This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Do I have a virus or not?

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello!
I am asking for your help because I am not sure if I have a virus or not. Why am I confused?

I`ve had some problems for last two months (once or twice a week) with starting any program, usually when I left computer turned on over the night. Problem was something like "…could not find path or folder.." and I should to reboot a computer. I didn` think it could be a virus because I run AVG AV free daily (updating and scanning is scheduled). At least once a week I also run Spybot and Ad-Aware SE Professional.

But I felt something is wrong so I reformatted (2 weeks ago) all my disks (5 logical on 2 physical disks) and installed everything from scratch. Before and after moving data among disks I made AVG AV scan of specific folder or drive. After installing programs I did AVG AV complete scan. My first action after setting new operating system is installing AV program (in my case AVG AV free 7.5.516) and firewall (ZoneAlarm Pro 7.0.462.000). Nothing found and I thougt I am out of problems.

Since reinstalling it`s happened two times that I could not start any program and had to reboot but somehow I took this as a "this must be a windows issue, let`s used to and live with it".

My AVG AV found some viruses ( Jan.8, 10 and 15th), named Trojan horse PSW.OnLineGames.AACY and Trojan horse Generic9.ALQH, cleaned infected files and I felt quite secure about my protection.

Until few days ago my colleague found a "Trojan horse Dropper.Agent GIT". When I was trying to help him I found out that this is the very same problem which ocurred to me several times …. (can not start programs… there`s no path…etc).

So I returned to my computer and I did all the scans again (AVG, Spybot, Ad-Aware, SpywareBlaster) but still nothing until I used Kaspersky Online Scanner and I FOUND some viruses and infected files.

I have some logs from doing this tests, I can send them to you.
* KAspersky log from yesterday,
* HJT log before ComboFix,
* ComboFix log (followed your instructions - using updated ComboFix, all browsers off) and
* HJT log after ComboFix.

Following your procedure "Before sending HJT log" I`ve done the following:
1. ATF Cleaner OK
2. Spybot No immediate threats were found
3. AVG AS (safe mode)
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 15:35:33 18.1.2008

+ Scan result:



Nothing found.



::Report end

4. HijackThis
Logfile of HijackThis v1.99.1
Scan saved at 22:04:11, on 18.1.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.finderg.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.finderg.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [zzzHPSETUP] H:\Setup.exe \RESET
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: I&zvoz v Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Raziskovanje - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C99103C6-52CA-470D-ACC3-C8F1ABF08D1B}: NameServer = 193.189.160.13,193.189.160.23
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

5. Kaspersky Online Scanner (I was curious and did it again. FOUND NOTHING, but some files are locked and skipped)
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, January 18, 2008 6:22:22 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/01/2008
Kaspersky Anti-Virus database records: 519241
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 46337
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 01:30:48

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\dusan\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\dusan\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped
C:\Documents and Settings\dusan\Application Data\Microsoft\Predloge\Normal.dot Object is locked skipped
C:\Documents and Settings\dusan\Application Data\PC Suite\357093002509614\357093002509614.db Object is locked skipped
C:\Documents and Settings\dusan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\ApplicationHistory\hpqimzone.exe.3204510e.ini.inuse Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\History\History.IE5\MSHist012008011820080119\index.dat Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Temp\~DF16BE.tmp Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Temp\~DFE1B7.tmp Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Temp\~DFE540.tmp Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Temporary Internet Files\Content.Word\~WRS0000.tmp Object is locked skipped
C:\Documents and Settings\dusan\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\dusan\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D4D7852E-2F26-4332-8213-97338AA3BFA0}\RP55\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\HPCOMPAQ.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{404BC8B9-1C64-4AE0-9C77-BF8DF7377CE5}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\ZLT0296c.TMP Object is locked skipped
C:\WINDOWS\TEMP\ZLT06f5f.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{D4D7852E-2F26-4332-8213-97338AA3BFA0}\RP55\change.log Object is locked skipped

Scan process completed.

Thank you in advance!
Dusan
Hello and Welcome to the forum.

I'm not seeing anything bad but lets see if we find anything

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
LDTate thanks for reply and all your help!

I made two logs, both attached.

I also attached Kaspersky Online Scanner log from 17th which made me confused (found viruses and infected objects). As well as I know Kaspersky Online Scanner does not heal, just scans. I didn`t notice any healing action from AVG AV or Spybot or Ad-Aware or ZoneAlarm Pro-AntySpyware, but I tried KAspersky several times again and NO viruses found anymore. In my opinion only reason for that is that I run ATF cleaner soon after KAspersky.

Thanks again
Dusan
You need to copy/paste the logs not attach them.

This is what it looks like when I open it:

ComboFix 08-01-23.1C - dusan 2008-01-25 11:17:32.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.330 [GMT 1:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 ))))))))))))))))))))))))))))))) . 2008-01-25 11:02 . 2008-01-25 11:03
d——– C:\Program Files\MagicISO 2008-01-25 10:47 . 2008-01-25 10:47
d——– C:\WINDOWS\system32\ffdshow 2008-01-25 10:47 . 2008-01-25 10:47
d——– C:\Program Files\SourceTec 2008-01-25 10:47 . 2006-03-11 04:56 438,272 –a—— C:\WINDOWS\system32\Mpeg2DecFilter.ax 2008-01-25 10:47 . 2006-03-11 04:48 434,176 –a—— C:\WINDOWS\system32\MatroskaSplitter.ax 2008-01-25 10:47 . 2005-07-10 02:12 241,664 –a—— C:\WINDOWS\system32\CoreVorbis.ax 2008-01-25 10:47 . 2004-08-18 00:04 217,088 –a—— C:\WINDOWS\system32\CoreFLACDecoder.ax 2008-01-25 10:47 . 2007-03-12 14:17 122,880 –a—— C:\WINDOWS\system32\stQTSource.ax 2008-01-24 14:29 . 2008-01-25 10:47
d——– C:\WINDOWS\LastGood 2008-01-23 13:51 . 2008-01-23 13:51
d——– C:\Program Files\Advanced Registry Optimizer 2008-01-23 12:50 . 2008-01-23 12:50
d——– C:\Program Files\PowerQuest 2008-01-23 09:53 . 2008-01-23 09:53
d——– C:\Program Files\Cucusoft 2008-01-23 09:53 . 2004-10-12 16:40 2,255,360 –a—— C:\WINDOWS\system32\libavcodec.dll 2008-01-23 09:53 . 2004-10-12 16:46 1,761,280 –a—— C:\WINDOWS\system32\ffdshow.ax 2008-01-23 09:53 . 2004-10-05 18:16 395,776 –a—— C:\WINDOWS\system32
sorry

ComboFIX
ComboFix 08-01-23.1C - dusan 2008-01-25 11:17:32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.330 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 )))))))))))))))))))))))))))))))
.

2008-01-25 11:02 . 2008-01-25 11:03 d——– C:\Program Files\MagicISO
2008-01-25 10:47 . 2008-01-25 10:47 d——– C:\WINDOWS\system32\ffdshow
2008-01-25 10:47 . 2008-01-25 10:47 d——– C:\Program Files\SourceTec
2008-01-25 10:47 . 2006-03-11 04:56 438,272 –a—— C:\WINDOWS\system32\Mpeg2DecFilter.ax
2008-01-25 10:47 . 2006-03-11 04:48 434,176 –a—— C:\WINDOWS\system32\MatroskaSplitter.ax
2008-01-25 10:47 . 2005-07-10 02:12 241,664 –a—— C:\WINDOWS\system32\CoreVorbis.ax
2008-01-25 10:47 . 2004-08-18 00:04 217,088 –a—— C:\WINDOWS\system32\CoreFLACDecoder.ax
2008-01-25 10:47 . 2007-03-12 14:17 122,880 –a—— C:\WINDOWS\system32\stQTSource.ax
2008-01-24 14:29 . 2008-01-25 10:47 d——– C:\WINDOWS\LastGood
2008-01-23 13:51 . 2008-01-23 13:51 d——– C:\Program Files\Advanced Registry Optimizer
2008-01-23 12:50 . 2008-01-23 12:50 d——– C:\Program Files\PowerQuest
2008-01-23 09:53 . 2008-01-23 09:53 d——– C:\Program Files\Cucusoft
2008-01-23 09:53 . 2004-10-12 16:40 2,255,360 –a—— C:\WINDOWS\system32\libavcodec.dll
2008-01-23 09:53 . 2004-10-12 16:46 1,761,280 –a—— C:\WINDOWS\system32\ffdshow.ax
2008-01-23 09:53 . 2004-10-05 18:16 395,776 –a—— C:\WINDOWS\system32\libmplayer.dll
2008-01-23 09:53 . 2004-10-12 16:42 262,144 –a—— C:\WINDOWS\system32\TomsMoComp_ff.dll
2008-01-23 09:53 . 2003-04-03 02:17 172,032 –a—— C:\WINDOWS\system32\ac3filter.ax
2008-01-23 09:53 . 2004-10-04 03:50 112,640 –a—— C:\WINDOWS\system32\libmpeg2_ff.dll
2008-01-23 09:41 . 2008-01-23 09:41 d——– C:\Program Files\MP4Converter
2008-01-21 21:24 . 2008-01-23 14:00 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-21 21:24 . 2008-01-21 21:24 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-21 21:23 . 2008-01-21 21:23 d——– C:\Program Files\iTunes
2008-01-21 21:23 . 2008-01-21 21:23 d——– C:\Program Files\iPod
2008-01-21 21:21 . 2008-01-21 21:22 d——– C:\Program Files\QuickTime
2008-01-21 13:07 . 2008-01-21 13:29 38 –a—— C:\WINDOWS\avisplitter.INI
2008-01-19 15:57 . 2008-01-19 15:57 d——– C:\Program Files\Bonjour
2008-01-19 11:09 . 2008-01-19 11:09 0 –a—— C:\WINDOWS\hpqemlsz.INI
2008-01-19 10:59 . 2006-02-15 18:24 430,080 -ra—— C:\WINDOWS\system32\hp3800co.dll
2008-01-19 10:53 . 2008-01-23 12:48 69 –a—— C:\WINDOWS\NeroDigital.ini
2008-01-18 23:40 . 2008-01-18 23:40 d——– C:\Program Files\MSXML 6.0
2008-01-18 23:32 . 2008-01-18 23:32 d——– C:\Program Files\Lavasoft
2008-01-18 23:29 . 2008-01-18 23:29 d——– C:\Program Files\MSXML 4.0
2008-01-18 23:22 . 2004-08-04 02:07 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-01-18 17:13 . 2008-01-18 17:14 d——– C:\totalcmd
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\UC.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\RAR.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\PKZIP.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\PKUNZIP.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\NOCLOSE.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\LHA.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\ARJ.PIF
2008-01-18 17:13 . 2008-01-18 17:17 541 –a—— C:\WINDOWS\wincmd.ini
2008-01-18 16:34 . 2008-01-18 16:34 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-18 16:11 . 2008-01-18 16:12 d——– C:\Program Files\Nero
2008-01-18 16:11 . 2008-01-18 16:11 d——– C:\Program Files\Common Files\Nero
2008-01-18 16:11 . 2006-03-17 11:45 1,757,184 –a—— C:\WINDOWS\system32\imagX7.dll
2008-01-18 16:11 . 2006-03-17 11:45 802,816 –a—— C:\WINDOWS\system32\imagXRA7.dll
2008-01-18 16:11 . 2006-03-17 11:45 497,296 –a—— C:\WINDOWS\system32\imagXpr7.dll
2008-01-18 16:11 . 2006-03-17 14:49 368,640 –a—— C:\WINDOWS\system32\TwnLib4.dll
2008-01-18 16:11 . 2006-03-17 11:45 258,048 –a—— C:\WINDOWS\system32\imagXR7.dll
2008-01-18 13:09 . 2007-05-30 13:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-18 12:53 . 2006-03-17 01:38 28,672 ——— C:\WINDOWS\system32\verclsid.exe
2008-01-17 22:51 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-17 19:58 . 2008-01-17 19:58 d——– C:\Program Files\SpywareBlaster
2008-01-17 19:58 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-01-17 16:11 . 2008-01-17 16:11 d——– C:\Program Files\URUSoft
2008-01-16 22:52 . 2008-01-16 22:52 d——– C:\Program Files\DIFX
2008-01-16 22:52 . 2008-01-16 22:52 d——– C:\Program Files\Common Files\PCSuite
2008-01-16 22:52 . 2008-01-16 22:52 d——– C:\Program Files\Common Files\Nokia
2008-01-16 22:51 . 2008-01-16 22:51 d——– C:\Program Files\PC Connectivity Solution
2008-01-16 22:51 . 2008-01-16 22:52 d——– C:\Program Files\Nokia
2008-01-16 22:51 . 2007-02-22 10:15 137,216 –a—— C:\WINDOWS\system32\drivers\nmwcd.sys
2008-01-16 22:51 . 2007-02-22 10:15 90,624 –a—— C:\WINDOWS\system32\nmwcdcls.dll
2008-01-16 22:51 . 2007-02-22 10:15 65,536 –a—— C:\WINDOWS\system32\nmwcdcocls.dll
2008-01-16 22:51 . 2007-02-22 10:15 12,288 –a—— C:\WINDOWS\system32\drivers\nmwcdcm.sys
2008-01-16 22:51 . 2007-02-22 10:15 8,320 –a—— C:\WINDOWS\system32\drivers\nmwcdc.sys
2008-01-16 07:31 . 2008-01-16 07:31 d——– C:\Program Files\CCleaner
2008-01-15 19:05 . 2008-01-15 19:05 d——– C:\Program Files\PhotoZoom Pro 2
2008-01-15 19:05 . 2008-01-15 19:05 1,600 –a—— C:\WINDOWS\jgdp_q64.ini
2008-01-15 17:01 . 2008-01-15 17:01 d——– C:\Program Files\Common Files\Sonic Shared
2008-01-15 16:59 . 2008-01-15 17:00 d——– C:\Program Files\Common Files\HP
2008-01-15 16:58 . 2008-01-15 16:58 d——– C:\WINDOWS\system32\URTTEMP
2008-01-15 16:50 . 2008-01-15 16:33 100,381 ——— C:\WINDOWS\hpgins13.dat.temp
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmpF360C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmpF260C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmp6250C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmp6150C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmp4750C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmp2C50C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmp1D50C.FOT
2008-01-15 16:50 . 2006-03-08 03:33 173 ——— C:\WINDOWS\hpgmdl13.dat
2008-01-15 16:40 . 2004-08-04 00:56 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2008-01-15 16:40 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-01-15 16:40 . 2004-08-03 22:58 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-01-15 16:40 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2008-01-15 16:32 . 2008-01-15 16:32 d——– C:\Program Files\Common Files\Hewlett-Packard
2008-01-15 16:30 . 2008-01-15 16:55 d——– C:\Program Files\HP
2008-01-15 16:28 . 2008-01-15 17:04 100,399 –a—— C:\WINDOWS\hpgins13.dat
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmpDEEBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmpB3FBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmpA7FBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmpA5FBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmp98FBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmp30EBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmp14EBF.FOT
2008-01-11 23:49 . 2008-01-15 10:40 d——– C:\WINDOWS\system32\NtmsData
2008-01-11 21:37 . 2008-01-15 10:20 d——– C:\Program Files\Common Files\Symantec Shared
2008-01-11 15:45 . 2008-01-19 10:40 d–h—– C:\WINDOWS\$hf_mig$
2008-01-11 15:23 . 2008-01-11 21:35 d——– C:\Program Files\Norton Security Scan
2008-01-11 13:57 . 2008-01-11 13:57 d——– C:\WINDOWS\Downloaded Installations

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 11:50 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-23 11:50 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-01-17 20:01 43,662 —-a-w C:\WINDOWS\Internet Logs\GLB2_2nd_2008_01_17_20_02_43_small.dmp.zip
2008-01-17 20:01 43,580 —-a-w C:\WINDOWS\Internet Logs\GLB8_2nd_2008_01_17_20_02_57_small.dmp.zip
2008-01-15 15:55 ——— d—–w C:\Program Files\Hewlett-Packard
2008-01-07 21:04 1,810 –sha-r C:\WINDOWS\system32\drivers\103C_HP_NTBK_HP Compaq nx7400 (RH646ES#AKN)_YN_0U_QCNU642412K_EU_46_I30A2_SHP_VKBC Version 40.17_B68YGU Ver. F.0C_T070725_WXP2_L409_M1016_J100_7Intel_8Core2 T5500_91.66_#080107_N14E4170C_(RH646ES#AKN)_XMOBILE_CN10.MRK
2008-01-07 20:55 ——— d—–w C:\Program Files\Analog Devices
2008-01-07 20:47 ——— d—–w C:\Program Files\Broadcom
2008-01-07 20:45 499,712 —-a-w C:\WINDOWS\system32\msvcp71.dll
2008-01-07 20:45 348,160 —-a-w C:\WINDOWS\system32\msvcr71.dll
2008-01-07 20:31 ——— d–h–w C:\Program Files\Uninstall Information
2008-01-07 20:26 ——— d—–w C:\Program Files\microsoft frontpage
2007-12-24 12:49 7,680 —-a-w C:\WINDOWS\system32\ff_vfw.dll
2007-12-04 01:33 682,496 —-a-w C:\WINDOWS\system32\divx.dll
2007-11-29 22:30 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:28 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2007-11-14 15:05 1,086,952 —-a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 16:40 227,328 —-a-w C:\WINDOWS\system32\wmasf.dll
2006-02-19 02:28 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:07 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 13:39 1289000]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-02-28 23:06 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-07 21:45 579072]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 17:36 872448]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 08:12 729088]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-09-14 09:32 141848]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-09-14 09:32 166424]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-09-14 09:32 137752]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 14:18 995328]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 14:13 1101824]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"NotebookHardwareControl"="C:\Program Files\Notebook Hardware Control\nhc.exe" [2007-05-04 01:33 2629632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"zzzHPSETUP"="H:\Setup.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:07 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-07 21:45 219136]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)


.
Contents of the 'Scheduled Tasks' folder
"2008-01-21 18:24:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-11 14:23:42 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-25 11:18:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-25 11:19:27
.
2008-01-24 13:30:39 — E O F —

HiJackThis
Logfile of HijackThis v1.99.1
Scan saved at 11:20:23, on 25.1.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.finderg.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [zzzHPSETUP] H:\Setup.exe \RESET
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: I&zvoz v Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Raziskovanje - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C99103C6-52CA-470D-ACC3-C8F1ABF08D1B}: NameServer = 193.189.160.13,193.189.160.23
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Kaspersky Online Scanner made on 17th
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Thursday, January 17, 2008 10:37:53 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/01/2008
Kaspersky Anti-Virus database records: 517094
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 45880
Number of viruses found: 1
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 01:22:26

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\dusan\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\dusan\Application Data\Mozilla\Firefox\Profiles\kvniiawl.default\history.dat Object is locked skipped
C:\Documents and Settings\dusan\Application Data\Mozilla\Firefox\Profiles\kvniiawl.default\parent.lock Object is locked skipped
C:\Documents and Settings\dusan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\ApplicationHistory\hpqimzone.exe.3204510e.ini.inuse Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Mozilla\Firefox\Profiles\kvniiawl.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Mozilla\Firefox\Profiles\kvniiawl.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Mozilla\Firefox\Profiles\kvniiawl.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Application Data\Mozilla\Firefox\Profiles\kvniiawl.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\History\History.IE5\MSHist012008011720080118\index.dat Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Temp\~DF8C62.tmp Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Temp\~DFEA8B.tmp Object is locked skipped
C:\Documents and Settings\dusan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dusan\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\dusan\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\dusan\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\RECYCLER\S-1-5-21-1078081533-1580436667-725345543-1003\Dc21.rar/msnc2.exe Infected: HackTool.Win32.MSNaccCrack.20 skipped
C:\RECYCLER\S-1-5-21-1078081533-1580436667-725345543-1003\Dc21.rar RAR: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D4D7852E-2F26-4332-8213-97338AA3BFA0}\RP51\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\HPCOMPAQ.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT064fe.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT06df3.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.
Open notepad and copy/paste the text in the Codebox below into it:

File::
C:\WINDOWS\hpqemlsz.INI
C:\WINDOWS\hpgins13.dat.temp

Folder::
C:\Program Files\Bonjour



Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
I had a problem while running a ComboFix. I had to reboot system because just before poping up a Combo`s log it freezed. Not sure why but could be because I had ZoneAlarm switched on and had to click "allow" several times in meantime when Combo was running. I saw that some files and folders were deleted (e.g. Program Files/Bonjour). There was also message in Combo FINDSTR:String for searching (or maybe finding) too loong (it was in my local language)

I run HiJackThis immediatelly when system restarted. I rerun Combo with CFSsript again.

Before posting log a few words about my system. Just before I got your post there was Norton Security Scan (free, version 1.4.0.16) updating and scanning system (I forgot already I have it on system). It found Trojan virus , but no location or name. I don`t know now is it really something there or is it only a marketing trick to buy a program.

Only thing which I see in last period different as before is that my CPU is heating a lot (T5500 Core2Duo in HPnx7400). It easy reaches over 90C, even 100C. Could be somehow because of the bunch of antivirus and antispaware programs??

HJT log made after restarting a machine. ComboFix was almost done but log was not posted
Logfile of HijackThis v1.99.1
Scan saved at 20:02, on 2008-01-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Notebook Hardware Control\nhc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.finderg.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: I&zvoz v Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Raziskovanje - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C99103C6-52CA-470D-ACC3-C8F1ABF08D1B}: NameServer = 193.189.160.13,193.189.160.23
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

CombFix with CFScript BUT after restarting a machine which caused by first ComboFix running
ComboFix 08-01-23.1C - dusan 2008-01-25 20:05:00.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.555 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\dusan\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\hpgins13.dat.temp
C:\WINDOWS\hpqemlsz.INI
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Program Files\Bonjour
C:\Program Files\Bonjour\mdnsNSP.dll
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\hpgins13.dat.temp
C:\WINDOWS\hpqemlsz.INI

.
((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 )))))))))))))))))))))))))))))))
.

2008-01-25 17:59 . 2008-01-25 17:59 d——– C:\Program Files\PhotoZoom Pro 2
2008-01-25 11:02 . 2008-01-25 11:03 d——– C:\Program Files\MagicISO
2008-01-25 10:47 . 2008-01-25 10:47 d——– C:\WINDOWS\system32\ffdshow
2008-01-25 10:47 . 2008-01-25 10:47 d——– C:\Program Files\SourceTec
2008-01-25 10:47 . 2006-03-11 04:56 438,272 –a—— C:\WINDOWS\system32\Mpeg2DecFilter.ax
2008-01-25 10:47 . 2006-03-11 04:48 434,176 –a—— C:\WINDOWS\system32\MatroskaSplitter.ax
2008-01-25 10:47 . 2005-07-10 02:12 241,664 –a—— C:\WINDOWS\system32\CoreVorbis.ax
2008-01-25 10:47 . 2004-08-18 00:04 217,088 –a—— C:\WINDOWS\system32\CoreFLACDecoder.ax
2008-01-25 10:47 . 2007-03-12 14:17 122,880 –a—— C:\WINDOWS\system32\stQTSource.ax
2008-01-23 13:51 . 2008-01-23 13:51 d——– C:\Program Files\Advanced Registry Optimizer
2008-01-23 12:50 . 2008-01-23 12:50 d——– C:\Program Files\PowerQuest
2008-01-23 09:53 . 2008-01-23 09:53 d——– C:\Program Files\Cucusoft
2008-01-23 09:53 . 2004-10-12 16:40 2,255,360 –a—— C:\WINDOWS\system32\libavcodec.dll
2008-01-23 09:53 . 2004-10-12 16:46 1,761,280 –a—— C:\WINDOWS\system32\ffdshow.ax
2008-01-23 09:53 . 2004-10-05 18:16 395,776 –a—— C:\WINDOWS\system32\libmplayer.dll
2008-01-23 09:53 . 2004-10-12 16:42 262,144 –a—— C:\WINDOWS\system32\TomsMoComp_ff.dll
2008-01-23 09:53 . 2003-04-03 02:17 172,032 –a—— C:\WINDOWS\system32\ac3filter.ax
2008-01-23 09:53 . 2004-10-04 03:50 112,640 –a—— C:\WINDOWS\system32\libmpeg2_ff.dll
2008-01-23 09:41 . 2008-01-23 09:41 d——– C:\Program Files\MP4Converter
2008-01-21 21:24 . 2008-01-25 19:59 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-21 21:24 . 2008-01-21 21:24 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-21 21:23 . 2008-01-21 21:23 d——– C:\Program Files\iTunes
2008-01-21 21:23 . 2008-01-21 21:23 d——– C:\Program Files\iPod
2008-01-21 21:21 . 2008-01-21 21:22 d——– C:\Program Files\QuickTime
2008-01-21 13:07 . 2008-01-21 13:29 38 –a—— C:\WINDOWS\avisplitter.INI
2008-01-19 10:59 . 2006-02-15 18:24 430,080 -ra—— C:\WINDOWS\system32\hp3800co.dll
2008-01-19 10:53 . 2008-01-23 12:48 69 –a—— C:\WINDOWS\NeroDigital.ini
2008-01-18 23:40 . 2008-01-18 23:40 d——– C:\Program Files\MSXML 6.0
2008-01-18 23:32 . 2008-01-18 23:32 d——– C:\Program Files\Lavasoft
2008-01-18 23:29 . 2008-01-18 23:29 d——– C:\Program Files\MSXML 4.0
2008-01-18 23:22 . 2004-08-04 02:07 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-01-18 17:13 . 2008-01-25 15:19 d——– C:\totalcmd
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\UC.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\RAR.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\PKZIP.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\PKUNZIP.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\NOCLOSE.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\LHA.PIF
2008-01-18 17:13 . 2004-03-03 06:02 545 –a—— C:\WINDOWS\ARJ.PIF
2008-01-18 17:13 . 2008-01-25 15:20 541 –a—— C:\WINDOWS\wincmd.ini
2008-01-18 16:34 . 2008-01-18 16:34 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-18 16:11 . 2008-01-18 16:12 d——– C:\Program Files\Nero
2008-01-18 16:11 . 2008-01-18 16:11 d——– C:\Program Files\Common Files\Nero
2008-01-18 16:11 . 2006-03-17 11:45 1,757,184 –a—— C:\WINDOWS\system32\imagX7.dll
2008-01-18 16:11 . 2006-03-17 11:45 802,816 –a—— C:\WINDOWS\system32\imagXRA7.dll
2008-01-18 16:11 . 2006-03-17 11:45 497,296 –a—— C:\WINDOWS\system32\imagXpr7.dll
2008-01-18 16:11 . 2006-03-17 14:49 368,640 –a—— C:\WINDOWS\system32\TwnLib4.dll
2008-01-18 16:11 . 2006-03-17 11:45 258,048 –a—— C:\WINDOWS\system32\imagXR7.dll
2008-01-18 13:09 . 2007-05-30 13:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-18 12:53 . 2006-03-17 01:38 28,672 ——— C:\WINDOWS\system32\verclsid.exe
2008-01-17 22:51 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-17 19:58 . 2008-01-17 19:58 d——– C:\Program Files\SpywareBlaster
2008-01-17 19:58 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-01-17 16:11 . 2008-01-17 16:11 d——– C:\Program Files\URUSoft
2008-01-16 22:52 . 2008-01-16 22:52 d——– C:\Program Files\DIFX
2008-01-16 22:52 . 2008-01-16 22:52 d——– C:\Program Files\Common Files\PCSuite
2008-01-16 22:52 . 2008-01-16 22:52 d——– C:\Program Files\Common Files\Nokia
2008-01-16 22:51 . 2008-01-16 22:51 d——– C:\Program Files\PC Connectivity Solution
2008-01-16 22:51 . 2008-01-16 22:52 d——– C:\Program Files\Nokia
2008-01-16 22:51 . 2007-02-22 10:15 137,216 –a—— C:\WINDOWS\system32\drivers\nmwcd.sys
2008-01-16 22:51 . 2007-02-22 10:15 90,624 –a—— C:\WINDOWS\system32\nmwcdcls.dll
2008-01-16 22:51 . 2007-02-22 10:15 65,536 –a—— C:\WINDOWS\system32\nmwcdcocls.dll
2008-01-16 22:51 . 2007-02-22 10:15 12,288 –a—— C:\WINDOWS\system32\drivers\nmwcdcm.sys
2008-01-16 22:51 . 2007-02-22 10:15 8,320 –a—— C:\WINDOWS\system32\drivers\nmwcdc.sys
2008-01-16 07:31 . 2008-01-16 07:31 d——– C:\Program Files\CCleaner
2008-01-15 19:05 . 2008-01-15 19:05 1,600 –a—— C:\WINDOWS\jgdp_q64.ini
2008-01-15 17:01 . 2008-01-15 17:01 d——– C:\Program Files\Common Files\Sonic Shared
2008-01-15 16:59 . 2008-01-15 17:00 d——– C:\Program Files\Common Files\HP
2008-01-15 16:58 . 2008-01-15 16:58 d——– C:\WINDOWS\system32\URTTEMP
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmpF360C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmpF260C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmp6250C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmp6150C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmp4750C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmp2C50C.FOT
2008-01-15 16:50 . 2008-01-15 16:50 1,409 –a—— C:\WINDOWS\system32\tmp1D50C.FOT
2008-01-15 16:50 . 2006-03-08 03:33 173 ——— C:\WINDOWS\hpgmdl13.dat
2008-01-15 16:40 . 2004-08-04 00:56 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2008-01-15 16:40 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-01-15 16:40 . 2004-08-03 22:58 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-01-15 16:40 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2008-01-15 16:32 . 2008-01-15 16:32 d——– C:\Program Files\Common Files\Hewlett-Packard
2008-01-15 16:30 . 2008-01-15 16:55 d——– C:\Program Files\HP
2008-01-15 16:28 . 2008-01-15 17:04 100,399 –a—— C:\WINDOWS\hpgins13.dat
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmpDEEBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmpB3FBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmpA7FBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmpA5FBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmp98FBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmp30EBF.FOT
2008-01-15 16:27 . 2008-01-15 16:27 1,409 –a—— C:\WINDOWS\system32\tmp14EBF.FOT
2008-01-11 23:49 . 2008-01-15 10:40 d——– C:\WINDOWS\system32\NtmsData
2008-01-11 21:37 . 2008-01-25 15:25 d——– C:\Program Files\Common Files\Symantec Shared
2008-01-11 15:45 . 2008-01-19 10:40 d–h—– C:\WINDOWS\$hf_mig$
2008-01-11 15:23 . 2008-01-25 18:00 d——– C:\Program Files\Norton Security Scan
2008-01-11 13:57 . 2008-01-11 13:57 d——– C:\WINDOWS\Downloaded Installations
2008-01-11 12:02 . 2008-01-11 12:02 d——– C:\WINDOWS\Sun
2008-01-11 12:01 . 2008-01-11 12:01 d——– C:\Program Files\Java
2008-01-11 12:01 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-01-11 12:00 . 2008-01-11 12:00 d——– C:\Program Files\Common Files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 11:50 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-23 11:50 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-01-17 20:01 43,662 —-a-w C:\WINDOWS\Internet Logs\GLB2_2nd_2008_01_17_20_02_43_small.dmp.zip
2008-01-17 20:01 43,580 —-a-w C:\WINDOWS\Internet Logs\GLB8_2nd_2008_01_17_20_02_57_small.dmp.zip
2008-01-15 15:55 ——— d—–w C:\Program Files\Hewlett-Packard
2008-01-07 21:04 1,810 –sha-r C:\WINDOWS\system32\drivers\103C_HP_NTBK_HP Compaq nx7400 (RH646ES#AKN)_YN_0U_QCNU642412K_EU_46_I30A2_SHP_VKBC Version 40.17_B68YGU Ver. F.0C_T070725_WXP2_L409_M1016_J100_7Intel_8Core2 T5500_91.66_#080107_N14E4170C_(RH646ES#AKN)_XMOBILE_CN10.MRK
2008-01-07 20:55 ——— d—–w C:\Program Files\Analog Devices
2008-01-07 20:47 ——— d—–w C:\Program Files\Broadcom
2008-01-07 20:45 499,712 —-a-w C:\WINDOWS\system32\msvcp71.dll
2008-01-07 20:45 348,160 —-a-w C:\WINDOWS\system32\msvcr71.dll
2008-01-07 20:31 ——— d–h–w C:\Program Files\Uninstall Information
2008-01-07 20:26 ——— d—–w C:\Program Files\microsoft frontpage
2007-12-24 12:49 7,680 —-a-w C:\WINDOWS\system32\ff_vfw.dll
2007-12-04 01:33 682,496 —-a-w C:\WINDOWS\system32\divx.dll
2007-11-29 22:30 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:28 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2007-11-14 15:05 1,086,952 —-a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 16:40 227,328 —-a-w C:\WINDOWS\system32\wmasf.dll
2006-02-19 02:28 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:07 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 13:39 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-07 21:45 579072]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 17:36 872448]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 08:12 729088]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-09-14 09:32 141848]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-09-14 09:32 166424]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-09-14 09:32 137752]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 14:18 995328]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 14:13 1101824]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"NotebookHardwareControl"="C:\Program Files\Notebook Hardware Control\nhc.exe" [2007-05-04 01:33 2629632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:07 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-07 21:45 219136]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)


.
Contents of the 'Scheduled Tasks' folder
"2008-01-21 18:24:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-25 18:42:37 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-25 20:06:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-25 20:06:58
ComboFix-quarantined-files.txt 2008-01-25 19:06:48
.
2008-01-24 13:30:39 — E O F —
Lets make sure norton's it totally gone:

To completely uninstall Symantec AntiVirus?
Problem: The solution to many problems with Symantec AntiVirus is to completely uninstall Symantec AntiVirus, then re-install. You can use these instructions to completely uninstall Symantec AntiVirus.

Solution: In order to completely uninstall Symantec AntiVirus and all related components you need to follow these instructions.
Note: This procedure will remove all Symantec products, not just Symantec AntiVirus.

1.Click on Start | Settings | Control Panel
2.In the control panel double-click on Add / Remove Programs
3.Look through the list of installed programs for any item that says either "Norton" or "Symantec" or "LiveUpdate". (for example "Symantec AntiVirus Corporate Edition" or "Norton AntiVirus 2000")
4.For each "Norton", "Symantec", or "LiveUpdate" item, select the item and click Add / Remove. Follow the instructions, and click Yes or Yes to all when prompted.
When you are done there should be no items in the list that say "Norton", "Symantec", or "LiveUpdate".
5.Click OK to close the Add / Remove Programs window.
6.Reboot your computer if it hasn't already automatically rebooted.
7.Delete the c:\Program Files\Symantec AntiVirus (or c:\Program Files\Norton) folder.
8.Delete the c:\Program Files\Symantec folder.
9.Delete the c:\Program Files\Common Files\Symantec Shared folder.



If uninstalling Symantec AntiVirus using Add / Remove Programs does not work, you can use the directions on this Symantec website to manually remove all elements of Symantec Antivirus from your computer.
http://service1.symantec.com/SUPPORT/ent-s…src=bar_sch_nam


Reboot and let me know how it's running now.
It`s done. There`re were no Norton/Symantec folders except c:\Program Files\Common Files\Symantec Shared folder. I think because I use Your Uninstaller for uninstall, it`s more thorough. I had only Symantec Security Scan on my system and no more than one week. It was only one of my attempts to find out do I have or have not a virus. So I don`t think Symantec caused a problem. At the moment I couldn`t say that something is very different as it was last few weeks. I intend to follow what is going on on my machine with different tools and maybe I`ll come back to forum and to you again. Larry, thank you very much for all your efforts and quick responses. Best regards Dusan
Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    Here's my usual all clean post

    Log looks good :D


    You need to create a new Clean restore point.

    Note: This will remove all previous Restore Points

    Click Start Menu > Run > copy and paste

    %SystemRoot%\System32\restore\rstrui.exe

    Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

    Double-click My Computer.
    Click the Tools menu, and then click Folder Options.
    Click the View tab.
    Check "Hide file extensions for known file types."
    Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
    Check "Hide protected operating system files."
    Click Apply, and then click OK.

    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI