\Talkback
2008-01-15 18:27 . 2008-01-15 18:27 d——– C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-01-15 18:25 . 2004-11-04 19:10 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-15 18:04 . 2008-01-15 18:04 d——– C:\Documents and Settings\Philip Bardin\Application Data\Grisoft
2008-01-15 18:04 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2008-01-15 18:03 . 2008-01-15 18:03 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-15 16:14 . 2008-01-15 16:14 d——– C:\Program Files\Lavasoft
2008-01-15 16:13 . 2008-01-15 16:15 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-15 16:12 . 2008-01-15 16:12 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-15 15:47 . 2008-01-15 15:47 335 –a—— C:\WINDOWS\mozregistry.dat
2008-01-15 02:15 . 2008-01-15 02:15 d——– C:\Program Files\SpywareBlaster
2008-01-14 16:19 . 2008-01-14 16:19 92 –a—— C:\WINDOWS\wininit.ini
2008-01-14 11:45 . 2008-01-14 12:16 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-13 23:13 . 2008-01-14 12:00 d——– C:\Program Files\Mozilla Firefox(2)
2008-01-13 22:22 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-13 22:19 . 2008-01-15 17:30 155,648 –a—— C:\WINDOWS\SYSTEM32\igfxtray .exe
2008-01-13 22:19 . 2008-01-15 17:30 126,976 –a—— C:\WINDOWS\SYSTEM32\hkcmd .exe
2008-01-13 14:07 . 2008-01-17 17:29 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-13 14:07 . 2008-01-13 14:07 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-11 19:13 . 2008-01-11 19:13 d——– C:\c5f77b987c73166d2cdca913fe4a
2008-01-11 18:39 . 2008-01-11 18:39 d——– C:\ffa65390c98e3f5c19c149e7f0a4532b
2008-01-10 16:34 . 2008-01-10 16:37 6 –a—— C:\WINDOWS\msoffice.ini
2008-01-10 16:30 . 2008-01-10 16:31 132 –ah—– C:\IPH.PH

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 22:28 ——— d—–w C:\Documents and Settings\Philip Bardin\Application Data\McAfee.com Personal Firewall
2008-01-15 23:26 ——— d—–w C:\Program Files\QuickTime
2008-01-15 23:09 ——— d—–w C:\Program Files\DellSupport
2008-01-10 23:53 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-10 23:51 ——— d—–w C:\Program Files\Canon
2008-01-10 21:52 ——— d—–w C:\Program Files\MUSICMATCH
2008-01-10 21:42 ——— d—–w C:\Program Files\Pure Networks
2008-01-10 21:42 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-10 21:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-10 21:37 ——— d—–w C:\Documents and Settings\Philip Bardin\Application Data\AOL
2008-01-10 21:20 ——— d—–w C:\Program Files\MySpace
2007-12-14 16:32 12,632 —-a-w C:\WINDOWS\SYSTEM32\lsdelete.exe
2007-11-30 05:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-11-27 20:33 ——— d—–w C:\Documents and Settings\Philip Bardin\Application Data\MySpace
2007-11-14 07:26 450,560 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\SYSTEM32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\lsasrv.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
2007-10-30 10:16 3,058,688 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
2007-10-27 22:40 227,328 —-a-w C:\WINDOWS\SYSTEM32\wmasf.dll
2007-10-27 22:40 227,328 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2004-12-17 03:30 848 –sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
—-a-w		   460,784 2008-01-15 22:30:46  C:\Program Files\DellSupport\DSAgnt .exe
—-a-w		   221,184 2008-01-15 22:30:30  C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
—-a-w			32,881 2008-01-15 22:30:37  C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
—-a-w		   303,104 2008-01-15 22:30:32  C:\Program Files\McAfee.com\Agent\mcagent .exe
—-a-w		   500,736 2008-01-14 17:27:00  C:\Program Files\McAfee.com\Agent\mcregwiz .exe
—-a-w		   135,168 2008-01-14 17:27:07  C:\Program Files\McAfee.com\Agent\MCREGW~1 .EXE
—-a-w		   576,000 2008-01-20 22:31:24  C:\Program Files\McAfee.com\Agent\mcupdate .exe
—-a-w		   576,000 2008-01-20 22:39:01  C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
—-a-w		 1,380,352 2008-01-15 22:30:42  C:\Program Files\McAfee.com\Personal Firewall\MpfTray .exe
—-a-w		   122,880 2008-01-15 22:30:30  C:\Program Files\McAfee.com\VSO\mcmnhdlr .exe
—-a-w		   163,840 2008-01-15 22:30:34  C:\Program Files\McAfee.com\VSO\mcvsshld .exe
—-a-w		   448,512 2008-01-15 22:30:34  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   448,512 2008-01-15 16:13:50  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   448,512 2008-01-15 06:24:00  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   448,512 2008-01-15 04:51:27  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   448,512 2008-01-14 17:26:59  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   448,512 2008-01-14 17:02:39  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   448,512 2008-01-14 04:05:33  C:\Program Files\QuickTime\qttask  .exe
—-a-w			26,112 2008-01-15 22:30:44  C:\Program Files\Real\RealPlayer\RealPlay .exe
—-a-w		 1,460,560 2008-01-15 22:30:46  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   126,976 2008-01-15 22:30:28  C:\WINDOWS\SYSTEM32\hkcmd .exe
—-a-w		   155,648 2008-01-15 22:30:27  C:\WINDOWS\SYSTEM32\igfxtray .exe


((((((((((((((((((((((((((((( snapshot@2008-01-13_22.47.25.98 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-24 13:28:54 141,424 —-a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
- 2008-01-14 03:26:08 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-20 22:20:25 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-14 03:26:09 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-20 22:20:25 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-14 03:26:09 2,826,240 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-20 22:20:25 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-14 03:26:09 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-20 22:20:25 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-14 03:26:09 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-20 22:20:25 3,211,264 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-14 03:26:09 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-20 22:20:25 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-15 21:14:27 1,038,336 —-a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
+ 2008-01-15 21:14:27 178,688 —-a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
+ 2008-01-15 21:14:27 171,008 —-a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe
+ 2008-01-15 21:14:27 8,704 —-a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe
+ 2007-03-29 14:20:50 110,592 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\as.dll
+ 2006-10-05 21:15:26 233,472 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\ascontrol.dll
+ 2005-06-03 19:03:18 96,256 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\asmdat.dll
+ 2003-08-01 16:00:16 36,864 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\certdll.dll
+ 2005-05-20 18:42:44 86,016 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\instlsp.dll
+ 2007-11-12 14:46:18 26,112 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\JID.dll
+ 2006-02-16 23:20:20 4,608 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\memvfile.dll
+ 2005-10-25 23:08:32 348,160 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\msvcr71.dll
+ 2007-11-26 16:10:36 61,440 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\NanoWrapper.dll
+ 2004-05-04 20:01:02 139,264 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavaleas.dll
+ 2006-07-14 18:04:10 45,056 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavdr.exe
+ 2006-04-10 15:50:02 159,832 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavexcom.dll
+ 2006-02-14 18:05:38 94,208 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavinas.dll
+ 2006-02-16 23:35:38 180,224 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavoe.dll
+ 2006-10-05 21:15:38 122,880 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavpz.dll
+ 2007-06-04 16:31:52 57,344 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavsddl.dll
+ 2006-06-30 19:13:38 8,704 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pfdnnt.exe
+ 2004-02-04 19:08:42 49,152 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\port32.dll
+ 2007-10-30 15:04:14 36,864 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\Prescan.dll
+ 2006-08-01 18:23:10 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pscpu.dll
+ 2007-11-21 15:00:06 376,832 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskahk.dll
+ 2007-10-31 18:05:06 32,768 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\PSKAHKPRESCAN.dll
+ 2006-08-17 16:38:14 10,752 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskalloc.dll
+ 2006-09-04 16:49:54 61,440 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskas.dll
+ 2006-08-18 13:46:18 779,264 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll
+ 2007-03-26 19:25:34 417,792 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskcmp.dll
+ 2006-08-09 15:42:24 90,112 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskfss.dll
+ 2006-07-19 15:55:58 208,896 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskhtml.dll
+ 2006-01-20 21:57:00 9,728 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskmas.dll
+ 2006-05-17 14:50:12 14,336 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskmdfs.dll
+ 2006-08-16 15:58:12 33,280 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskpack.dll
+ 2006-06-30 19:42:36 266,240 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskscs.dll
+ 2006-08-17 19:33:14 62,976 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskutil.dll
+ 2006-08-08 18:13:10 13,312 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvfile.dll
+ 2006-08-18 13:53:08 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvfs.dll
+ 2006-08-18 13:49:50 167,936 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvm.dll
+ 2007-10-18 14:30:16 105,472 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnahk.dll
+ 2007-11-23 19:29:08 10,752 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psndsk.dll
+ 2007-10-18 14:30:38 42,496 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnflg.dll
+ 2007-10-30 16:19:22 98,304 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnglknt.dll
+ 2007-08-22 13:52:00 20,272 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnhsh.dll
+ 2007-11-12 20:49:34 11,776 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnjidsign.dll
+ 2007-08-22 13:52:04 76,080 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnkrnl.dll
+ 2007-08-22 13:52:06 21,296 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnmem.dll
+ 2007-10-04 20:26:28 28,672 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\PsnPen.dll
+ 2007-10-23 16:40:10 86,016 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psntuc.dll
+ 2007-05-24 16:27:36 27,136 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\PSNXprs.dll
+ 2007-04-18 22:16:04 353,840 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psscan.dll
+ 2007-01-22 19:42:48 35,328 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\rawvfile.dll
+ 2007-06-08 14:44:36 8,576 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\RKPavProc.sys
+ 2007-06-05 15:56:40 44,928 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\sdthook.sys
+ 1997-09-18 11:12:32 9,488 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\sporder.dll
+ 2006-02-28 22:23:40 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\tcpvfile.dll
+ 2007-09-17 14:14:08 126,976 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\Tucan.dll
+ 2006-08-02 17:39:06 73,728 —-a-w C:\WINDOWS\SYSTEM32\asuninst.exe
+ 2004-08-04 11:00:00 158,208 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msconfig.exe
+ 2007-07-11 18:37:26 6,272 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\AWRTPD.sys
+ 2007-08-07 17:58:08 8,320 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\AWRTRD.sys
+ 2007-08-07 17:56:58 9,344 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\NSDriver.sys
+ 2007-11-21 00:52:38 2,884,992 —-a-w C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32.dll
+ 2007-11-21 00:52:40 218,496 —-a-w C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-01-18 23:35:48 70,264 —-a-w C:\WINDOWS\SYSTEM32\Macromed\Flash\uninstall_plugin.exe
+ 2008-01-14 17:00:52 195,560 —-a-w C:\WINDOWS\SYSTEM32\Restore\rstrlog.dat
+ 2003-03-25 23:53:50 11,776 —-a-w C:\WINDOWS\SYSTEM32\ZPORT4AS.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{90DBBCF1-9D4A-4E5F-807E-EF21E7E0E42B}]
2008-01-20 17:38 336384 ——— C:\WINDOWS\system32\gebcb.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [ ]
"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [ ]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [ ]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\MCUPDA~2.EXE" [2008-01-20 17:39 576000]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [ ]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [ ]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [ ]
"licli"="li.exe" []
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [ ]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\gebcb.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\gebcb


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b78d7fc-c08c-11dc-9f1c-000f1f5be233}]
\Shell\AutoRun\command - E:\wd_windows_tools\setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 17:39:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\bcbeg.ini 6514 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\gebcb.dll
.
Completion time: 2008-01-20 17:41:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-20 22:41:44
ComboFix2.txt 2008-01-14 03:50:18
.
2008-01-12 00:13:46 — E O F —

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:45:29 PM, on 1/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Philip Bardin\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
F3 - REG:win.ini: load=C:\WINDOWS\system32\gebcb.exe
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\MCUPDA~2.EXE
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [licli] li.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe

–
End of file - 5082 bytes

Ad-Aware 2007
Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player Plugin
Adobe Reader 6.0.1
AOL Uninstaller (Choose which Products to Remove)
AVG Anti-Spyware 7.5
Banctec Service Agreement
Broadcom Management Programs
Canon i550
CCleaner (remove only)
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Networking Guide
DellSupport
EarthLink Setup Files
HijackThis 2.0.2
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Intel® 537EP V9x DF PCI Modem
Intel® Extreme Graphics Driver
Internet Explorer Default Page
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2_03
Macromedia Flash Player 8
McAfee Personal Firewall Plus
McAfee SecurityCenter
McAfee VirusScan
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 SR-1 Professional
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Modem Event Monitor
Modem Helper
Modem On Hold
Mozilla Firefox (2.0.0.11)
Panda ActiveScan
QuickTime
RealPlayer Basic
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Spybot - Search & Destroy
SpywareBlaster v3.5.1
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Viewpoint Media Player
WebFldrs XP
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WordPerfect Office 12
Hi :)

Step 1

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\SYSTEM32\gebcb.dll
C:\WINDOWS\SYSTEM32\DRIVERS\rwbelwjxghvp.sys

Registry::

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"licli"=-
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

RenV::

—-a-w		   460,784 2008-01-15 22:30:46  C:\Program Files\DellSupport\DSAgnt .exe
—-a-w		   221,184 2008-01-15 22:30:30  C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
—-a-w			32,881 2008-01-15 22:30:37  C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
—-a-w		   303,104 2008-01-15 22:30:32  C:\Program Files\McAfee.com\Agent\mcagent .exe
—-a-w		   500,736 2008-01-14 17:27:00  C:\Program Files\McAfee.com\Agent\mcregwiz .exe
—-a-w		   135,168 2008-01-14 17:27:07  C:\Program Files\McAfee.com\Agent\MCREGW~1 .EXE
—-a-w		   576,000 2008-01-20 22:31:24  C:\Program Files\McAfee.com\Agent\mcupdate .exe
—-a-w		   576,000 2008-01-20 22:39:01  C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
—-a-w		 1,380,352 2008-01-15 22:30:42  C:\Program Files\McAfee.com\Personal Firewall\MpfTray .exe
—-a-w		   122,880 2008-01-15 22:30:30  C:\Program Files\McAfee.com\VSO\mcmnhdlr .exe
—-a-w		   163,840 2008-01-15 22:30:34  C:\Program Files\McAfee.com\VSO\mcvsshld .exe
—-a-w		   448,512 2008-01-15 22:30:34  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   448,512 2008-01-15 16:13:50  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   448,512 2008-01-15 06:24:00  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   448,512 2008-01-15 04:51:27  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   448,512 2008-01-14 17:26:59  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   448,512 2008-01-14 17:02:39  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   448,512 2008-01-14 04:05:33  C:\Program Files\QuickTime\qttask  .exe
—-a-w			26,112 2008-01-15 22:30:44  C:\Program Files\Real\RealPlayer\RealPlay .exe
—-a-w		 1,460,560 2008-01-15 22:30:46  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   126,976 2008-01-15 22:30:28  C:\WINDOWS\SYSTEM32\hkcmd .exe
—-a-w		   155,648 2008-01-15 22:30:27  C:\WINDOWS\SYSTEM32\igfxtray .exe

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save (Save the CFScript in the same location as Combofix.exe)

Close any open windows.

Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix.

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Be sure to save it to a convenient location.

Step 2

Click on Start, then Control Panel. Double click on Add or Remove Programs.

Please remove the following program(s):

  • Java 2 Runtime Environment, SE v1.4.2_03
  • Viewpoint Media Player <– Only remove this if you haven't installed it yourself.

Then download and install Java Runtime Environment (JRE) 6 Update 4.

Step 3

Close all programs before continuing, and try not to run anything during the scan.

Please do an online scan with Kaspersky WebScanner. (You will need to use Internet Explorer to run this scan)

On the welcome screen, click Accept.

You will be promted to install an ActiveX component from Kaspersky, click Install.

  • The program will launch and then begin downloading the latest definition files.
  • Once the files have been downloaded click on Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:

  • Scan using the following Anti-Virus database:

    Extended (if available, otherwise Standard)

  • Scan Options:

    Scan Archives
    Scan Mail Bases

  • Click OK.
  • Now under Select a Target to Scan:

    Select My Computer.

  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button and save the file to your desktop.

Step 4

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • the Kaspersky Online Scan report
  • a new HijackThis log
ComboFix 08-01-20.1 - Philip Bardin 2008-01-21 15:22:20.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.96 [GMT -5:00]Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Philip Bardin\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\SYSTEM32\DRIVERS\rwbelwjxghvp.sys
C:\WINDOWS\SYSTEM32\gebcb.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Real\RealPlayer\RealPlay .exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\SYSTEM32\bcbeg.ini
C:\WINDOWS\SYSTEM32\bcbeg.ini2
C:\WINDOWS\system32\gebcb.dll
C:\WINDOWS\system32\gebcb.exe

C:\Program Files\Real\RealPlayer\RealPlay .exe —> QooBox
.
.
((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-21 13:16 . 2008-01-21 13:16 d——– C:\Program Files\Sun
2008-01-21 13:15 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-01-21 13:09 . 2008-01-21 13:15 d——– C:\Program Files\Java
2008-01-20 17:22 . 2004-08-03 23:00 260,272 –a—— C:\cmldr
2008-01-20 17:22 . 2008-01-14 23:58 211 –a—— C:\Boot.bak
2008-01-20 01:29 . 2008-01-20 01:29 d——– C:\Program Files\CCleaner
2008-01-18 18:53 . 2008-01-18 18:53 d——– C:\Documents and Settings\Guest.BARDIN58\Application Data\Talkback
2008-01-18 18:50 . 2004-11-04 19:10 d——– C:\Documents and Settings\Guest.BARDIN58\Application Data\Jasc Software Inc
2008-01-17 10:59 . 2008-01-17 10:59 d——– C:\Documents and Settings\LocalService\Application Data\Talkback
2008-01-15 19:38 . 2008-01-16 00:17 d——– C:\WINDOWS\SYSTEM32\ActiveScan
2008-01-15 19:38 . 2008-01-15 19:38 30,590 –a—— C:\WINDOWS\SYSTEM32\pavas.ico
2008-01-15 19:38 . 2008-01-15 19:38 2,550 –a—— C:\WINDOWS\SYSTEM32\Uninstall.ico
2008-01-15 19:38 . 2008-01-15 19:38 1,406 –a—— C:\WINDOWS\SYSTEM32\Help.ico
2008-01-15 19:30 . 2008-01-15 19:30 d——– C:\Documents and Settings\Philip Bardin\Application Data\Talkback
2008-01-15 18:27 . 2008-01-15 18:27 d——– C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-01-15 18:25 . 2004-11-04 19:10 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-15 18:04 . 2008-01-15 18:04 d——– C:\Documents and Settings\Philip Bardin\Application Data\Grisoft
2008-01-15 18:04 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2008-01-15 18:03 . 2008-01-15 18:03 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-15 16:14 . 2008-01-15 16:14 d——– C:\Program Files\Lavasoft
2008-01-15 16:13 . 2008-01-15 16:15 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-15 16:12 . 2008-01-15 16:12 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-15 15:47 . 2008-01-15 15:47 335 –a—— C:\WINDOWS\mozregistry.dat
2008-01-15 02:15 . 2008-01-15 02:15 d——– C:\Program Files\SpywareBlaster
2008-01-14 16:19 . 2008-01-14 16:19 92 –a—— C:\WINDOWS\wininit.ini
2008-01-14 11:45 . 2008-01-14 12:16 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-13 23:13 . 2008-01-14 12:00 d——– C:\Program Files\Mozilla Firefox(2)
2008-01-13 22:22 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-13 22:19 . 2008-01-15 17:30 155,648 –a—— C:\WINDOWS\SYSTEM32\igfxtray.exe
2008-01-13 22:19 . 2008-01-15 17:30 126,976 –a—— C:\WINDOWS\SYSTEM32\hkcmd.exe
2008-01-13 14:07 . 2008-01-17 17:29 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-13 14:07 . 2008-01-13 14:07 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-11 19:13 . 2008-01-11 19:13 d——– C:\c5f77b987c73166d2cdca913fe4a
2008-01-11 18:39 . 2008-01-11 18:39 d——– C:\ffa65390c98e3f5c19c149e7f0a4532b
2008-01-10 16:34 . 2008-01-10 16:37 6 –a—— C:\WINDOWS\msoffice.ini
2008-01-10 16:30 . 2008-01-10 16:31 132 –ah—– C:\IPH.PH

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-21 20:21 ——— d—–w C:\Program Files\DellSupport
2008-01-21 17:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-21 17:27 ——— d—–w C:\Program Files\QuickTime
2008-01-20 22:28 ——— d—–w C:\Documents and Settings\Philip Bardin\Application Data\McAfee.com Personal Firewall
2008-01-10 23:53 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-10 23:51 ——— d—–w C:\Program Files\Canon
2008-01-10 21:52 ——— d—–w C:\Program Files\MUSICMATCH
2008-01-10 21:42 ——— d—–w C:\Program Files\Pure Networks
2008-01-10 21:42 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-10 21:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-10 21:37 ——— d—–w C:\Documents and Settings\Philip Bardin\Application Data\AOL
2008-01-10 21:20 ——— d—–w C:\Program Files\MySpace
2007-11-30 05:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-11-27 20:33 ——— d—–w C:\Documents and Settings\Philip Bardin\Application Data\MySpace
2004-12-17 03:30 848 –sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot_2008-01-20_17.40.59.68 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-20 22:20:25 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-21 20:21:34 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-20 22:20:25 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-21 20:21:34 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-20 22:20:25 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-21 20:21:34 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-20 22:20:25 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-21 20:21:34 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-20 22:20:25 3,211,264 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-21 20:21:34 3,219,456 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-20 22:20:25 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-21 20:21:34 147,456 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2003-11-19 22:36:26 24,681 —-a-w C:\WINDOWS\SYSTEM32\java.exe
+ 2007-12-14 05:57:22 135,168 —-a-w C:\WINDOWS\SYSTEM32\java.exe
- 2003-11-19 22:36:30 28,779 —-a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2007-12-14 05:57:24 135,168 —-a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2007-12-14 06:59:16 139,264 —-a-w C:\WINDOWS\SYSTEM32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [ ]
"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [ ]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [ ]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [ ]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [ ]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [ ]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [ ]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [ ]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b78d7fc-c08c-11dc-9f1c-000f1f5be233}]
\Shell\AutoRun\command - E:\wd_windows_tools\setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-21 15:28:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-21 15:30:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-21 20:30:40
ComboFix2.txt 2008-01-21 17:40:40
ComboFix3.txt 2008-01-20 22:41:59
ComboFix4.txt 2008-01-14 03:50:18
.
2008-01-12 00:13:46 — E O F —

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, January 21, 2008 5:15:49 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/01/2008
Kaspersky Anti-Virus database records: 526068
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\

Scan Statistics:
Total number of scanned objects: 39022
Number of viruses found: 5
Number of infected objects: 101
Number of suspicious objects: 0
Duration of the scan process: 01:03:21

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd002.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Philip Bardin\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Philip Bardin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Philip Bardin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Philip Bardin\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Philip Bardin\Local Settings\History\History.IE5\MSHist012008012120080122\index.dat Object is locked skipped
C:\Documents and Settings\Philip Bardin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Philip Bardin\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Philip Bardin\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Intel\Modem Event Monitor\IntelMEM.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\ISM\ism.exe.vir Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\QooBox\Quarantine\C\Program Files\McAfee.com\Agent\mcagent.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\McAfee.com\Agent\McUpdate.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\McAfee.com\PERSON~1\MpfTray.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\McAfee.com\VSO\mcmnhdlr.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\McAfee.com\VSO\mcvsshld.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Real\RealPlayer\RealPlay.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\000070.exe.vir Infected: Trojan-Downloader.Win32.Small.hqc skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\000080.exe.vir/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\000080.exe.vir/stream Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\000080.exe.vir NSIS: infected - 2 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\gebcb.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP854\A0143330.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP854\A0143331.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP854\A0143332.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP854\A0143333.exe Infected: Trojan.Win32.LowZones.dn skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP854\A0143344.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP854\A0143362.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP854\A0143363.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP854\A0143365.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP855\A0143377.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP855\A0143378.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP855\A0143379.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0143390.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0143392.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0143393.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0143394.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145403.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145405.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145409.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145418.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145422.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145423.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145433.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145434.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145436.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145443.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145458.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145460.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP856\A0145461.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP857\A0145624.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP857\A0145625.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP858\A0145675.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP859\A0145728.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP859\A0145738.EXE Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP860\A0145742.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP860\A0145747.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP861\A0145755.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP861\A0145756.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP861\A0145757.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP861\A0145758.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP861\A0145759.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP861\A0145760.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP861\A0145761.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP861\A0145762.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP861\A0145773.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145775.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145796.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145797.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145799.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145800.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145801.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145802.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145803.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145804.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145805.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP862\A0145806.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP864\A0145909.rbf Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP866\A0146019.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP866\A0146027.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP866\A0146028.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP866\A0146029.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP866\A0146030.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP866\A0146032.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP866\A0146033.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP866\A0146034.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146057.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146058.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146059.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146060.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146061.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146062.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146063.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146064.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146065.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146070.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146073.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP868\A0146074.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP869\A0146076.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP869\A0146079.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP869\A0146080.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP869\A0146081.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP869\A0146082.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP869\A0146083.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP869\A0146084.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP869\A0146085.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP869\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\SYSTEM32\000050.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\WINDOWS\SYSTEM32\000050.exe NSIS: infected - 1 skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:32:18 PM, on 1/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Philip Bardin\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe

–
End of file - 4854 bytes
Hi :)

You'll probably have to reinstall McAfee, RealPlayer, AOL and all other programs that aren't functioning correctly. They were infected, and couldn't be disinfected properly.

Please copy and paste the text in the code box into Notepad (Go to Start > Run, type Notepad and hit Enter)

@echo off
if exist "%temp%\log.txt" del "%temp%\log.txt"
for %%g in (
"C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
"C:\Program Files\QuickTime\qttask.exe"
"C:\WINDOWS\SYSTEM32\000050.exe"
) do (
del /a/f/q %%g >nul 2>&1
if exist %%g echo.%%~g>>"%temp%\log.txt"
)
if exist "%temp%\log.txt" ( start notepad "%temp%\log.txt"
) else echo.Deleted Successfully !!
nircmd wait 7000
del %0

Go to File > Save As:. Save the file as "Fix.bat" (Including the quotes)

Double-click on Fix.bat to run the file.

If a Notepad windows pops up, please post its contents in your next reply. Also let me know how your computer is currently running.
Alright, I'm not noticing any odd behavior, and it doesn't seem to slow. Do I need to run any more scans or post anything else? Thank you so much for taking time to help.
Congratulations, your log looks clean. Please advise of any problems you are still experiencing, or follow these simple steps to keep your computer clean in the future:

Click Start then Run….

  • Type Combofix /u in the runbox and click OK. (Note: The space between the x and the /u needs to be there)

    [external image: Posted Image]

  • This will uninstall Combofix.

Make your Internet Explorer More Secure

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

  • Change the Download signed ActiveX controls to Prompt.
  • Change the Download unsigned ActiveX controls to Disable.
  • Change the Initialise and script ActiveX controls not marked as safe to Disable.
  • Change the Installation of desktop items to Prompt.
  • Change the Launching programs and files in an IFRAME to Prompt.
  • Change the Navigate sub-frames across different domains to Prompt.
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.

  • Next press the Apply button and then the OK to exit the Internet Properties page.

Visit Microsoft's Update Site Frequently - It is important that you visit http://update.microsoft.com/ regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install WinPatrol - An excellent startup manager, notifies you if programs are added to startup, allows delayed startup, … A must have! An installation guide can be found here: http://www.winpatrol.com/download.html

Install Malwarebytes' Anti-Malware - You should scan your computer with the program on a regular basis just as you would with your anti-virus software. You can download the program here: http://www.malwarebytes.org/mbam.php

Install IE-Spyad - IE-Spyad places more than 4000 dubious websites and domains in the IE Restricted list. This severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites. A tutorial on installing this product can be found here: http://www.spywarewarrior.com/uiuc/resource.htm#IESPYAD

Update All Your Security Programs Regularly - Make sure you update all your security programs (Anti-Virus, Firewall, Anti-Spyware) regularly (once a weak, at least). Without regular updates you WILL NOT be protected when new malicious programs are released.

You can also read this excellent article by TonyKlein: So how did I get infected in the first place?

Follow this list and your potential for being infected again will reduce dramatically.

Stand Up and Be Counted! - Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints: Malware Complaints. You have to be registered to post. After registering just find your country room and register your complaint. The infection you had was Vundo.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI