rajiv
Topic Starter
Hello everyone,
I am totally new to this and I have been having problems with my machine for a few days now since someone used a USB pen drive on my machine while I was away. I have been thinking of reloading Windows on my drives but thought I should give this a try once.
Also, I am afraid that the same infection might still persist if I try copying all my information and files onto any other media and reloading the same to my machine after reformatting my drives. Please help.
When I came back and booted up, Norton kept coming up with 2 consecutive warnings saying it was a Hacktool.Rootkit -
one was a randomly named *.dll file which it kept deleting
the other was consistently wincab.sys in c:\winNT\system32 which was also deleted.
Now, the warning popped-up only when I tried to open up the Drive Letters from My Computer.
Norton came up with the consecutive warnings and deleted them as usual.
Next time I try opening the Drive letter - again the warnings and deletion.
The wincab.sys error was constant while the name of the *.dll file kept changing.
The other thing that I noticed was that I was unable to view hidden files and folders. Everytime I checked it in folderoptions and applied the changes it would still be the same. The infection had blocked it completely.
Afterwards, I tried an online Trend housecall which I think stalled after checking and listing all the malware found.
I think it stalled because after cleaning it consecutively a few times it would never go to a 'Congratulations' screen which one might expect. Finally, I gave up on that and closed the browser. However, there was no mention of wincab.sys or Hacktool.Rootkit.
Afterwards, I removed Norton completely from the system and installed AVG.
Ran a scan and again there was no mention about wincab.sys or Hacktool.Rootkit.
However, the results were similar to the Trend Housecall results that the infection was win32/NSAnti.H
A few files were cleaned and most were moved to the Vault. Another thing I noticed in the list of infections was that
a there were many "Autorun.inf" files in each drive letter which came up.
A copy of the AVG Log is under -
"","","Virus identified Win32/NSAnti.H","C:\WINNT\System32\KAVO.EXE","3/6/2008 10:24:17 AM","KAVO.EXE","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\WINNT\system32\tavo.exe","3/6/2008 10:29:08 AM","tavo.exe","110.37 KB"
"","","Virus found Win32/NSAnti","C:\Documents and Settings\Rajiv\Local Settings\Temp\9.dll","3/6/2008 11:01:07 AM","9.dll","29.56 KB"
"","","Virus found Win32/NSAnti","C:\Documents and Settings\Rajiv\Local Settings\Temp\7z.dll","3/6/2008 11:01:07 AM","7z.dll","28.73 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109671.com","3/6/2008 11:01:07 AM","A0109671.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109712.com","3/6/2008 11:01:07 AM","A0109712.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109726.com","3/6/2008 11:01:07 AM","A0109726.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110003.com","3/6/2008 11:01:07 AM","A0110003.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110289.com","3/6/2008 11:01:07 AM","A0110289.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110304.com","3/6/2008 11:01:07 AM","A0110304.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110320.EXE","3/6/2008 11:01:07 AM","A0110320.EXE","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110321.exe","3/6/2008 11:01:07 AM","A0110321.exe","110.37 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109673.com","3/6/2008 11:01:07 AM","A0109673.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109714.com","3/6/2008 11:01:08 AM","A0109714.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109728.com","3/6/2008 11:01:08 AM","A0109728.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110005.com","3/6/2008 11:01:08 AM","A0110005.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110291.com","3/6/2008 11:01:08 AM","A0110291.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110306.com","3/6/2008 11:01:08 AM","A0110306.com","114.98 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109651.dll","3/6/2008 11:01:08 AM","A0109651.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109652.dll","3/6/2008 11:01:08 AM","A0109652.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109653.dll","3/6/2008 11:01:08 AM","A0109653.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109655.dll","3/6/2008 11:01:08 AM","A0109655.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109656.dll","3/6/2008 11:01:08 AM","A0109656.dll","83.5 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109675.com","3/6/2008 11:01:08 AM","A0109675.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109716.com","3/6/2008 11:01:08 AM","A0109716.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110007.com","3/6/2008 11:01:08 AM","A0110007.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110293.com","3/6/2008 11:01:08 AM","A0110293.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110308.com","3/6/2008 11:01:08 AM","A0110308.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109677.com","3/6/2008 11:01:08 AM","A0109677.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109718.com","3/6/2008 11:01:08 AM","A0109718.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109732.com","3/6/2008 11:01:08 AM","A0109732.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110009.com","3/6/2008 11:01:08 AM","A0110009.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110295.com","3/6/2008 11:01:08 AM","A0110295.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110310.com","3/6/2008 11:01:08 AM","A0110310.com","114.98 KB"
"","","Trojan horse Dialer.AKE","G:\WINDOWS\internt.exe","3/6/2008 11:01:08 AM","internt.exe","22.5 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109679.com","3/6/2008 11:01:08 AM","A0109679.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109720.com","3/6/2008 11:01:08 AM","A0109720.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109734.com","3/6/2008 11:01:08 AM","A0109734.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110297.com","3/6/2008 11:01:08 AM","A0110297.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110312.com","3/6/2008 11:01:08 AM","A0110312.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109722.com","3/6/2008 11:01:08 AM","A0109722.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109736.com","3/6/2008 11:01:08 AM","A0109736.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110013.com","3/6/2008 11:01:08 AM","A0110013.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110299.com","3/6/2008 11:01:08 AM","A0110299.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110314.com","3/6/2008 11:01:08 AM","A0110314.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109683.com","3/6/2008 11:01:08 AM","A0109683.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109738.com","3/6/2008 11:01:08 AM","A0109738.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110015.com","3/6/2008 11:01:08 AM","A0110015.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110301.com","3/6/2008 11:01:08 AM","A0110301.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110316.com","3/6/2008 11:01:08 AM","A0110316.com","114.98 KB"
That's my AVG log after the scan. Now, there is another problem.
Whenever I try accessing my drives through My Computer (Drive C:\ for example) there is a Windows pop-up saying :
"Choose the program you want to use to open this file
File C:\"
with a list of all programs underneath. Basically the drive letters are being treated as files i think.
Although, I am able to access the drives through the RUN option.
Now, I have to say that all this has been done with SYSTEM RESTORE on ON mode.
I did not shut it off fearing loss of important information due to the infection.
I think I have given the complete History. Hopefully it helps.
I am afraid to meddle with my machine any further in fear of losing my important files and emails all together.
Should I restore all the AVG files from the Vault to start with? Please advise how should I rid myself of this.
Here's my HijackThis Log:
Logfile of HijackThis v1.99.1
Scan saved at 11:30:05 AM, on 3/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\hkcmd.exe
C:\WINNT\RTHDCPL.EXE
C:\WINNT\ALCMTR.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINNT\system32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [kava] C:\WINNT\system32\kavo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Bluetooth.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{80058C66-6148-483F-8D99-4A1F1294F38A}: NameServer = 203.145.184.32 203.145.184.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINNT\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MMHTVMSFY - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\MMHTVMSFY.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: QATVIIGQQLS - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\QATVIIGQQLS.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SZYZQD - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\SZYZQD.exe
Regards
Rajiv
I am totally new to this and I have been having problems with my machine for a few days now since someone used a USB pen drive on my machine while I was away. I have been thinking of reloading Windows on my drives but thought I should give this a try once.
Also, I am afraid that the same infection might still persist if I try copying all my information and files onto any other media and reloading the same to my machine after reformatting my drives. Please help.
When I came back and booted up, Norton kept coming up with 2 consecutive warnings saying it was a Hacktool.Rootkit -
one was a randomly named *.dll file which it kept deleting
the other was consistently wincab.sys in c:\winNT\system32 which was also deleted.
Now, the warning popped-up only when I tried to open up the Drive Letters from My Computer.
Norton came up with the consecutive warnings and deleted them as usual.
Next time I try opening the Drive letter - again the warnings and deletion.
The wincab.sys error was constant while the name of the *.dll file kept changing.
The other thing that I noticed was that I was unable to view hidden files and folders. Everytime I checked it in folderoptions and applied the changes it would still be the same. The infection had blocked it completely.
Afterwards, I tried an online Trend housecall which I think stalled after checking and listing all the malware found.
I think it stalled because after cleaning it consecutively a few times it would never go to a 'Congratulations' screen which one might expect. Finally, I gave up on that and closed the browser. However, there was no mention of wincab.sys or Hacktool.Rootkit.
Afterwards, I removed Norton completely from the system and installed AVG.
Ran a scan and again there was no mention about wincab.sys or Hacktool.Rootkit.
However, the results were similar to the Trend Housecall results that the infection was win32/NSAnti.H
A few files were cleaned and most were moved to the Vault. Another thing I noticed in the list of infections was that
a there were many "Autorun.inf" files in each drive letter which came up.
A copy of the AVG Log is under -
"","","Virus identified Win32/NSAnti.H","C:\WINNT\System32\KAVO.EXE","3/6/2008 10:24:17 AM","KAVO.EXE","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\WINNT\system32\tavo.exe","3/6/2008 10:29:08 AM","tavo.exe","110.37 KB"
"","","Virus found Win32/NSAnti","C:\Documents and Settings\Rajiv\Local Settings\Temp\9.dll","3/6/2008 11:01:07 AM","9.dll","29.56 KB"
"","","Virus found Win32/NSAnti","C:\Documents and Settings\Rajiv\Local Settings\Temp\7z.dll","3/6/2008 11:01:07 AM","7z.dll","28.73 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109671.com","3/6/2008 11:01:07 AM","A0109671.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109712.com","3/6/2008 11:01:07 AM","A0109712.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109726.com","3/6/2008 11:01:07 AM","A0109726.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110003.com","3/6/2008 11:01:07 AM","A0110003.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110289.com","3/6/2008 11:01:07 AM","A0110289.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110304.com","3/6/2008 11:01:07 AM","A0110304.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110320.EXE","3/6/2008 11:01:07 AM","A0110320.EXE","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110321.exe","3/6/2008 11:01:07 AM","A0110321.exe","110.37 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109673.com","3/6/2008 11:01:07 AM","A0109673.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109714.com","3/6/2008 11:01:08 AM","A0109714.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109728.com","3/6/2008 11:01:08 AM","A0109728.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110005.com","3/6/2008 11:01:08 AM","A0110005.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110291.com","3/6/2008 11:01:08 AM","A0110291.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110306.com","3/6/2008 11:01:08 AM","A0110306.com","114.98 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109651.dll","3/6/2008 11:01:08 AM","A0109651.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109652.dll","3/6/2008 11:01:08 AM","A0109652.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109653.dll","3/6/2008 11:01:08 AM","A0109653.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109655.dll","3/6/2008 11:01:08 AM","A0109655.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109656.dll","3/6/2008 11:01:08 AM","A0109656.dll","83.5 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109675.com","3/6/2008 11:01:08 AM","A0109675.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109716.com","3/6/2008 11:01:08 AM","A0109716.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110007.com","3/6/2008 11:01:08 AM","A0110007.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110293.com","3/6/2008 11:01:08 AM","A0110293.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110308.com","3/6/2008 11:01:08 AM","A0110308.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109677.com","3/6/2008 11:01:08 AM","A0109677.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109718.com","3/6/2008 11:01:08 AM","A0109718.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109732.com","3/6/2008 11:01:08 AM","A0109732.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110009.com","3/6/2008 11:01:08 AM","A0110009.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110295.com","3/6/2008 11:01:08 AM","A0110295.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110310.com","3/6/2008 11:01:08 AM","A0110310.com","114.98 KB"
"","","Trojan horse Dialer.AKE","G:\WINDOWS\internt.exe","3/6/2008 11:01:08 AM","internt.exe","22.5 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109679.com","3/6/2008 11:01:08 AM","A0109679.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109720.com","3/6/2008 11:01:08 AM","A0109720.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109734.com","3/6/2008 11:01:08 AM","A0109734.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110297.com","3/6/2008 11:01:08 AM","A0110297.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110312.com","3/6/2008 11:01:08 AM","A0110312.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109722.com","3/6/2008 11:01:08 AM","A0109722.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109736.com","3/6/2008 11:01:08 AM","A0109736.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110013.com","3/6/2008 11:01:08 AM","A0110013.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110299.com","3/6/2008 11:01:08 AM","A0110299.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110314.com","3/6/2008 11:01:08 AM","A0110314.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109683.com","3/6/2008 11:01:08 AM","A0109683.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109738.com","3/6/2008 11:01:08 AM","A0109738.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110015.com","3/6/2008 11:01:08 AM","A0110015.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110301.com","3/6/2008 11:01:08 AM","A0110301.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110316.com","3/6/2008 11:01:08 AM","A0110316.com","114.98 KB"
That's my AVG log after the scan. Now, there is another problem.
Whenever I try accessing my drives through My Computer (Drive C:\ for example) there is a Windows pop-up saying :
"Choose the program you want to use to open this file
File C:\"
with a list of all programs underneath. Basically the drive letters are being treated as files i think.
Although, I am able to access the drives through the RUN option.
Now, I have to say that all this has been done with SYSTEM RESTORE on ON mode.
I did not shut it off fearing loss of important information due to the infection.
I think I have given the complete History. Hopefully it helps.
I am afraid to meddle with my machine any further in fear of losing my important files and emails all together.
Should I restore all the AVG files from the Vault to start with? Please advise how should I rid myself of this.
Here's my HijackThis Log:
Logfile of HijackThis v1.99.1
Scan saved at 11:30:05 AM, on 3/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\hkcmd.exe
C:\WINNT\RTHDCPL.EXE
C:\WINNT\ALCMTR.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINNT\system32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [kava] C:\WINNT\system32\kavo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Bluetooth.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{80058C66-6148-483F-8D99-4A1F1294F38A}: NameServer = 203.145.184.32 203.145.184.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINNT\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MMHTVMSFY - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\MMHTVMSFY.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: QATVIIGQQLS - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\QATVIIGQQLS.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SZYZQD - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\SZYZQD.exe
Regards
Rajiv