This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected - Need Help

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone,

I am totally new to this and I have been having problems with my machine for a few days now since someone used a USB pen drive on my machine while I was away. I have been thinking of reloading Windows on my drives but thought I should give this a try once.
Also, I am afraid that the same infection might still persist if I try copying all my information and files onto any other media and reloading the same to my machine after reformatting my drives. Please help.

When I came back and booted up, Norton kept coming up with 2 consecutive warnings saying it was a Hacktool.Rootkit -
one was a randomly named *.dll file which it kept deleting
the other was consistently wincab.sys in c:\winNT\system32 which was also deleted.

Now, the warning popped-up only when I tried to open up the Drive Letters from My Computer.
Norton came up with the consecutive warnings and deleted them as usual.
Next time I try opening the Drive letter - again the warnings and deletion.
The wincab.sys error was constant while the name of the *.dll file kept changing.

The other thing that I noticed was that I was unable to view hidden files and folders. Everytime I checked it in folderoptions and applied the changes it would still be the same. The infection had blocked it completely.

Afterwards, I tried an online Trend housecall which I think stalled after checking and listing all the malware found.
I think it stalled because after cleaning it consecutively a few times it would never go to a 'Congratulations' screen which one might expect. Finally, I gave up on that and closed the browser. However, there was no mention of wincab.sys or Hacktool.Rootkit.

Afterwards, I removed Norton completely from the system and installed AVG.
Ran a scan and again there was no mention about wincab.sys or Hacktool.Rootkit.
However, the results were similar to the Trend Housecall results that the infection was win32/NSAnti.H
A few files were cleaned and most were moved to the Vault. Another thing I noticed in the list of infections was that
a there were many "Autorun.inf" files in each drive letter which came up.

A copy of the AVG Log is under -

"","","Virus identified Win32/NSAnti.H","C:\WINNT\System32\KAVO.EXE","3/6/2008 10:24:17 AM","KAVO.EXE","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\WINNT\system32\tavo.exe","3/6/2008 10:29:08 AM","tavo.exe","110.37 KB"
"","","Virus found Win32/NSAnti","C:\Documents and Settings\Rajiv\Local Settings\Temp\9.dll","3/6/2008 11:01:07 AM","9.dll","29.56 KB"
"","","Virus found Win32/NSAnti","C:\Documents and Settings\Rajiv\Local Settings\Temp\7z.dll","3/6/2008 11:01:07 AM","7z.dll","28.73 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109671.com","3/6/2008 11:01:07 AM","A0109671.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109712.com","3/6/2008 11:01:07 AM","A0109712.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109726.com","3/6/2008 11:01:07 AM","A0109726.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110003.com","3/6/2008 11:01:07 AM","A0110003.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110289.com","3/6/2008 11:01:07 AM","A0110289.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110304.com","3/6/2008 11:01:07 AM","A0110304.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110320.EXE","3/6/2008 11:01:07 AM","A0110320.EXE","114.98 KB"
"","","Virus identified Win32/NSAnti.H","C:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110321.exe","3/6/2008 11:01:07 AM","A0110321.exe","110.37 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109673.com","3/6/2008 11:01:07 AM","A0109673.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109714.com","3/6/2008 11:01:08 AM","A0109714.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109728.com","3/6/2008 11:01:08 AM","A0109728.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110005.com","3/6/2008 11:01:08 AM","A0110005.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110291.com","3/6/2008 11:01:08 AM","A0110291.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","D:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110306.com","3/6/2008 11:01:08 AM","A0110306.com","114.98 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109651.dll","3/6/2008 11:01:08 AM","A0109651.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109652.dll","3/6/2008 11:01:08 AM","A0109652.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109653.dll","3/6/2008 11:01:08 AM","A0109653.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109655.dll","3/6/2008 11:01:08 AM","A0109655.dll","83.5 KB"
"","","Trojan horse Downloader.Agent.AEQ","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109656.dll","3/6/2008 11:01:08 AM","A0109656.dll","83.5 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109675.com","3/6/2008 11:01:08 AM","A0109675.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109716.com","3/6/2008 11:01:08 AM","A0109716.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110007.com","3/6/2008 11:01:08 AM","A0110007.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110293.com","3/6/2008 11:01:08 AM","A0110293.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","E:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110308.com","3/6/2008 11:01:08 AM","A0110308.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109677.com","3/6/2008 11:01:08 AM","A0109677.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109718.com","3/6/2008 11:01:08 AM","A0109718.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109732.com","3/6/2008 11:01:08 AM","A0109732.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110009.com","3/6/2008 11:01:08 AM","A0110009.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110295.com","3/6/2008 11:01:08 AM","A0110295.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","F:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110310.com","3/6/2008 11:01:08 AM","A0110310.com","114.98 KB"
"","","Trojan horse Dialer.AKE","G:\WINDOWS\internt.exe","3/6/2008 11:01:08 AM","internt.exe","22.5 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109679.com","3/6/2008 11:01:08 AM","A0109679.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109720.com","3/6/2008 11:01:08 AM","A0109720.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109734.com","3/6/2008 11:01:08 AM","A0109734.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110297.com","3/6/2008 11:01:08 AM","A0110297.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110312.com","3/6/2008 11:01:08 AM","A0110312.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109722.com","3/6/2008 11:01:08 AM","A0109722.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109736.com","3/6/2008 11:01:08 AM","A0109736.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110013.com","3/6/2008 11:01:08 AM","A0110013.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110299.com","3/6/2008 11:01:08 AM","A0110299.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","H:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110314.com","3/6/2008 11:01:08 AM","A0110314.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109683.com","3/6/2008 11:01:08 AM","A0109683.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109738.com","3/6/2008 11:01:08 AM","A0109738.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110015.com","3/6/2008 11:01:08 AM","A0110015.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110301.com","3/6/2008 11:01:08 AM","A0110301.com","114.98 KB"
"","","Virus identified Win32/NSAnti.H","I:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110316.com","3/6/2008 11:01:08 AM","A0110316.com","114.98 KB"

That's my AVG log after the scan. Now, there is another problem.
Whenever I try accessing my drives through My Computer (Drive C:\ for example) there is a Windows pop-up saying :
"Choose the program you want to use to open this file
File C:\"
with a list of all programs underneath. Basically the drive letters are being treated as files i think.
Although, I am able to access the drives through the RUN option.

Now, I have to say that all this has been done with SYSTEM RESTORE on ON mode.
I did not shut it off fearing loss of important information due to the infection.

I think I have given the complete History. Hopefully it helps.
I am afraid to meddle with my machine any further in fear of losing my important files and emails all together.
Should I restore all the AVG files from the Vault to start with? Please advise how should I rid myself of this.

Here's my HijackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 11:30:05 AM, on 3/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\hkcmd.exe
C:\WINNT\RTHDCPL.EXE
C:\WINNT\ALCMTR.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINNT\system32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [kava] C:\WINNT\system32\kavo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Bluetooth.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{80058C66-6148-483F-8D99-4A1F1294F38A}: NameServer = 203.145.184.32 203.145.184.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINNT\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MMHTVMSFY - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\MMHTVMSFY.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: QATVIIGQQLS - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\QATVIIGQQLS.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SZYZQD - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\SZYZQD.exe


Regards
Rajiv
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


If you already have Combofix, please delete that copy and download it again as it's being updated regularly.

Please download Combofix from Bleeping Computer.

If you can't download it from there, please try these 2 alternative sites:

Forospyware
Geeks to Go

  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.



In your next reply post:
Uninstall list
ComboFix.txt
New HijackThis log taken after the above scan has run
Hi Scotty,
Thank you for your reply and your help.

Here's the Uninstall List -

Adobe Flash Player 9 ActiveX
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 6.0.1
AutoCAD 2004
Autodesk Express Viewer
AVG 7.5
CardRd81
CCScore
CR2
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
essvcpt
Google Earth
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB888111
Hijackthis 1.99.1
HijackThis 1.99.1
HLPPDOCK
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB935448)
HP Customer Participation Program 8.0
HP Deskjet 8.0 Software
HP Image Zone 4.7
HP Imaging Device Functions 8.0
HP Photosmart Essential
HP Smart Web Printing 1.0
HP Software Update
HP Solution Center 8.0
HP Update
HPSSupply
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Adapters and Drivers
Java™ 6 Update 5
kgcbase
Kodak EasyShare software
KSU
LiveReg (Symantec Corporation)
LiveUpdate 1.80 (Symantec Corporation)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Premium
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Nero Suite
Nokia Connectivity Cable Driver
Nokia PC Suite
Norton WMI Update
Notifier
OfotoXMI
OTtBP
OTtBPSDK
QuickTime
Realtek High Definition Audio Driver
SafeCast Shared Components
SAMSUNG CDMA Modem Driver Set
SAMSUNG Mobile USB Modem ^^
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
SFR
SHASTA
SKIN0001
SKINXSDK
staticcr
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
VPRINTOL
WIDCOMM Bluetooth Software
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver
WIRELESS
XMLinst


Here's the Combofix Log -

ComboFix 08-03-05.3 - Rajiv 2008-03-06 19:26:45.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.244 [GMT 5.5:30]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\WINNT\system32\kavo0.dll
C:\WINNT\system32\kavo1.dll
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
G:\Autorun.inf
H:\Autorun.inf
I:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.

2008-03-06 10:24 . 2008-03-06 10:24 dr-h—– C:\$VAULT$.AVG
2008-03-06 10:20 . 2008-03-06 10:20 d——– C:\Documents and Settings\Rajiv\Application Data\AVG7
2008-03-06 10:19 . 2008-03-06 10:20 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-06 10:19 . 2008-03-06 10:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
2008-03-06 10:19 . 2008-03-06 10:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
2008-03-05 19:39 . 2008-03-05 19:37 102,664 –a—— C:\WINNT\system32\drivers\tmcomm.sys
2008-03-05 19:36 . 2008-03-05 19:36 d——– C:\Documents and Settings\Rajiv\.housecall6.6
2008-03-05 19:34 . 2008-03-05 19:34 d——– C:\WINNT\Sun
2008-03-05 19:34 . 2008-02-22 02:33 69,632 –a—— C:\WINNT\system32\javacpl.cpl
2008-03-05 19:33 . 2008-03-05 19:33 d——– C:\Program Files\Java
2008-03-05 19:27 . 2008-03-05 19:27 d——– C:\Program Files\Common Files\Java
2008-03-04 13:05 . 2008-03-04 13:05 81,408 -r-hs—- C:\WINNT\system32\tavo1.dll
2008-03-03 11:07 . 2008-03-06 10:15 81,408 -r-hs—- C:\WINNT\system32\tavo0.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-12 08:57 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\Symantec
2008-01-11 10:31 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\AdobeUM
2008-01-11 05:53 44,544 —-a-w C:\WINNT\system32\dllcache\pngfilt.dll
2008-01-10 16:33 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\Autodesk
2008-01-10 14:58 ——— d—–w C:\Documents and Settings\Guest\Application Data\HP
2008-01-10 14:44 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\HP
2007-12-19 23:01 347,136 —-a-w C:\WINNT\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 —-a-w C:\WINNT\system32\dllcache\mrxdav.sys
2007-12-08 05:21 3,592,192 ——w C:\WINNT\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ——w C:\WINNT\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ——w C:\WINNT\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ——w C:\WINNT\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ——w C:\WINNT\system32\dllcache\ieakui.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 21:54 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 16:28 68856]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-03 19:26 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINNT\system32\igfxtray.exe" [2005-02-08 23:06 155648]
"HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [2005-02-08 23:02 126976]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINNT\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-04-13 11:51 14156800 C:\WINNT\RTHDCPL.EXE]
"NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-11-23 16:13 77824]
"DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" [2004-08-24 13:30 986624]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE" [2004-08-17 16:04 148992]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-06 10:19 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 16:28 68856]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-06 10:19 219136]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56 65588]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52 53248]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-07 06:26:28 180224]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-10-09 01:16:54 610365]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=

R3 USB_RNDIS_51;USB Remote NDIS Device Driver;C:\WINNT\system32\DRIVERS\usb8023.sys [2004-08-03 17:34]
S3 MMHTVMSFY;MMHTVMSFY;C:\DOCUME~1\Rajiv\LOCALS~1\Temp\MMHTVMSFY.exe [2008-03-04 18:44]
S3 QATVIIGQQLS;QATVIIGQQLS;C:\DOCUME~1\Rajiv\LOCALS~1\Temp\QATVIIGQQLS.exe [2008-03-04 18:44]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINNT\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINNT\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINNT\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
S3 SZYZQD;SZYZQD;C:\DOCUME~1\Rajiv\LOCALS~1\Temp\SZYZQD.exe [2008-03-04 18:45]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{915e66f4-e776-11dc-b6d5-00085c59bee1}]
\Shell\AutoRun\command - J:\cfv90h.com
\Shell\explore\Command - J:\cfv90h.com
\Shell\open\Command - J:\cfv90h.com

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 19:29:44
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\wscntfy.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2008-03-06 19:31:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-06 14:01:06
.
2008-02-13 12:44:32 — E O F —



And here's the HijackThis Log after the scan -

Logfile of HijackThis v1.99.1
Scan saved at 19:38, on 2008-03-06
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\RTHDCPL.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINNT\explorer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Bluetooth.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINNT\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MMHTVMSFY - Unknown owner - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\MMHTVMSFY.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: QATVIIGQQLS - Unknown owner - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\QATVIIGQQLS.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SZYZQD - Unknown owner - C:\DOCUME~1\Rajiv\LOCALS~1\Temp\SZYZQD.exe (file missing)

Hope I did it right!!!

Regards
Rajiv
Hi

You can delete whatever is the AVG vault.

Step 1:
Download Flash_Disinfector from here and save it to your desktop.
Doubleclick on Flash_Disinfector.exe to run it and follow the prompts.
Wait until it has finished scanning and then exit the program.
The utility may ask you to insert your flash drive and/or other removable drives. This may include your mobile phone.
Please do so and allow the utility to clean up those drives as well.


Step 2:
Remember to disconnect from the Internet before carrying out the next instruction, and to save the following script before you do.


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

KillAll::
 
File::
C:\WINNT\system32\tavo1.dll
C:\WINNT\system32\tavo0.dll
C:\DOCUME~1\Rajiv\LOCALS~1\Temp\MMHTVMSFY.exe
C:\DOCUME~1\Rajiv\LOCALS~1\Temp\QATVIIGQQLS.exe
C:\DOCUME~1\Rajiv\LOCALS~1\Temp\SZYZQD.exe
J:\cfv90h.com

Driver::
MMHTVMSFY
QATVIIGQQLS
SZYZQD

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Step 3:
Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.

*Note* If you do not have Firefox or Opera, those options will be greyed out.


Step 4:
F-Secure Online Scan

Scan online using F-Secure Online Scanner Next Generation using Internet Explorer
http://support.f-secure.com/enu/home/ols3.shtml
Click on the link "F-Secure Online Scanner Next Generation".
You may receive an alert on the address bar at this point to install the ActiveX control.
Click on that alert and then Click Insall ActiveX component.
Read the license agreement and click "Accept".
Click "Full System Scan" to download the scanning components and begin scan and cleaning.
When done click "Show report" and copy/paste its contents into your next reply.

Step 5:
In your next reply post:
ComboFix.txt
F-Secure report
New HijackThis log taken after the above scans have run
Hi,
First of all ….. Oops … Somehow I missed the first line of your reply …. I emptied the Virus Vault only after completing all the scans … Is that a problem???)

I don't normally use any Flash drives on my machine nor any mobile devices. When I ran the Disinfector it gave me the prompt to plug them in and I clicked Esc. However, I think it ran the scan anyways, as I got a message that the scan was complete.

Here's the Combofix Log -

ComboFix 08-03-05.3 - Rajiv 2008-03-07 10:32:46.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.249 [GMT 5.5:30]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Rajiv\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\DOCUME~1\Rajiv\LOCALS~1\Temp\MMHTVMSFY.exe
C:\DOCUME~1\Rajiv\LOCALS~1\Temp\QATVIIGQQLS.exe
C:\DOCUME~1\Rajiv\LOCALS~1\Temp\SZYZQD.exe
C:\WINNT\system32\tavo0.dll
C:\WINNT\system32\tavo1.dll
J:\cfv90h.com
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\system32\tavo0.dll
C:\WINNT\system32\tavo1.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_MMHTVMSFY
——-\LEGACY_QATVIIGQQLS
——-\LEGACY_SZYZQD
——-\MMHTVMSFY
——-\QATVIIGQQLS
——-\SZYZQD


((((((((((((((((((((((((( Files Created from 2008-02-07 to 2008-03-07 )))))))))))))))))))))))))))))))
.

2008-03-06 10:24 . 2008-03-06 10:24 dr-h—– C:\$VAULT$.AVG
2008-03-06 10:20 . 2008-03-06 10:20 d——– C:\Documents and Settings\Rajiv\Application Data\AVG7
2008-03-06 10:19 . 2008-03-06 10:20 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-06 10:19 . 2008-03-06 10:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
2008-03-06 10:19 . 2008-03-06 10:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
2008-03-05 19:39 . 2008-03-05 19:37 102,664 –a—— C:\WINNT\system32\drivers\tmcomm.sys
2008-03-05 19:36 . 2008-03-05 19:36 d——– C:\Documents and Settings\Rajiv\.housecall6.6
2008-03-05 19:34 . 2008-03-05 19:34 d——– C:\WINNT\Sun
2008-03-05 19:34 . 2008-02-22 02:33 69,632 –a—— C:\WINNT\system32\javacpl.cpl
2008-03-05 19:33 . 2008-03-05 19:33 d——– C:\Program Files\Java
2008-03-05 19:27 . 2008-03-05 19:27 d——– C:\Program Files\Common Files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-12 08:57 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\Symantec
2008-01-11 10:31 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\AdobeUM
2008-01-11 05:53 44,544 —-a-w C:\WINNT\system32\dllcache\pngfilt.dll
2008-01-10 16:33 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\Autodesk
2008-01-10 14:58 ——— d—–w C:\Documents and Settings\Guest\Application Data\HP
2008-01-10 14:44 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\HP
2007-12-19 23:01 347,136 —-a-w C:\WINNT\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 —-a-w C:\WINNT\system32\dllcache\mrxdav.sys
2007-12-08 05:21 3,592,192 ——w C:\WINNT\system32\dllcache\mshtml.dll
.

((((((((((((((((((((((((((((( snapshot@2008-03-06_19.30.54.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2000-08-31 02:30:00 163,328 —-a-w C:\WINNT\erdnt\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 21:54 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 16:28 68856]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-03 19:26 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINNT\system32\igfxtray.exe" [2005-02-08 23:06 155648]
"HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [2005-02-08 23:02 126976]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINNT\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-04-13 11:51 14156800 C:\WINNT\RTHDCPL.EXE]
"NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-11-23 16:13 77824]
"DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" [2004-08-24 13:30 986624]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE" [2004-08-17 16:04 148992]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-06 10:19 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 16:28 68856]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-06 10:19 219136]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56 65588]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52 53248]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-07 06:26:28 180224]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-10-09 01:16:54 610365]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=

R3 USB_RNDIS_51;USB Remote NDIS Device Driver;C:\WINNT\system32\DRIVERS\usb8023.sys [2004-08-03 17:34]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINNT\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINNT\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINNT\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{915e66f4-e776-11dc-b6d5-00085c59bee1}]
\Shell\AutoRun\command - J:\cfv90h.com
\Shell\explore\Command - J:\cfv90h.com
\Shell\open\Command - J:\cfv90h.com

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-07 10:37:07
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\WINNT\system32\HPZipm12.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2008-03-07 10:38:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-07 05:08:32
ComboFix2.txt 2008-03-06 14:01:10
.
2008-02-13 12:44:32 — E O F —


Here's the F-Secure Online Scan Report -

Scanning Report
Friday, March 07, 2008 13:55:41 - 15:33:48
Computer name: WIPRO-CE776EF0C
Scanning type: Scan system for malware, rootkits
Target: C:\ D:\ E:\ F:\ G:\ H:\ I:\


——————————————————————————–

Result: 58 malware found
Trojan-PSW.Win32.OnLineGames.szb (virus)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP305\A0110407.INF (Renamed & Submitted)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110305.INF (Renamed & Submitted)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109727.INF (Renamed & Submitted)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110004.INF (Renamed & Submitted)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110290.INF (Renamed & Submitted)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109713.INF (Renamed & Submitted)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109672.INF (Renamed & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP305\A0110408.INF (Renamed & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110307.INF (Renamed & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109729.INF (Renamed & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110006.INF (Renamed & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110292.INF (Renamed & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109715.INF (Renamed & Submitted)
D:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109674.INF (Renamed & Submitted)
E:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP305\A0110409.INF (Renamed & Submitted)
E:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110309.INF (Renamed & Submitted)
E:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109731.INF (Renamed & Submitted)
E:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110008.INF (Renamed & Submitted)
E:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110294.INF (Renamed & Submitted)
E:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109717.INF (Renamed & Submitted)
E:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109676.INF (Renamed & Submitted)
F:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP305\A0110410.INF (Renamed & Submitted)
F:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110311.INF (Renamed & Submitted)
F:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109733.INF (Renamed & Submitted)
F:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110010.INF (Renamed & Submitted)
F:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110296.INF (Renamed & Submitted)
F:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109719.INF (Renamed & Submitted)
F:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109678.INF (Renamed & Submitted)
G:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP305\A0110411.INF (Renamed & Submitted)
G:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110313.INF (Renamed & Submitted)
G:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109735.INF (Renamed & Submitted)
G:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110012.INF (Renamed & Submitted)
G:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110298.INF (Renamed & Submitted)
G:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109721.INF (Renamed & Submitted)
G:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109680.INF (Renamed & Submitted)
H:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP305\A0110412.INF (Renamed & Submitted)
H:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110315.INF (Renamed & Submitted)
H:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109737.INF (Renamed & Submitted)
H:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110014.INF (Renamed & Submitted)
H:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110300.INF (Renamed & Submitted)
H:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109723.INF (Renamed & Submitted)
H:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109682.INF (Renamed & Submitted)
I:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP305\A0110413.INF (Renamed & Submitted)
I:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110317.INF (Renamed & Submitted)
I:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109739.INF (Renamed & Submitted)
I:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110016.INF (Renamed & Submitted)
I:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110302.INF (Renamed & Submitted)
I:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP302\A0109725.INF (Renamed & Submitted)
I:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109684.INF (Renamed & Submitted)
Virus.Win32.HLLW.VB.a (virus)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109741.EXE (Renamed & Submitted)
W32/Smalltroj.CZXR (virus)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP305\A0110405.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP305\A0110406.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109998.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0110284.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP301\A0109666.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP300\A0109589.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP300\A0109616.DLL
Worm.Win32.Muha.a (virus)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP303\A0109740.EXE (Renamed & Submitted)

——————————————————————————–

Statistics
Scanned:
Files: 54321
System: 3671
Not scanned: 7
Actions:
Disinfected: 0
Renamed: 51
Deleted: 0
None: 7
Submitted: 51
Files not scanned:
C:\PAGEFILE.SYS
C:\WINNT\SYSTEM32\CONFIG\SECURITY
C:\WINNT\SYSTEM32\CONFIG\SOFTWARE
C:\WINNT\SYSTEM32\CONFIG\SYSTEM
C:\WINNT\SYSTEM32\CONFIG\DEFAULT
C:\WINNT\SYSTEM32\CONFIG\SAM
G:\SYSTEM VOLUME INFORMATION\_RESTORE{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110322.EXE

——————————————————————————–

Options
Scanning engines:
F-Secure USS: 2.20.0
F-Secure Hydra: 2.6.7470, 2008-03-06
F-Secure AVP: 7.0.171, 2008-03-06
F-Secure Pegasus: 1.20.0, 2008-02-04
F-Secure Blacklight: 1.0.64
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
Use Advanced heuristics


And here's the HJT Log after the scan -

Logfile of HijackThis v1.99.1
Scan saved at 15:45, on 2008-03-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\RTHDCPL.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINNT\explorer.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Bluetooth.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{80058C66-6148-483F-8D99-4A1F1294F38A}: NameServer = 203.145.184.32 203.145.184.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINNT\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Regards
Rajiv
Hi

It wont have mattered when you emptied the vault. :thumbup:
I would advise your friend with the infected USB drive to get checked out too.


Remember to disconnect from the Internet before carrying out the next instruction, and to save the following script before you do.


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

KillAll::
 
File::
J:\cfv90h.com

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{915e66f4-e776-11dc-b6d5-00085c59bee1}]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe


Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Rajiv\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Post that log back here.

1 - Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: www.adobe.com/uk/products/acrobat/readstep2.html and download the latest version of Adobe Reader
OR, after uninstalling Adobe Reader, you could try installing Foxit Reader from >here<
Foxit Reader has fewer add-ons therefore loads more quickly.

In your next reply post:
MBAM report
ComboFix.txt
New HijackThis log taken after the above scan has run
Hi,
Thanks for your reply.
Here's the MBAM report -

Malwarebytes' Anti-Malware 1.07
Database version: 463

Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
Objects scanned: 91197
Time elapsed: 20 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Here's the Combofix Log -

ComboFix 08-03-05.3 - Rajiv 2008-03-07 19:52:58.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.247 [GMT 5.5:30]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Rajiv\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
J:\cfv90h.com
.

((((((((((((((((((((((((( Files Created from 2008-02-07 to 2008-03-07 )))))))))))))))))))))))))))))))
.

2008-03-07 13:30 . 2008-03-07 13:30 d——– C:\fsaua.data
2008-03-06 10:24 . 2008-03-06 10:24 dr-h—– C:\$VAULT$.AVG
2008-03-06 10:20 . 2008-03-06 10:20 d——– C:\Documents and Settings\Rajiv\Application Data\AVG7
2008-03-06 10:19 . 2008-03-06 10:20 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-06 10:19 . 2008-03-06 10:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
2008-03-06 10:19 . 2008-03-06 10:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
2008-03-05 19:39 . 2008-03-05 19:37 102,664 –a—— C:\WINNT\system32\drivers\tmcomm.sys
2008-03-05 19:36 . 2008-03-05 19:36 d——– C:\Documents and Settings\Rajiv\.housecall6.6
2008-03-05 19:34 . 2008-03-05 19:34 d——– C:\WINNT\Sun
2008-03-05 19:34 . 2008-02-22 02:33 69,632 –a—— C:\WINNT\system32\javacpl.cpl
2008-03-05 19:33 . 2008-03-05 19:33 d——– C:\Program Files\Java
2008-03-05 19:27 . 2008-03-05 19:27 d——– C:\Program Files\Common Files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-12 08:57 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\Symantec
2008-01-11 10:31 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\AdobeUM
2008-01-11 05:53 44,544 —-a-w C:\WINNT\system32\dllcache\pngfilt.dll
2008-01-10 16:33 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\Autodesk
2008-01-10 14:58 ——— d—–w C:\Documents and Settings\Guest\Application Data\HP
2008-01-10 14:44 ——— d—–w C:\Documents and Settings\Rajiv\Application Data\HP
2007-12-19 23:01 347,136 —-a-w C:\WINNT\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 —-a-w C:\WINNT\system32\dllcache\mrxdav.sys
2007-12-08 05:21 3,592,192 ——w C:\WINNT\system32\dllcache\mshtml.dll
.

((((((((((((((((((((((((((((( snapshot@2008-03-06_19.30.54.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-02-27 10:29:28 290,816 —-a-w C:\WINNT\Downloaded Program Files\auc_lib.dll
+ 2008-02-27 10:29:28 495,616 —-a-w C:\WINNT\Downloaded Program Files\daas_s.dll
+ 2008-02-27 10:30:12 262,144 —-a-w C:\WINNT\Downloaded Program Files\fscax.dll
+ 2008-02-27 10:29:16 588,392 —-a-w C:\WINNT\Downloaded Program Files\gatelauncher.exe
+ 2000-08-31 02:30:00 163,328 —-a-w C:\WINNT\erdnt\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 21:54 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 16:28 68856]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-03 19:26 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINNT\system32\igfxtray.exe" [2005-02-08 23:06 155648]
"HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [2005-02-08 23:02 126976]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINNT\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-04-13 11:51 14156800 C:\WINNT\RTHDCPL.EXE]
"NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-11-23 16:13 77824]
"DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" [2004-08-24 13:30 986624]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE" [2004-08-17 16:04 148992]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-06 10:19 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 16:28 68856]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-06 10:19 219136]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56 65588]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52 53248]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-07 06:26:28 180224]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-10-09 01:16:54 610365]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"E:\\Tally Data Backup\\Tally\\tally9.exe"=

R3 USB_RNDIS_51;USB Remote NDIS Device Driver;C:\WINNT\system32\DRIVERS\usb8023.sys [2004-08-03 17:34]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINNT\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINNT\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINNT\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-07 19:57:24
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\WINNT\system32\HPZipm12.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2008-03-07 19:59:04 - machine was rebooted [Rajiv]
ComboFix-quarantined-files.txt 2008-03-07 14:29:02
ComboFix3.txt 2008-03-06 14:01:10
ComboFix2.txt 2008-03-07 05:08:36
.
2008-02-13 12:44:32 — E O F —


And here's the HJT log after the above scans -

Logfile of HijackThis v1.99.1
Scan saved at 20:48, on 2008-03-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\hkcmd.exe
C:\WINNT\RTHDCPL.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Bluetooth.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{2EB0EC7E-ED18-455A-B539-F55B209F6893}: NameServer = 203.145.184.13,202.56.250.5
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINNT\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Regards
Rajiv
Hi

Go to http://virusscan.jotti.org
Copy the following line into the white textbox:
E:\Tally Data Backup\Tally\tally9.exe
Click Submit.
Please post the results of this scan to this thread.
Hi, gatelauncher.exe does not show up in C:\WINNT\Downloaded Program Files I checked 'Show hidden files and folders' and Unchecked 'Hide protected operating system files'. It does not show up. The only items that are there in C:\WINNT\Downloaded Program Files are - F-Secure Online Scanner 3.3 Java Runtime Environment 1.6.0 Shockwave Flash Object Ran an advanced file search to include all hidden and system folders. It still does not show up. Regards Rajiv
Ok

Congratulations, you appear to be malware free.


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.

    [external image: Posted Image]


Here are two free programs I recommend.

Spybot Search and Destroy
Download it from here . Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here


Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here


Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"

Here is some great information from experts in this field that will help you stay clean and safe online.
http://forum.malwareremoval.com/viewtopic.php?t=14

Follow this list and your potential for being infected again will reduce dramatically.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
Hi, Before I do that ….. My virus scanner ran automatically this morning and found a virus again. Here's the report "2008/03/10 11:30:22","General","Rajiv","Complete Test was started." "2008/03/10 12:02:12","Virus","Rajiv","In G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110322.exe was ""Dialer.AKE"" virus found." "2008/03/10 12:02:16","General","Rajiv","Complete Test ended. Found 1 infected files." "2008/03/10 12:02:17","Virus","Rajiv","G:\System Volume Information\_restore{7C58872A-5692-48C9-85C0-C70AEA212D5D}\RP304\A0110322.exe was cleaned." Do I still have an infection ??? Regards Rajiv
They are in the System Restore points. When you run the Combofix /u instruction, all the restore points will be flushed out and a new clean one created. :thumbup:
Hi, Followed the instructions …. It completed the task and I finally got a message that Combofix is uninstalled. I guess the problem is over. What do I do with all the software downloaded for the cleaning??? Will install Spybot and Winpatrol. Before you close the thread, a very big thanks to you for your time and guidance. Will come back to you in case something resurfaces. Regards Rajiv

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI