This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] vundo efcaax won't go away...

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hey all,

brand new here. need help removing this trojan.
i have trend micro and it is "unable to quarantine".
i looked at some other threads and tried the vundofix and it said i was clean.
i went in and tried to just delete it, but i can't do that either.
efcaaax.dll is what trend is telling me is the name.

i keep getting popups from trend saying that they have deleted a trojan and i "need to restart my computer" to make sure
its all gone. i tried that 5 times and it keeps coming back up.
it also has a popup that's titled "dangerous wesite, close internet exploreer immediately", and i havent opened anything plus
i use firefox.

any help would be greatly appreciated…

hijacklog….

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:25:11 PM, on 3/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15C9938F-CB96-496D-800A-B827F2E34EA1} - (no file)
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
O2 - BHO: (no name) - {A3E5D9F3-E915-4195-9E72-C9ED073AB9F6} - C:\WINDOWS\system32\ddcca.dll (file missing)
O2 - BHO: (no name) - {B1D321B8-EFA1-4B0B-A58E-F2F37D01BBD2} - C:\WINDOWS\system32\ssqrr.dll (file missing)
O2 - BHO: (no name) - {E9383002-FC55-4330-B9C9-67E03BC5C840} - C:\WINDOWS\system32\efcaaax.dll (file missing)
O2 - BHO: (no name) - {EE2C7F0D-1C9A-410B-8B84-732746266BD4} - C:\WINDOWS\system32\gebyw.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [pccguide.exe] C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~4\Office\1033\phdintl.dll/phdContext.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} - https://password.bellsouth.net/sdccommon/do…oad/tgctlsr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1187450554390
O20 - Winlogon Notify: efcaaax - efcaaax.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

–
End of file - 7310 bytes


thanks in advance!



just found a thread that said run HJT, system scan only and click the problems (efcaaax) and click FIX CHECKED.
so i did….
new HJT…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:43:59 PM, on 3/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15C9938F-CB96-496D-800A-B827F2E34EA1} - (no file)
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
O2 - BHO: (no name) - {A3E5D9F3-E915-4195-9E72-C9ED073AB9F6} - C:\WINDOWS\system32\ddcca.dll (file missing)
O2 - BHO: (no name) - {B1D321B8-EFA1-4B0B-A58E-F2F37D01BBD2} - C:\WINDOWS\system32\ssqrr.dll (file missing)
O2 - BHO: (no name) - {EE2C7F0D-1C9A-410B-8B84-732746266BD4} - C:\WINDOWS\system32\gebyw.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [pccguide.exe] C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~4\Office\1033\phdintl.dll/phdContext.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} - https://password.bellsouth.net/sdccommon/do…oad/tgctlsr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1187450554390
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

–
End of file - 7138 bytes

is there anything else in there i should remove/do??
thanks…
Hello cmd :),

I will be assisting you with your malware issues.
  • Whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.
  • Continue to respond to this thread until I give you the All Clean! If you have any question or you're stuck in there please reply it to me. I will try my best to help you!
  • Please bookmark or favourite this page. In case you need it as reference or etc.
IMPORTANT NOTE:
If you are using Windows Vista you must right click on the desktop icon and choose Run as Administrator all tools.
———————————————-
Remove MS Java
The Microsoft Java Virtual Machine, or MS Java VM, is used to run Java applets that can be found on web sites. When you visit a web site that has a Java applet, the MS JVM will compile and execute that applet on your machine. Microsoft no longer supports the MS JVM and it has become obsolete. There have also been known security issues with unpatched versions of the MS JVM and you should remove it and install the safer SUN JVM as an alternative (instructions follow).
Instructions on how to remove MS Java can be found here

If you have a problem following the above instructions you can use this tool to remove MSJava.
———————————————-
Update Java Runtime:

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 5.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Go to Java Runtime Environment (JRE) 6 Update 5 and click on Download button.
  • In Platform box choose Windows.
  • Check the box to Accept License Agreement and click Continue.
  • Click on Windows Offline Installation, click on the link under it which says "jre-6u4-windows-i586-p.exe" and save the downloaded file to your desktop.
  • Go to Start => Control Panel => Add or Remove Programs
  • Uninstall all old versions of Java (Java 3 Runtime Environment, JRE or JSE)
  • Reboot your computer
  • Delete the folder C:\Program Files\Java if present
  • Install the new version by running the newly-downloaded file with the java icon which will be at your desktop, and follow the on-screen instructions.
  • Reboot your computer
———————————————-
FIX HIJACKTHIS ENTRIES

Open up Hijackthis.
Click on do a system scan only.
Place a checkmark next to these lines(if still present).

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O2 - BHO: (no name) - {15C9938F-CB96-496D-800A-B827F2E34EA1} - (no file)
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
O2 - BHO: (no name) - {A3E5D9F3-E915-4195-9E72-C9ED073AB9F6} - C:\WINDOWS\system32\ddcca.dll (file missing)
O2 - BHO: (no name) - {B1D321B8-EFA1-4B0B-A58E-F2F37D01BBD2} - C:\WINDOWS\system32\ssqrr.dll (file missing)
O2 - BHO: (no name) - {EE2C7F0D-1C9A-410B-8B84-732746266BD4} - C:\WINDOWS\system32\gebyw.dll (file missing)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present << fix this if you didn't add these policies

Then close all windows except Hijackthis and click Fix Checked
Close HijackThis.
———————————————-
Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to and find the following FOLDER: if found, delete the following (some may not be present after previous steps):

C:\PROGRAM FILES\COMMON FILES\WinTools
———————————————-
Please download ATF cleaner
Make sure that all browser windows are closed.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
———————————————-
Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Post that log back here.
———————————————-
Run Kaspersky Online AV Scanner
Using Internet Explorer Go to http://www.kaspersky.com/kos/eng/partner/d…kavwebscan.html and click the Accept button at the end of the page.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded, click Next.
  • Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with a fresh HJT log and a description of how your PC is behaving.
———————————————-
Post back:
Malwarebytes' Anti-Malware Report.
Kaspersky Report.
A new Hijackthis log.
hey chryssi2001..

THANK you sooo much for all the help!!!

i did all you asked and had no real problems… (you really weren't lying about puttin the kettle on!)

so here's all the logs….

MALAWARES



Malwarebytes' Anti-Malware 1.09
Database version: 507

Scan type: Full Scan (A:\|C:\|D:\|E:\|)
Objects scanned: 140065
Time elapsed: 3 hour(s), 24 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 12
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{e9383002-fc55-4330-b9c9-67e03bc5c840} (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\SYSTEM32\_004866_.tmp.dll (Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\_004897_.tmp.dll (Dropped.Malware) -> Quarantined and deleted successfully.


Kasperskys: ( super long)

KASPERSKY ONLINE SCANNER REPORT
Thursday, March 20, 2008 11:19:13 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 20/03/2008
Kaspersky Anti-Virus database records: 644561
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 106108
Number of viruses found: 24
Number of infected objects: 117
Number of suspicious objects: 0
Duration of the scan process: 01:48:22

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\alethea ball\Local Settings\Temp\hsperfdata_alethea ball\2676 Object is locked skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/instGamehouse.exe Infected: not-a-virus:AdWare.Win32.Comet.ao skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/CSBand.dll Infected: not-a-virus:AdWare.Win32.Comet.x skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/csbho.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/cscore.dll Infected: not-a-virus:AdWare.Win32.Comet.b skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/csctx.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/cseng.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/csietb.dll Infected: not-a-virus:AdWare.Win32.Comet.ai skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/skinui.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/comet.exe Infected: not-a-virus:AdWare.Win32.Comet.c skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/csbrange.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/fileutil.dll Infected: not-a-virus:AdWare.Win32.Comet.o skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/csutil.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/csapputil.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/csinst.dll Infected: not-a-virus:AdWare.Win32.Comet.h skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/comutil.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/cstray.exe Infected: not-a-virus:AdWare.Win32.Comet.p skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/csres.dat Infected: not-a-virus:AdWare.Win32.Comet.au skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe/csadzap.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\swtbinst.exe CAB: infected - 18 skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\WToolsA.cab/WToolsA.exe Infected: not-a-virus:AdWare.Win32.Wintol.c skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\WToolsA.cab CAB: infected - 1 skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~11812.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~151444.tmp Object is locked skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~20492.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~36425.tmp Object is locked skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~462.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~470293.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~525066.tmp Object is locked skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~527278.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~538725.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~540551.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~542405.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~542495.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~547316.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~548948.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~553986.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~555877.tmp Infected: Trojan-Downloader.Win32.Wintool.d skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~556276.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~56691.tmp Infected: Trojan-Downloader.Win32.Wintool.d skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~574475.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~577223.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~579012.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~581591.tmp Object is locked skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~608731.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~619799.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~625114.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~656326.tmp Infected: Trojan-Downloader.Win32.Wintool.d skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~656561.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~677041.tmp Infected: Trojan-Downloader.Win32.Wintool.d skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~694456.tmp Infected: not-a-virus:AdWare.Win32.Wintol.i skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~708532.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~724630.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~725156.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~752661.tmp Object is locked skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~771005.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~777499.tmp Infected: not-a-virus:AdWare.Win32.Wintol.i skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~860928.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~89063.tmp Infected: not-a-virus:AdWare.Win32.Wintol.i skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~909299.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\alethea ball\Local Settings\Temp\~932738.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b4f9f0a51f6a84837e027d69f156170_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3b621f2f83d58bb21d8129014926bb9e_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped
C:\Documents and Settings\christy dikes\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\christy dikes\ntuser.dat Object is locked skipped
C:\Documents and Settings\christy dikes\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\itouch_crash_info.txt Object is locked skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/instGamehouse.exe Infected: not-a-virus:AdWare.Win32.Comet.ao skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/CSBand.dll Infected: not-a-virus:AdWare.Win32.Comet.x skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csbho.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/cscore.dll Infected: not-a-virus:AdWare.Win32.Comet.b skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csctx.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/cseng.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csietb.dll Infected: not-a-virus:AdWare.Win32.Comet.ai skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/skinui.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/comet.exe Infected: not-a-virus:AdWare.Win32.Comet.c skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csbrange.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/fileutil.dll Infected: not-a-virus:AdWare.Win32.Comet.o skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csutil.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csapputil.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csinst.dll Infected: not-a-virus:AdWare.Win32.Comet.h skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/comutil.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/cstray.exe Infected: not-a-virus:AdWare.Win32.Comet.p skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csres.dat Infected: not-a-virus:AdWare.Win32.Comet.au skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csadzap.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe WiseSFX: infected - 19 skipped
C:\Program Files\MahjongInstall-Starware.exe WiseSFXDropper: infected - 19 skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\162.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\163.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\17.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\18.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\19.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C0.tmp/data0006 Infected: Trojan-Downloader.Win32.VB.caw skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C0.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C0.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C1.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C1.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C1.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C4.tmp Infected: Trojan-Downloader.Win32.Agent.lbx skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C5.tmp Infected: Trojan-Downloader.Win32.Agent.lbx skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C7.tmp/data0006 Infected: Trojan-Downloader.Win32.VB.caw skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C7.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C7.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C8.tmp/data0006 Infected: Trojan-Downloader.Win32.VB.caw skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C8.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C8.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C9.tmp/data0006 Infected: Trojan-Downloader.Win32.VB.caw skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C9.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6C9.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6CA.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6CB.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6CC.tmp Infected: Trojan-Downloader.Win32.Small.swa skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6CD.tmp Infected: Trojan-Downloader.Win32.Small.swa skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6CE.tmp Infected: not-a-virus:Downloader.Win32.WinFixer.dz skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6CF.tmp Infected: not-a-virus:Downloader.Win32.WinFixer.dz skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6D7.tmp Infected: Trojan-Downloader.Win32.Agent.lbx skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6D8.tmp Infected: Trojan-Downloader.Win32.Agent.lbx skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\6DB.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped
C:\System Volume Information\catalog.wci\00010003.ci Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped
C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Conexant SmartHSFi V92 56K DF PCI Modem.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{06BE6A7E-8217-4CAB-905F-578A7F0EF164}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\zip1.tmp/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped
C:\WINDOWS\zip1.tmp ZIP: infected - 1 skipped
C:\WINDOWS\zip1.tmp MIME.Broken: infected - 1 skipped
C:\WINDOWS\zip2.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\WINDOWS\zip2.tmp ZIP: infected - 1 skipped
C:\WINDOWS\zip2.tmp MIME.Broken: infected - 1 skipped
C:\WINDOWS\zip3.tmp/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped
C:\WINDOWS\zip3.tmp ZIP: infected - 1 skipped
C:\WINDOWS\zip3.tmp MIME.Broken: infected - 1 skipped

Scan process completed.

new HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31:11 AM, on 3/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~2\PccGuide.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\LVComsX.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [pccguide.exe] C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~4\Office\1033\phdintl.dll/phdContext.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} - https://password.bellsouth.net/sdccommon/do…oad/tgctlsr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1187450554390
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

–
End of file - 6738 bytes


SO much to look at..

and my computer has been doing ok. no more popups from trend micro since i took out efcaax.dll.
but i did have a problem connecting to the internet via internet explorer for 10 minutes, but then it was fine. strange.
everything else is fine… so far…

THANK YOU!!!! :notworthy:
Hello cmd :) ,

Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to and find the following Folder:

C:\Documents and Settings\alethea ball\Local Settings\Temp

Right-Click on it and empty all it's contents.

Using the same way navigate to this folder and empty it's contents too:

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine
———————————————-
Please download the OTMoveIt2 by OldTimer and Save it to your Desktop.
  • Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN
    C:\WINDOWS\zip1.tmp
    C:\WINDOWS\zip2.tmp
    C:\WINDOWS\zip3.tmp
  • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
———————————————-
Update Adobe Reader
Recently there have been vunerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version. Adobe Reader 8.
You can download it from http://www.adobe.com/products/acrobat/readstep2.html
If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Adobe 8 is a large program and if you prefer a smaller program you can get Foxit 2.0 instead from http://www.foxitsoftware.com/pdf/rd_intro.php
———————————————-
Post back:
OTMoveIt2 report.
A new Hijackthis log.
Tell me how the pc behaves.
feeling a little stupid :blush: but i can't find

C:\Documents and Settings\alethea ball\Local Settings\Temp

when i go into C:\Documents and Settings\alethea ball , there is no "Local Settings"
there is "alethea ball's documents", "desktop", "favorites", "start menu",
"user data", and "windows"… i looked through all of these and no Local Settings or Temp.
theres a "temp" just under the C drive, but it's already empty….

what am i missing??

here's the OTMoveIt2 by OldTimer


File/Folder C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN not found.
C:\WINDOWS\zip1.tmp moved successfully.
C:\WINDOWS\zip2.tmp moved successfully.
C:\WINDOWS\zip3.tmp moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03202008_211811

the new HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:28:12 PM, on 3/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~2\PccGuide.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\LVComsX.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [pccguide.exe] C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1315614252-1712498625-2512854226-1008\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User 'alethea ball')
O4 - HKUS\S-1-5-21-1315614252-1712498625-2512854226-1008\..\Run: [Sonic RecordNow!] (User 'alethea ball')
O4 - HKUS\S-1-5-21-1315614252-1712498625-2512854226-1008\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'alethea ball')
O4 - HKUS\S-1-5-21-1315614252-1712498625-2512854226-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'alethea ball')
O4 - HKUS\S-1-5-21-1315614252-1712498625-2512854226-1008\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart (User 'alethea ball')
O4 - HKUS\S-1-5-21-1315614252-1712498625-2512854226-1008\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User 'alethea ball')
O4 - HKUS\S-1-5-21-1315614252-1712498625-2512854226-1008\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'alethea ball')
O4 - HKUS\S-1-5-21-1315614252-1712498625-2512854226-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'alethea ball')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~4\Office\1033\phdintl.dll/phdContext.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} - https://password.bellsouth.net/sdccommon/do…oad/tgctlsr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1187450554390
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

–
End of file - 8032 bytes

the computer is running fine still…
i did have this, though…

"PccVScan.exe encountered a problem and needs to close", etc…

i wasn't running anything and nothing really happened afterwards… but it
seems like that has happened a few times before i came to you for help… with different programs, though.
i wrote down what the programs were, but, of course, i can't find them now…
should i scour the apt for 'em?? :)

thanks!!!!!!
Hi cmd,

Set Your Computer to Show All Files
  • Click Start.
  • Click My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading, select Show hidden files and folders.
  • Uncheck Hide protected operating system files (recommended).
  • Click Yes to confirm.
  • Uncheck the Hide file extensions for known file types.
  • Click OK.
In addition, go to Start, Search.  When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom.
Make sure that 'Search system folders', 'Search hidden files and folders', and 'Search subfolders' are checked.
—————————————————-
Now try to find and empty this folder again:
C:\Documents and Settings\alethea ball\Local Settings\Temp

Let me know if you found it.
—————————————————-

"PccVScan.exe encountered a problem and needs to close", etc…


This file is related to your Trendmicro Internet security. I will make some more re-search about it to see if i can help you with it.
YAY!! i found it.

i forgot about the "hidden files' part…

so i set it to "show hidden files", etc.
and i got to the folder
C:\Documents and Settings\alethea ball\Local Settings\Temp

emptied most but a couple won't go.
they are…
file: ~DF5714.tmp when i try to delete this… "it is being used by another person or program" "try and close program"

folder : hsperfdata_alethea ball

in the above folder is a file "2676" when i try to delete this… it says "access denied" "make sure disk
is not full or wright-protected"

ALSO:
when i was trying to delete these, i left clicked, and attempted to "scan for virus" and my TrendMicro started to scan,
but then a popup box saying "scan failed" kept coming up and everytime i clicked ok, it would pop up again.
i had to CTRL-ALT-DELETE to get it to stop.

did this trojan screw up my trendmicro?? :huh:

thanks!!
Hello cmd,

The infected files in
C:\Documents and Settings\alethea ball\Local Settings\Temp were too many to list them here, so i preferred telling you to empty the whole Folder.

Which ever you can't remove let them there.

folder : hsperfdata_alethea ball

<< no infected files in this folder

"PccVScan.exe encountered a problem and needs to close"

Now regarding the problem you have with your Trendmicro Internet security i suggest you contact support of Trendmicro and they will help you.
http://esupport.trendmicro.com/support/sup…entral.do?id=m1

It might have a problem scanning certain files which are protected.
———————————————-
Now i would like you to re-run Kaspersky (I am sorry about that, i know it takes long) and post back the report.

You didn't update Adobe Reader as per my previous post, please do so.
———————————————-
Post back:
A new Kaspersky report.
A new HijackThis log, as you run it the first time. If you run it signed in as administrator please do so.
Do you run this pc as Administrator?
Who is the user alethea ball? You?
Hopefully your Kaspersky report will be clean this time. ;)
hey chryssi,

alethea is the other log in name we have on the computer, but we haven't used in a VERY long time.
we only use my log in, christy, which is the administrator.

i updated adobe, sorry about that…

and a new kaspersky report… not clean :(

i ran it before i emptied the recycle bin, so disregard all the "RECYCLE" files.




KASPERSKY ONLINE SCANNER REPORT
Saturday, March 22, 2008 12:20:57 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/03/2008
Kaspersky Anti-Virus database records: 654320
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 105707
Number of viruses found: 18
Number of infected objects: 86
Number of suspicious objects: 0
Duration of the scan process: 01:51:20

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\alethea ball\Local Settings\Temp\hsperfdata_alethea ball\2676 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b4f9f0a51f6a84837e027d69f156170_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3b621f2f83d58bb21d8129014926bb9e_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped
C:\Documents and Settings\christy dikes\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\History\History.IE5\MSHist012008032120080322\index.dat Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\christy dikes\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\christy dikes\ntuser.dat Object is locked skipped
C:\Documents and Settings\christy dikes\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\itouch_crash_info.txt Object is locked skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/instGamehouse.exe Infected: not-a-virus:AdWare.Win32.Comet.ao skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/CSBand.dll Infected: not-a-virus:AdWare.Win32.Comet.x skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csbho.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/cscore.dll Infected: not-a-virus:AdWare.Win32.Comet.b skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csctx.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/cseng.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csietb.dll Infected: not-a-virus:AdWare.Win32.Comet.ai skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/skinui.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/comet.exe Infected: not-a-virus:AdWare.Win32.Comet.c skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csbrange.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/fileutil.dll Infected: not-a-virus:AdWare.Win32.Comet.o skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csutil.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csapputil.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csinst.dll Infected: not-a-virus:AdWare.Win32.Comet.h skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/comutil.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/cstray.exe Infected: not-a-virus:AdWare.Win32.Comet.p skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csres.dat Infected: not-a-virus:AdWare.Win32.Comet.au skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN/csadzap.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe/WISE0045.BIN Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\Program Files\MahjongInstall-Starware.exe WiseSFX: infected - 19 skipped
C:\Program Files\MahjongInstall-Starware.exe WiseSFXDropper: infected - 19 skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc102.cab/WToolsA.exe Infected: not-a-virus:AdWare.Win32.Wintol.c skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc102.cab CAB: infected - 1 skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/instGamehouse.exe Infected: not-a-virus:AdWare.Win32.Comet.ao skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/CSBand.dll Infected: not-a-virus:AdWare.Win32.Comet.x skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/csbho.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/cscore.dll Infected: not-a-virus:AdWare.Win32.Comet.b skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/csctx.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/cseng.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/csietb.dll Infected: not-a-virus:AdWare.Win32.Comet.ai skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/skinui.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/comet.exe Infected: not-a-virus:AdWare.Win32.Comet.c skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/csbrange.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/fileutil.dll Infected: not-a-virus:AdWare.Win32.Comet.o skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/csutil.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/csapputil.dll Infected: not-a-virus:AdWare.Win32.Comet.q skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/csinst.dll Infected: not-a-virus:AdWare.Win32.Comet.h skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/comutil.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/cstray.exe Infected: not-a-virus:AdWare.Win32.Comet.p skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/csres.dat Infected: not-a-virus:AdWare.Win32.Comet.au skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe/csadzap.dll Infected: not-a-virus:AdWare.Win32.Comet.v skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe CAB: infected - 18 skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc453.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc454.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc455.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc456.tmp Infected: not-a-virus:AdWare.Win32.Wintol.i skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc457.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc458.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc459.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc460.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc461.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc462.tmp Infected: not-a-virus:AdWare.Win32.Wintol.i skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc463.tmp Infected: Trojan-Downloader.Win32.Wintool.d skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc464.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc465.tmp Infected: Trojan-Downloader.Win32.Wintool.d skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc466.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc467.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc468.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc513.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc514.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc515.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc516.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc517.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc518.tmp Infected: Trojan-Downloader.Win32.Wintool.d skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc519.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc520.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc521.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc522.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc523.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc524.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc525.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc526.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc527.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc528.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc529.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc530.tmp Infected: not-a-virus:AdWare.Win32.Wintol.i skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc531.tmp Infected: Trojan-Downloader.Win32.Wintool.d skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc532.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc533.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc534.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped
C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc535.tmp Infected: not-a-virus:AdWare.Win32.Wintol.j skipped


C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped
C:\System Volume Information\catalog.wci\00010003.ci Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped
C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Conexant SmartHSFi V92 56K DF PCI Modem.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{06BE6A7E-8217-4CAB-905F-578A7F0EF164}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\_OTMoveIt\MovedFiles\03202008_211811\WINDOWS\zip1.tmp/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped
C:\_OTMoveIt\MovedFiles\03202008_211811\WINDOWS\zip1.tmp ZIP: infected - 1 skipped
C:\_OTMoveIt\MovedFiles\03202008_211811\WINDOWS\zip1.tmp MIME.Broken: infected - 1 skipped
C:\_OTMoveIt\MovedFiles\03202008_211811\WINDOWS\zip2.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\_OTMoveIt\MovedFiles\03202008_211811\WINDOWS\zip2.tmp ZIP: infected - 1 skipped
C:\_OTMoveIt\MovedFiles\03202008_211811\WINDOWS\zip2.tmp MIME.Broken: infected - 1 skipped
C:\_OTMoveIt\MovedFiles\03202008_211811\WINDOWS\zip3.tmp/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped
C:\_OTMoveIt\MovedFiles\03202008_211811\WINDOWS\zip3.tmp ZIP: infected - 1 skipped
C:\_OTMoveIt\MovedFiles\03202008_211811\WINDOWS\zip3.tmp MIME.Broken: infected - 1 skipped

Scan process completed.



new HJT…


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:17:44 PM, on 3/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVComsX.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [pccguide.exe] C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~4\Office\1033\phdintl.dll/phdContext.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} - https://password.bellsouth.net/sdccommon/do…oad/tgctlsr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1187450554390
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

–
End of file - 7030 bytes

i'm gonna check on the TRENDMICRO after all this!! thanks for the link!!
Hello cmd,

i'm gonna check on the TRENDMICRO after all this!! thanks for the link!!

Yes you better do that! ;) You are welcome :)
———————————————-
Now Go to Start-Settings-Control Panel, click on Add remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.

MahjongInstall-Starware.exe
———————————————-
Let's use OTMoveIt2 again to remove all the infections shown in Kaspersky report, including the RECYCLER items if still there. Just to be on the safe side ;)

OTMoveIt2 by OldTimer
  • Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Program Files\MahjongInstall-Starware.exe 
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc102.cab
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc453.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc454.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc455.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc456.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc457.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc459.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc460.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc461.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc462.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc463.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc464.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc465.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc466.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc467.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc468.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc514.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc515.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc516.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc517.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc518.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc519.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc520.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc521.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc522.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc523.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc524.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc525.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc526.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc528.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc530.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc531.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc533.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc534.tmp
    C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc535.tmp
  • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
———————————————-
Post back:
OTMoveIt2 report .
C:\Program Files\MahjongInstall-Starware.exe moved successfully. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc102.cab not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc410.exe not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc453.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc454.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc455.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc456.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc457.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc459.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc460.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc461.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc462.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc463.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc464.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc465.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc466.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc467.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc468.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc514.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc515.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc516.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc517.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc518.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc519.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc520.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc521.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc522.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc523.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc524.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc525.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc526.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc528.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc530.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc531.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc533.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc534.tmp not found. File/Folder C:\RECYCLER\S-1-5-21-1315614252-1712498625-2512854226-1007\Dc535.tmp not found. OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03232008_120827 i didn't find the mahjong-install.exe when i looked under programs to add/remove, yet the OTMOVEIT found it and moved it. i don't understand that. i would love to just get rid of it. the rest of the files from the kaspersky report are ok? thanks!!!
Hello cmd,

i didn't find the mahjong-install.exe when i looked under programs to add/remove, yet the OTMOVEIT found it and moved it.
i don't understand that. i would love to just get rid of it.

Not sure about that, some programs do not show in Add/Remove Programs, we are lucky we have OTMoveIt2 to find them.;)

the rest of the files from the kaspersky report are ok?

Yes everything looks fine now :)
———————————————-
Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately.

Please download OTMoveIt2 and save it to desktop.
  • Double-click OTMoveIt2.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
———————————————-
Congratulations you are clean! :)
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Disable and Enable System Restore. - If you are using Windows XP or Vista then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide

or

Windows Vista System Restore Guide

Re-enable system restore with instructions from tutorial above.

Here are some free programs I recommend that could help you improve your computer's security.
(Vista users must ensure that any programs are Vista compatible BEFORE installing)

Spybot Search and Destroy 1.5.2
Download it from here. Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here
Find here changes from older version 1.4 here

Install SpyWare Blaster 4.0
Download it from here
Find here the tutorial on how to use Spyware Blaster here

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here

Install FireTrust SiteHound
You can find information and download it from here

Install MVPS Hosts File from here
The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer.
Find Tutorial here : http://www.mvps.org/winhelp2002/hosts.htm

Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
You can use one of these sites to check if any updates are needed for your pc.
Secunia Software Inspector
F-secure Health Check

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com

Please check out Tony Klein's article "How did I get infected in the first place?"

Read some information here how to prevent Malware.

Happy safe surfing!
Alright!! thanks so much for all your help!!! im glad i signed up here, it was much more of a mess than i thought. you're a computer saver!!! thanks again!! :notworthy:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI