This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HijackThis Log

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello all, Ive come to you guys before, you work miracles via internet. :]

heres my log, ive been recently getting alot of spyware that leads to infections :[.

Logfile of HijackThis v1.99.1
Scan saved at 12:25:33 PM, on 2/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Ideazon\ZEngine\Zboard.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\killer\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BMc7978b04] Rundll32.exe "C:\WINDOWS\system32\juswnhrj.dll",s
O4 - HKLM\..\Run: [c4a4b898] rundll32.exe "C:\WINDOWS\system32\kmwvilgr.dll",b
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\AllMusicConverter\YouTubeRipper.dll
O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\AllMusicConverter\YouTubeRipper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMovieServer - SoundMovieServer - C:\WINDOWS\system32\snmvtsvc.exe


Thanks in advance internet buddies
Sincerly, Arrik Montijo
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!





__________________________________________________________
I see you have been here before with a few different machines.
Why does this one not have an anti Virus program running? :pullhair:

I see no signs of an anti virus program.. I suggest you get one in asap.
I will list 3 free anti virus programs just choose 1.

AVG FREE

Avast

Avira AntiVir Personal Edition Classic


Download and install one of these and run a full scan.

____________________________________________________

Something is hiding from us.

Right click on hijackthis.exe and choose rename:
Rename it to noname:


Post a new HJT log after renaming of HJT.
I installed Avira Antivir and it kept popping up with 2 viruses everytime i tried to delete, quarentine, or ignore them they would just keep popping up to the point that i had to reboot, so i restarted and renamed the file and heres the log

also did a scan and delete a bunch of virsus

Logfile of HijackThis v1.99.1
Scan saved at 9:35:59 PM, on 2/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Ideazon\ZEngine\Zboard.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\whatwhat\noname.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ChangerBHO Class - {0edc6c20-a31c-11db-8ab9-0800200c9a66} - C:\WINDOWS\system32\cliconfga.dll
O2 - BHO: ContextualAds Class - {3AAC4C68-AFC8-11DB-80EF-8AF955D89593} - C:\Program Files\TrustIn Contextual\trustincontext.dll
O2 - BHO: ChangerBHO Class - {4c03732f-43bb-4d80-ba45-66fd05db11df} - C:\WINDOWS\system32\6to4svcs.dll
O2 - BHO: KontekstualAds Class - {72217827-914b-46c6-a6ee-c00c70842ebf} - C:\Program Files\TrustIn Kontekstual\InTru.dll
O2 - BHO: {12a7dbf2-38a9-06cb-c6c4-81c2cddf2d79} - {97d2fddc-2c18-4c6c-bc60-9a832fbd7a21} - C:\WINDOWS\system32\nfbnbhqh.dll (file missing)
O2 - BHO: (no name) - {E99C690E-E103-42E6-A444-F1A258311F71} - C:\WINDOWS\system32\jkhfg.dll
O2 - BHO: WeeklyExecuter Class - {f015f320-ab08-11db-abbd-0800200c9a66} - C:\WINDOWS\inetloader.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BMc7978b04] Rundll32.exe "C:\WINDOWS\system32\fvxsxhgs.dll",s
O4 - HKLM\..\Run: [c4a4b898] rundll32.exe "C:\WINDOWS\system32\qdvwcofl.dll",b
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\AllMusicConverter\YouTubeRipper.dll
O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\AllMusicConverter\YouTubeRipper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O20 - Winlogon Notify: jkhfg - C:\WINDOWS\system32\jkhfg.dll
O20 - Winlogon Notify: rqrsrsq - C:\WINDOWS\SYSTEM32\rqrsrsq.dll
O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMovieServer - SoundMovieServer - C:\WINDOWS\system32\snmvtsvc.exe
1. Download Combo fix from one of these locations.
* IMPORTANT !!! Place combofix.exe on your Desktop

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

2. Click start/run and copy and Paste this in exactly using the picture below for reference:

"%userprofile%\desktop\combofix.exe" /killall


[external image: Posted Image]

3. Combo will begin to run DO NOTHING while this is happeneing.
  • It will kill a few processes and disconnect you from the internet.
  • If by chance it stops prematurly you can re-establish your internet connection by restarting your computer.
  • This needs to be done so the program can work most efficiently for you.
Do not attempt to use the internet or anything else while it's doing its job for you.

If when it's completed you can not get on the internet just reboot the computer

Post the log from comboFix for me located in
c:\comboFix.txt
ok i did everything asked heres the log

ComboFix 08-02-18.1 - Emmanuel Montijo 2008-02-18 10:01:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.697 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\TrustIn Contextual
C:\Program Files\TrustIn Contextual\trustincontext.dll
C:\Program Files\TrustIn Kontekstual
C:\Program Files\TrustIn Kontekstual\InTru.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\inetloader.dll
C:\WINDOWS\system32\awfymedt.ini
C:\WINDOWS\system32\byodlflw.ini
C:\WINDOWS\system32\eggtjtbv.ini
C:\WINDOWS\system32\fjyyevno.ini
C:\WINDOWS\system32\fnuupyfn.ini
C:\WINDOWS\system32\fvwcmksr.ini
C:\WINDOWS\system32\gfhkj.bak1
C:\WINDOWS\system32\gfhkj.bak2
C:\WINDOWS\system32\gfhkj.ini
C:\WINDOWS\system32\gfpdvhlj.dll
C:\WINDOWS\system32\gfvqfeif.ini
C:\WINDOWS\system32\glblskoy.ini
C:\WINDOWS\system32\gooqnjne.ini
C:\WINDOWS\system32\gwkxklbp.ini
C:\WINDOWS\system32\haqneshv.ini
C:\WINDOWS\system32\hhdelobn.dll
C:\WINDOWS\system32\hlxqtrmo.ini
C:\WINDOWS\system32\hqxfolub.ini
C:\WINDOWS\system32\ibplsbni.ini
C:\WINDOWS\system32\iuoqpymw.ini
C:\WINDOWS\system32\jdgjuiii.ini
C:\WINDOWS\system32\klarrhqe.ini
C:\WINDOWS\system32\lbwefskq.dll
C:\WINDOWS\system32\ldywvtnq.ini
C:\WINDOWS\system32\lfocwvdq.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdaalgwh.ini
C:\WINDOWS\system32\mhcyfhhw.ini
C:\WINDOWS\system32\mlqbwbwf.dll
C:\WINDOWS\system32\mupmyeyy.ini
C:\WINDOWS\system32\myojtajx.ini
C:\WINDOWS\system32\oivutweg.dll
C:\WINDOWS\system32\ouofgxyl.ini
C:\WINDOWS\system32\pxqdluye.ini
C:\WINDOWS\system32\qmptrupw.ini
C:\WINDOWS\system32\rglivwmk.ini
C:\WINDOWS\system32\rgyixibh.ini
C:\WINDOWS\system32\rtnnmega.ini
C:\WINDOWS\system32\stvrltov.ini
C:\WINDOWS\system32\thjtsqvq.dll
C:\WINDOWS\system32\tsmcrtqo.ini
C:\WINDOWS\system32\ungkdljs.ini
C:\WINDOWS\system32\uqihrdrd.ini
C:\WINDOWS\system32\vaokxtbg.ini
C:\WINDOWS\system32\vfcwvwju.dll
C:\WINDOWS\system32\xtufpcai.dll
C:\WINDOWS\system32\xxhkyyfj.ini
C:\WINDOWS\system32\ytqyyrhr.ini
C:\WINDOWS\system32\yxhdvnbp.ini

.
((((((((((((((((((((((((( Files Created from 2008-01-18 to 2008-02-18 )))))))))))))))))))))))))))))))
.

2008-02-17 20:18 . 2008-02-17 20:18 d——– C:\Program Files\Avira
2008-02-17 20:18 . 2008-02-17 20:18 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-02-15 18:58 . 2008-02-17 20:16 13,288 –a—— C:\WINDOWS\BMc7978b04.xml
2008-02-15 18:58 . 2008-02-17 13:59 21 –a—— C:\WINDOWS\pskt.ini
2008-01-23 19:55 . 2008-01-23 19:55 294 —hs—- C:\WINDOWS\system32\mufbxaxk.ini
2008-01-22 23:21 . 2008-02-18 10:05 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-22 23:21 . 2008-01-22 23:21 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-22 23:20 . 2008-01-22 23:20 d——– C:\Program Files\iTunes
2008-01-22 23:20 . 2008-01-22 23:20 d——– C:\Program Files\iPod
2008-01-22 15:56 . 2008-01-22 15:56 d——– C:\Program Files\Windows Media Connect 2
2008-01-22 15:55 . 2008-01-22 15:55 d——– C:\WINDOWS\system32\drivers\UMDF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-18 05:38 ——— d—–w C:\Documents and Settings\Emmanuel Montijo\Application Data\BitTorrent DNA
2008-02-18 05:35 ——— d—–w C:\Program Files\whatwhat
2008-01-26 08:31 ——— d—–w C:\Program Files\World of Warcraft
2008-01-24 02:20 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-23 07:19 ——— d—–w C:\Program Files\QuickTime
2008-01-11 04:45 ——— d—–w C:\Program Files\Common Files\AVSMedia
2008-01-11 04:44 ——— d—–w C:\Program Files\AVSMedia
2008-01-10 04:51 ——— d—–w C:\Documents and Settings\Emmanuel Montijo\Application Data\Sibelius Software
2008-01-10 04:49 ——— d—–w C:\Program Files\Musicnotes
2007-12-28 18:22 ——— d—–w C:\Program Files\Free CD Music Converter
2007-12-27 22:36 ——— d—–w C:\Documents and Settings\Emmanuel Montijo\Application Data\deskUNPDF
2007-12-27 22:34 ——— d—–w C:\Program Files\Docudesk
2007-12-18 19:40 ——— d—–w C:\Program Files\AllMusicConverter
2007-12-18 19:31 ——— d—–w C:\Program Files\MP4Converter
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-17 05:47 4,346,084 —-a-w C:\WoW-2.3.0.7561-to-0.3.2.7627-enUS-patch.exe
2007-12-15 01:07 513,152 —-a-w C:\WINDOWS\system32\MusCDriverV32.sys
2007-12-15 01:07 3,768 —-a-w C:\WINDOWS\system32\MusCVideo32.sys
2007-12-15 01:07 10,552 —-a-w C:\WINDOWS\system32\MusCVideo32.dll
2007-12-15 01:06 184,320 —-a-w C:\WINDOWS\system32\snmvtsvc.exe
2007-12-07 00:44 666,112 —-a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
2007-11-24 05:59 22,016 —-a-w C:\WINDOWS\system32\6to4svcs.dll
2007-11-23 05:47 22,016 —-a-w C:\WINDOWS\system32\asferrorv.dll
2007-11-22 00:49 22,016 —-a-w C:\WINDOWS\system32\appmgra.dll
2007-08-23 05:22 51,185,123 —-a-w C:\Documents and Settings\Emmanuel Montijo\WoW-2.1.3.6898-to-0.2.0.6932-enUS-patch.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4c03732f-43bb-4d80-ba45-66fd05db11df}]
2007-11-23 21:59 22016 –a—— C:\WINDOWS\system32\6to4svcs.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97d2fddc-2c18-4c6c-bc60-9a832fbd7a21}]
C:\WINDOWS\system32\nfbnbhqh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E99C690E-E103-42E6-A444-F1A258311F71}]
C:\WINDOWS\system32\jkhfg.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 13:17 50736]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"BitTorrent DNA"="C:\Program Files\BitTorrent_DNA\dna.exe" [2007-10-11 22:55 286016]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56 64512]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 17:20 339968 C:\WINDOWS\stsystra.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-11-11 16:10 4583424]
"Zboard"="C:\Program Files\Ideazon\ZEngine\Zboard.exe" [2007-04-03 18:46 57344]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-13 10:43 185632]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 03:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"BMc7978b04"="C:\WINDOWS\system32\fvxsxhgs.dll" [ ]
"c4a4b898"="C:\WINDOWS\system32\qdvwcofl.dll" [ ]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-17 20:20 249896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhfg]
C:\WINDOWS\system32\jkhfg.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrsrsq]
rqrsrsq.dll 2007-09-24 11:30 23552 C:\WINDOWS\system32\rqrsrsq.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2007-03-05 16:36 140976 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll

R3 Alpham1;Ideazon Merc USB Human Interface Device;C:\WINDOWS\system32\DRIVERS\Alpham1.sys [2007-03-20 09:49]
R3 Alpham2;Ideazon Merc MM USB Human Interface Device;C:\WINDOWS\system32\DRIVERS\Alpham2.sys [2007-03-20 09:49]
R3 MusCDriverV32;MusCDriverV32;C:\WINDOWS\system32\drivers\MusCDriverV32.sys [2007-12-14 17:07]
R3 MusCVideo32;MusCVideo32;C:\WINDOWS\system32\DRIVERS\MusCVideo32.sys [2007-12-14 17:07]
S3 SoundMovieServer;SoundMovieServer;"C:\WINDOWS\system32\snmvtsvc.exe" [2007-12-14 17:06]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-13 06:37:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-18 10:06:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2008-02-18 10:08:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-18 18:08:27
.
2008-02-13 11:00:42 — E O F —
________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\BMc7978b04.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\mufbxaxk.ini
C:\WINDOWS\system32\asferrorv.dll
C:\WINDOWS\system32\appmgra.dll
C:\WINDOWS\system32\fvxsxhgs.dll
C:\WINDOWS\system32\rqrsrsq.dll
C:\WINDOWS\system32\jkhfg.dll



Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrsrsq]
[=HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhfg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"BMc7978b04"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"c4a4b898"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4c03732f-43bb-4d80-ba45-66fd05db11df}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97d2fddc-2c18-4c6c-bc60-9a832fbd7a21}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E99C690E-E103-42E6-A444-F1A258311F71}]



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.





______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).


_________________________________


Using Internet explorer (firefox will not work)
Please do an online scan with Kaspersky Online Scanner
Click accept on the first page.

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.



_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from Kasperskys
All instructions followed. :thumbup:
Heres my HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 20:03, on 2008-02-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Ideazon\ZEngine\Zboard.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\whatwhat\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BMc7978b04] Rundll32.exe "C:\WINDOWS\system32\fvxsxhgs.dll",s
O4 - HKLM\..\Run: [c4a4b898] rundll32.exe "C:\WINDOWS\system32\qdvwcofl.dll",b
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\AllMusicConverter\YouTubeRipper.dll
O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\AllMusicConverter\YouTubeRipper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O20 - Winlogon Notify: jkhfg - C:\WINDOWS\system32\jkhfg.dll (file missing)
O20 - Winlogon Notify: rqrsrsq - rqrsrsq.dll (file missing)
O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMovieServer - SoundMovieServer - C:\WINDOWS\system32\snmvtsvc.exe

And heres my Kaspersky Report:



KASPERSKY ONLINE SCANNER REPORT
2008-02-18 20:03
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 19/02/2008
Kaspersky Anti-Virus database records: 572657
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
Scan Statistics
Total number of scanned objects 87812
Number of viruses found 4
Number of infected objects 40
Number of suspicious objects 0
Duration of the scan process 01:28:12

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Application Data\Ideazon\ZEngine\data\mods\IDeazon.ldb Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Application Data\Ideazon\ZEngine\data\mods\IDeazon.zbd Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\cert8.db Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\flashgot.log Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\history.dat Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\key3.db Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\parent.lock Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Local Settings\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Local Settings\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Local Settings\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Local Settings\Application Data\Mozilla\Firefox\Profiles\t1pmo642.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Local Settings\Temp\JETA70D.tmp Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\My Documents\My Music\iTunes\iTunes Library.itl Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Emmanuel Montijo\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\gfpdvhlj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\hhdelobn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\lbwefskq.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mlqbwbwf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\oivutweg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\rqrsrsq.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aex skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\thjtsqvq.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vfcwvwju.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xtufpcai.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP208\A0016456.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018238.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018239.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018311.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018312.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018313.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018314.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018315.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018316.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018317.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018318.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018319.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018320.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018321.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018326.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018327.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018328.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018329.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018330.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018331.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018332.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018333.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018334.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018335.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018336.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018337.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018338.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018339.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018340.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018341.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018342.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018343.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018344.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018345.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018346.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018347.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018348.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018349.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018350.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018351.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018352.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018353.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018354.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018355.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018356.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018357.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018358.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018359.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018360.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018361.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018362.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018363.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018364.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018365.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018366.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018367.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018368.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018369.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018370.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018371.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018372.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018373.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018374.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018375.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018376.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018377.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018378.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018379.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018380.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018381.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018382.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018383.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018384.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP234\A0018387.dll Object is locked skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018407.dll Infected: Trojan-Downloader.Win32.Small.ddp skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018408.dll Infected: Trojan-Downloader.Win32.Small.ddp skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018409.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018410.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018411.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018412.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018413.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018414.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018415.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018416.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP235\A0018455.dll Infected: Trojan-Downloader.Win32.Small.ddp skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP236\A0018524.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aex skipped
C:\System Volume Information\_restore{1118AB6D-D758-48D6-97DB-1BB9D8F39D60}\RP236\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{A8646616-0A9E-45EE-8B83-DA0F726D3755}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\adsntv.dll Infected: Trojan-Downloader.Win32.Small.ddp skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\ckadsyfi.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\fffkvjva.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\ooqrlaws.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\WINDOWS\system32\rkiscddi.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Its acceptable, this job opportunity must get hairy :pullhair:

heres the combofix log:

ComboFix 08-02-18.1 - Emmanuel Montijo 2008-02-19 8:43:28.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-19 to 2008-02-19 )))))))))))))))))))))))))))))))
.

2008-02-18 17:20 . 2008-02-18 17:20 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-18 17:20 . 2008-02-18 17:20 d——– C:\WINDOWS\LastGood
2008-02-18 17:20 . 2008-02-18 17:20 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-18 17:12 . 2008-02-18 17:12 d——– C:\Program Files\CCleaner
2008-02-17 20:18 . 2008-02-17 20:18 d——– C:\Program Files\Avira
2008-02-17 20:18 . 2008-02-17 20:18 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-01-22 23:21 . 2008-02-18 10:05 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-22 23:21 . 2008-01-22 23:21 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-22 23:20 . 2008-01-22 23:20 d——– C:\Program Files\iTunes
2008-01-22 23:20 . 2008-01-22 23:20 d——– C:\Program Files\iPod
2008-01-22 15:56 . 2008-01-22 15:56 d——– C:\Program Files\Windows Media Connect 2
2008-01-22 15:55 . 2008-01-22 15:55 d——– C:\WINDOWS\system32\drivers\UMDF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-19 16:38 ——— d—–w C:\Documents and Settings\Emmanuel Montijo\Application Data\BitTorrent DNA
2008-02-19 04:03 ——— d—–w C:\Program Files\whatwhat
2008-02-18 22:29 ——— d—–w C:\Program Files\World of Warcraft
2008-01-24 02:20 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-23 07:19 ——— d—–w C:\Program Files\QuickTime
2008-01-11 04:45 ——— d—–w C:\Program Files\Common Files\AVSMedia
2008-01-11 04:44 ——— d—–w C:\Program Files\AVSMedia
2008-01-10 04:51 ——— d—–w C:\Documents and Settings\Emmanuel Montijo\Application Data\Sibelius Software
2008-01-10 04:49 ——— d—–w C:\Program Files\Musicnotes
2007-12-28 18:22 ——— d—–w C:\Program Files\Free CD Music Converter
2007-12-27 22:36 ——— d—–w C:\Documents and Settings\Emmanuel Montijo\Application Data\deskUNPDF
2007-12-27 22:34 ——— d—–w C:\Program Files\Docudesk
2007-12-17 05:47 4,346,084 —-a-w C:\WoW-2.3.0.7561-to-0.3.2.7627-enUS-patch.exe
2007-12-15 01:07 513,152 —-a-w C:\WINDOWS\system32\MusCDriverV32.sys
2007-12-15 01:07 3,768 —-a-w C:\WINDOWS\system32\MusCVideo32.sys
2007-12-15 01:07 10,552 —-a-w C:\WINDOWS\system32\MusCVideo32.dll
2007-12-15 01:06 184,320 —-a-w C:\WINDOWS\system32\snmvtsvc.exe
2007-12-07 00:44 666,112 —-a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
2007-11-24 05:59 22,016 —-a-w C:\WINDOWS\system32\6to4svcs.dll
2007-08-23 05:22 51,185,123 —-a-w C:\Documents and Settings\Emmanuel Montijo\WoW-2.1.3.6898-to-0.2.0.6932-enUS-patch.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 13:17 50736]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"BitTorrent DNA"="C:\Program Files\BitTorrent_DNA\dna.exe" [2007-10-11 22:55 286016]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56 64512]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 17:20 339968 C:\WINDOWS\stsystra.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-11-11 16:10 4583424]
"Zboard"="C:\Program Files\Ideazon\ZEngine\Zboard.exe" [2007-04-03 18:46 57344]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-13 10:43 185632]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 03:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"BMc7978b04"="C:\WINDOWS\system32\fvxsxhgs.dll" [ ]
"c4a4b898"="C:\WINDOWS\system32\qdvwcofl.dll" [ ]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-17 20:20 249896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhfg]
C:\WINDOWS\system32\jkhfg.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrsrsq]
rqrsrsq.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2007-03-05 16:36 140976 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll

R3 Alpham1;Ideazon Merc USB Human Interface Device;C:\WINDOWS\system32\DRIVERS\Alpham1.sys [2007-03-20 09:49]
R3 Alpham2;Ideazon Merc MM USB Human Interface Device;C:\WINDOWS\system32\DRIVERS\Alpham2.sys [2007-03-20 09:49]
R3 MusCDriverV32;MusCDriverV32;C:\WINDOWS\system32\drivers\MusCDriverV32.sys [2007-12-14 17:07]
R3 MusCVideo32;MusCVideo32;C:\WINDOWS\system32\DRIVERS\MusCVideo32.sys [2007-12-14 17:07]
S3 SoundMovieServer;SoundMovieServer;"C:\WINDOWS\system32\snmvtsvc.exe" [2007-12-14 17:06]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-13 06:37:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-19 08:46:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-19 8:47:18
ComboFix-quarantined-files.txt 2008-02-19 16:47:15
ComboFix2.txt 2008-02-19 01:12:03
ComboFix3.txt 2008-02-18 18:08:30
.
2008-02-13 11:00:42 — E O F —

Its acceptable, this job opportunity must get hairy :pullhair:


They just offered to double my pay also. I was excited until I remembered I volunteered. What's twice nothing ? :rofl:



The following programs have been damaged by this file infector and need to be uninstalled and reinstalled.

Yahoo!\Search Protection

BitComet


A word on Peer to peer programs
A majority of infected computers have some sort of file sharing program and is where many get infected.
It's not the program so much as it is the garbage that gets downloaded with them. Please do not use this program untll I have you all clean.
I would give some thought to not using such a program as it leaves you wide open for infections such as this one and much worse.






______________________________
RUN HJT

HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked




O4 - HKLM\..\Run: [BMc7978b04] Rundll32.exe "C:\WINDOWS\system32\fvxsxhgs.dll",s
O4 - HKLM\..\Run: [c4a4b898] rundll32.exe "C:\WINDOWS\system32\qdvwcofl.dll",b

O20 - Winlogon Notify: jkhfg - C:\WINDOWS\system32\jkhfg.dll (file missing)
O20 - Winlogon Notify: rqrsrsq - rqrsrsq.dll (file missing)


Close that.





________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\adsntv.dll
C:\WINDOWS\system32\ckadsyfi.dll
C:\WINDOWS\system32\fffkvjva.dll
C:\WINDOWS\system32\ooqrlaws.dll
C:\WINDOWS\system32\rkiscddi.dll



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.



______________________________________________________
We now suggest that you install the Windows Recovery Console.
The Windows recovery console will allow you to boot up into a special recovery mode that allows us to help you
in the case that your computer has a problem after an attempted removal of malware.

Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System

[external image: Posted Image]



Download the file & save it as it's originally named, next to ComboFix.exe.

[external image: Posted Image]

Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it.
Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.
When complete, a log named CF_RC.txt will open. Please post the contents of that log.

_________________________
In your next reply I would like to see:
  • A new HJT log
  • The1st report from ComboFix (ComboFix.txt)
  • The 2nd report from combofix (CF_RC.txt)
  • Let me know how thing seem to be running.
well things have really been running alot smoother at my end thanks alot for all your help

heres the new hjt log-
Logfile of HijackThis v1.99.1
Scan saved at 16:08, on 2008-02-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Ideazon\ZEngine\Zboard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\whatwhat\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\AllMusicConverter\YouTubeRipper.dll
O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\AllMusicConverter\YouTubeRipper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMovieServer - SoundMovieServer - C:\WINDOWS\system32\snmvtsvc.exe

1st ComboFix report-
ComboFix 08-02-18.1 - Emmanuel Montijo 2008-02-19 15:59:58.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.678 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Emmanuel Montijo\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\adsntv.dll
C:\WINDOWS\system32\ckadsyfi.dll
C:\WINDOWS\system32\fffkvjva.dll
C:\WINDOWS\system32\ooqrlaws.dll
C:\WINDOWS\system32\rkiscddi.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\adsntv.dll
C:\WINDOWS\system32\ckadsyfi.dll
C:\WINDOWS\system32\fffkvjva.dll
C:\WINDOWS\system32\ooqrlaws.dll
C:\WINDOWS\system32\rkiscddi.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-19 to 2008-02-19 )))))))))))))))))))))))))))))))
.

2008-02-18 17:20 . 2008-02-18 17:20 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-18 17:20 . 2008-02-18 17:20 d——– C:\WINDOWS\LastGood
2008-02-18 17:20 . 2008-02-18 17:20 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-18 17:12 . 2008-02-18 17:12 d——– C:\Program Files\CCleaner
2008-02-17 20:18 . 2008-02-17 20:18 d——– C:\Program Files\Avira
2008-02-17 20:18 . 2008-02-17 20:18 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-01-22 23:21 . 2008-02-18 10:05 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-22 23:21 . 2008-01-22 23:21 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-22 23:20 . 2008-01-22 23:20 d——– C:\Program Files\iTunes
2008-01-22 23:20 . 2008-01-22 23:20 d——– C:\Program Files\iPod
2008-01-22 15:56 . 2008-01-22 15:56 d——– C:\Program Files\Windows Media Connect 2
2008-01-22 15:55 . 2008-01-22 15:55 d——– C:\WINDOWS\system32\drivers\UMDF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-19 23:58 ——— d—–w C:\Documents and Settings\Emmanuel Montijo\Application Data\BitTorrent DNA
2008-02-19 23:56 ——— d—–w C:\Program Files\whatwhat
2008-02-19 23:55 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-18 22:29 ——— d—–w C:\Program Files\World of Warcraft
2008-01-24 02:20 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-23 07:19 ——— d—–w C:\Program Files\QuickTime
2008-01-11 04:45 ——— d—–w C:\Program Files\Common Files\AVSMedia
2008-01-11 04:44 ——— d—–w C:\Program Files\AVSMedia
2008-01-10 04:51 ——— d—–w C:\Documents and Settings\Emmanuel Montijo\Application Data\Sibelius Software
2008-01-10 04:49 ——— d—–w C:\Program Files\Musicnotes
2007-12-28 18:22 ——— d—–w C:\Program Files\Free CD Music Converter
2007-12-27 22:36 ——— d—–w C:\Documents and Settings\Emmanuel Montijo\Application Data\deskUNPDF
2007-12-27 22:34 ——— d—–w C:\Program Files\Docudesk
2007-12-17 05:47 4,346,084 —-a-w C:\WoW-2.3.0.7561-to-0.3.2.7627-enUS-patch.exe
2007-12-15 01:07 513,152 —-a-w C:\WINDOWS\system32\MusCDriverV32.sys
2007-12-15 01:07 3,768 —-a-w C:\WINDOWS\system32\MusCVideo32.sys
2007-12-15 01:07 10,552 —-a-w C:\WINDOWS\system32\MusCVideo32.dll
2007-12-15 01:06 184,320 —-a-w C:\WINDOWS\system32\snmvtsvc.exe
2007-12-07 00:44 666,112 —-a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
2007-11-24 05:59 22,016 —-a-w C:\WINDOWS\system32\6to4svcs.dll
2007-08-23 05:22 51,185,123 —-a-w C:\Documents and Settings\Emmanuel Montijo\WoW-2.1.3.6898-to-0.2.0.6932-enUS-patch.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 13:17 50736]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"BitTorrent DNA"="C:\Program Files\BitTorrent_DNA\dna.exe" [2007-10-11 22:55 286016]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56 64512]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 17:20 339968 C:\WINDOWS\stsystra.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-11-11 16:10 4583424]
"Zboard"="C:\Program Files\Ideazon\ZEngine\Zboard.exe" [2007-04-03 18:46 57344]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-13 10:43 185632]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 03:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-17 20:20 249896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2007-03-05 16:36 140976 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll

R3 Alpham1;Ideazon Merc USB Human Interface Device;C:\WINDOWS\system32\DRIVERS\Alpham1.sys [2007-03-20 09:49]
R3 Alpham2;Ideazon Merc MM USB Human Interface Device;C:\WINDOWS\system32\DRIVERS\Alpham2.sys [2007-03-20 09:49]
R3 MusCDriverV32;MusCDriverV32;C:\WINDOWS\system32\drivers\MusCDriverV32.sys [2007-12-14 17:07]
R3 MusCVideo32;MusCVideo32;C:\WINDOWS\system32\DRIVERS\MusCVideo32.sys [2007-12-14 17:07]
S3 SoundMovieServer;SoundMovieServer;"C:\WINDOWS\system32\snmvtsvc.exe" [2007-12-14 17:06]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-13 06:37:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-19 16:02:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-19 16:03:15
ComboFix-quarantined-files.txt 2008-02-20 00:03:13
ComboFix2.txt 2008-02-19 16:47:18
ComboFix3.txt 2008-02-19 01:12:03
ComboFix4.txt 2008-02-18 18:08:30
.
2008-02-13 11:00:42 — E O F —

2nd ComboFix report-

winxpsp1_en_hom_bf.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
Great news ! [external image: Posted Image]

Your log now appears to be clean.

Lets do a few things to tidy up.
Please do these in the order I suggest!


____________________________
Go to start > run and copy and paste this in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the
system/hidden files and resets System Restore again.

________________________________

Be sure to uninstall and reinstall those 2 programs.

Yahoo!\Search Protection

BitComet


______________________________




A few things to help with possible threats

These are optional . But will help protect you further.
___________________________________

SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Internet Explorer settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.


______________________________
SiteHound

http://www.firetrust.com/firetrustsitehound.html

This tool bar will help protect you from.

Over 4,000 fake bank and credit sites.
Tens of thousands of pornographic
and adult sites.
The never ending fake phishing sites.
Malicious sites, which can infect you
with spyware and adware if you visit
them.
Sites to download software which
may infect your computer with
spyware, a virus or adware


___________________________________
Download and Install a HOSTS File
A Hosts file is a plain text file which prevents your computer from connecting to malware and spyware sites by redirecting the connection request to 127.0.0.1, which is your local address. If you use a proxy server, or if you are on AOL, be sure to read the special instructions.
You can download the MVPS Hosts File and see a HOSTS file tutorial here :
This website also contains useful tips, and links to other resources and utilities.


___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.


Here's a site with great advise on how to AVOID malware. Much easier to do than removing it.


___________________________________
If your anything like me you should be mad these people have done this to you.
Please take the time to tell us what you would like to be done to these idiots!
We can only get something done about this if the people that we help, like you, are prepared to complain.
We have a dedicated forum for collecting these complaints Malware Complaints, you do not have to be registered to post.. just find your country room and register your complaint.

The infections you had was Vundo


Safe and Happy Surfing. :)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI