This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can't remove Conhook,virtumonde,adialer, etc...

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys! my first post on this forum,hope you can help.After scanning with Windows Defender,i get those malware back every time i do a complete scan.Now i have AVG(use to have Norton but just deleted it),Spybot and Hijackthis to help me remove those bad guys.

So i guess i have to post my hijack log..if there is anything else you need please tell me.

Logfile of HijackThis v1.99.1
Scan saved at 19:08:28, on 2008-03-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\REMYLE~1.REM\LOCALS~1\Temp\Rar$EX23.922\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_CA&c=64&bd=pavilion&pf=laptop
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
Hi novaprospect,

I'm sorry it's taken a while for you to get a response to your post, if you still need help please do as follows:

Please download the latest version of HijackThis from here:
http://downloads.malwareremoval.com/HJTInstall.exe

Once you have downloaded the new version, remove the old version via Start->Control Panel->Add/Remove Programs and then delete the old version from your Desktop or wherever it is located.
Then run the new version's installer HJTInstall.exe and follow the prompts.
After installing, HijackThis will open automatically but close it for now.


Download Deckard's System Scanner (DSS) to your Desktop (right-click the link, select Save Target As…, select your Desktop and press Save)
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply

Once complete, please post both DSS logs, you won't need to produce a new HijackThis log as DSS produces one for you.
Hi ans thanks for responding there you go,first one is main.txt second extra.txt.Waiting for your reply



Deckard's System Scanner v20071014.68
Run by [removed] on 2008-03-23 16:45:07
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 4 Restore Point(s) –
4: 2008-03-23 20:45:11 UTC - RP4 - Deckard's System Scanner Restore Point
3: 2008-03-21 16:31:02 UTC - RP3 - Software Distribution Service 3.0
2: 2008-03-20 01:03:35 UTC - RP2 - Supprimé Adobe Reader 7.0.5 - Français
1: 2008-03-19 20:15:12 UTC - RP1 - Point de vérification système


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as Remy Lebreux.exe) —————————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:24, on 2008-03-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Remy Lebreux.REMXHP\Bureau\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Remy Lebreux.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xporter; vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=FR_CA&c;=64&bd;=pavilion&pf;=laptop
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O24 - Desktop Component 1: (no name) - http://www.justin.tv/habstv

–
End of file - 8075 bytes

– File Associations ———————————————————–

.reg - regfile - shell\open\command - "regedit.exe" "%1"


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.2.0.3) - c:\windows\system32\drivers\aegisp.sys
Hi novaprospect,

Please download Suspicious File Packer to your Desktop.
  • Right-click sfp.zip, choose Extract All… and extract sfp.exe to your Desktop
  • Double-click sfp.exe to start the program
  • Copy and Paste the following file list into the text box of the program:

    C:\WINDOWS\cc_20080323_1639.reg
    C:\WINDOWS\cc_20080313_2132.reg
    C:\WINDOWS\cc_20080319_2054.reg
    C:\WINDOWS\cc_20080318_2227.reg
    C:\WINDOWS\cc_20080318_1814.reg
    C:\WINDOWS\cc_20080317_1145.reg
    C:\WINDOWS\cc_20080316_0956.reg
    C:\WINDOWS\cc_20080314_2242.reg
    C:\WINDOWS\cc_20080313_2131.reg

  • A file called requested-files[YYYY-MM-DD_MM_ss].cab will appear on your Desktop.
  • Now open this page in your browser
  • Press Browse and browse to the requested-files[YYYY-MM-DD_MM_ss].cab file on your Desktop, fill in the other fields as appropriate then press Send File

————————————————————————

Please open Start->Control Panel->Add/Remove Programs, look down the list for J2SE Runtime Environment 5.0 Update 6 and remove it. It is out of date and now a security risk, you can get the latest update (version 6 update 5) from here

Pokerstars has been reported as being malware-related so I strongly recommend you remove it.
To do so, find Pokerstars and select Remove

————————————————————————

Next, fix file associations with DSS:
  • Make sure DSS.exe is on your Desktop
  • Next press Start->Run, copy/paste the following command into the box and press OK:

    "%userprofile%\desktop\dss.exe" /daft

  • Press OK to the disclaimer(s) and then press Scan
  • Place checkmarks in all the boxes that appear and press Fix
  • Then close Deckard's System Scanner

————————————————————————

Temporarily disable Spybot's TeaTimer. This is a two step process.
First:
  • Right click Spybot in the System Tray (looks like a calendar with a padlock symbol)
  • Choose Exit Spybot S&D Resident
Second:
  • Open Spybot S&D
  • Click Mode, check Advanced Mode
  • Go To Left Panel, Click Tools, then also in left panel, click Resident
  • If your firewall raises a question, say OK
  • Uncheck the box labeled Resident TeaTimer and OK any prompts.
  • Use File, Exit to terminate Spybot.
  • Reboot your machine for the changes to take effect.

Temporarily disable Windows Defender:
  • Right-click on the Windows Defender icon in the system tray and select Open
  • Click on Tools from the top menu, then press Options
  • Scroll down to Real-time protection options, uncheck Use real-time protection and press Save
  • Close Windows Defender

————————————————————————

Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines:

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

————————————————————————

Then please do an online scan with Kaspersky:
Open Kaspersky Online Scanner in Internet Explorer using this link:
http://www.kaspersky.com/kos/eng/partner/d…kavwebscan.html
  • Click Accept and the web scanner will begin to load
  • If a yellow warning bar appears at the top of the browser, click it and choose Install ActiveX Control
  • You will be prompted to install an ActiveX component from Kaspersky, click Install
  • If you are prompted about another ActiveX control called Kaspersky Online Scanner GUI part then allow it to be installed also.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on Next and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save Report As… button, change Save as type: to Text file and save the file to your desktop as Kaspersky.txt
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

————————————————————————

Once complete, please post the Kaspersky report and a new HijackThis log.
Hi silver,

I think we'll never be able to thank you guys enough for the work you're doing.

Couple of things : I did not remove pokerstars and will not unless you say i have to.

I could not run DSS with the command you send to me ("%userprofile%\desktop\dss.exe" /daft) an error saying the path is not available appears.

And here is the Kaspersky report and the Hijackthis log:


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, March 24, 2008 9:00:05 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 24/03/2008
Kaspersky Anti-Virus database records: 656986
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 83070
Number of viruses found: 14
Number of infected objects: 106
Number of suspicious objects: 2
Duration of the scan process: 01:43:37

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-03112008-134433.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde66.zip/avp.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde66.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\01 Piste 1.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\02 Piste 2.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\03 Piste 3.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\04 Piste 4.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\05 Piste 5.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\06 Piste 6.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\07 Piste 7.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\08 Piste 8.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\09 Piste 9.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\10 Piste 10.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\11 Piste 11.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\12 Piste 12.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-48-28)\desktop.ini Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\01 Piste 1.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\02 Piste 2.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\03 Piste 3.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\04 Piste 4.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\05 Piste 5.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\06 Piste 6.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\07 Piste 7.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\08 Piste 8.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\09 Piste 9.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\10 Piste 10.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\11 Piste 11.wma Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\Album inconnu (2007-06-02 19-56-04)\desktop.ini Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\Artiste inconnu\desktop.ini Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\My Playlists\50.wpl Object is locked skipped
C:\Documents and Settings\remy lebreux\Bureau\BEST\My Playlists\Nouvelle sélection.wpl Object is locked skipped
C:\Documents and Settings\Remy Lebreux.REMXHP\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Remy Lebreux.REMXHP\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Remy Lebreux.REMXHP\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Remy Lebreux.REMXHP\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Remy Lebreux.REMXHP\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Remy Lebreux.REMXHP\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Remy Lebreux.REMXHP\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Remy Lebreux.REMXHP\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Program Files\Services en ligne\Vonage\Xtras\regxtra121.x32 Infected: Backdoor.Win32.RAdmin.ag skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004356.exe Infected: Backdoor.Win32.IRCBot.dd skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004357.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004358.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004359.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004360.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004361.exe Infected: P2P-Worm.Win32.Kapucen.b skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004362.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004363.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004364.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004365.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004366.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004367.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004368.exe Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004369.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004370.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004371.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004372.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004373.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004374.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004375.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004376.exe Infected: Trojan-Downloader.Win32.Alphabet.f skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004377.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004378.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004379.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004380.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004381.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004382.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004383.exe Infected: Trojan-Downloader.Win32.Tiny.eu skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004384.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004385.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004386.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004387.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004388.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004389.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004390.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004391.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004392.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004393.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004394.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004395.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004396.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004397.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004398.exe Infected: Trojan-PSW.Win32.Papras.cj skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004399.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004400.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004401.exe Infected: Trojan-Downloader.Win32.Alphabet.h skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004402.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004403.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004404.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004405.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004406.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004407.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004408.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004409.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004410.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004411.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004412.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004413.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004414.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004415.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004416.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004417.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004418.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004419.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004420.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004421.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004422.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004423.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004424.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004425.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004426.exe Infected: Trojan-PSW.Win32.Papras.cj skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004427.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004428.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004429.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004430.EXE Infected: Trojan-Downloader.Win32.Alphabet.h skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004431.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004432.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004433.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004434.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004435.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004436.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004437.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004438.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004439.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004440.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004441.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004442.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004443.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004444.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004445.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004446.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004447.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004448.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004449.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004450.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004451.dll Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004452.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004453.exe Infected: P2P-Worm.Win32.Kapucen.b skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004454.exe Infected: P2P-Worm.Win32.Kapucen.b skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004455.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004456.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004457.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004458.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004459.exe Infected: Trojan.Win32.Obfuscated.ev skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\A0004460.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{70329B0E-B6A8-45AA-8681-145DAE055B05}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{206D5C9A-566B-437B-A762-213EF381532E}\RP7\change.log Object is locked skipped

Scan process completed.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:08:38, on 2008-03-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_CA&c=64&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O24 - Desktop Component 1: (no name) - http://www.justin.tv/habstv

–
End of file - 8184 bytes
Hi novaprospect,

I could not run DSS with the command you send to me ("%userprofile%\desktop\dss.exe" /daft) an error saying the path is not available appears.

That's because my instructions were not correct for your language settings - you don't have a Desktop, you have a Bureau :) please try this:

  • Make sure DSS.exe is on your Desktop
  • Next press Start->Run, copy/paste the following command into the box and press OK:

    "%userprofile%\bureau\dss.exe" /daft

  • Press OK to the disclaimer(s) and then press Scan
  • Place checkmarks in all the boxes that appear and press Fix
  • Then close Deckard's System Scanner

————————————————————————

There is one more program I would advise you to remove however it is only a recommendation and not malware:

You have LimeWire, a P2P file sharing program installed on your computer. This program does not come bundled with malware as some similar programs do, but peer-to-peer file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I recommend you remove it, but of course the choice is yours.
You can remove LimeWire 4.14.10 via Add/Remove Programs.

————————————————————————

Clean Spybots quarantined files:
Open Spybot - Search & Destroy
Select Recovery from the menu on the left side
Select the relevant item(s) and choose Purge selected items
Close Spybot - Search & Destroy

————————————————————————

This file has been flagged by Kaspersky as being a remote access application:

C:\Program Files\Services en ligne\Vonage\Xtras\regxtra121.x32

It appears to be a part of legitimate software from Vonage, however if you get alerts from your protection software and you do not use this program you may wish to remove it.

————————————————————————

Create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close

Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore press Clean up… and say Yes to the prompt
Press OK and Yes to confirm

————————————————————————

Once complete, please post another HijackThis log and let me know if you had any difficulties with the instructions.
Hi silver,

Sorry for the delai, and thanks again for helping me out.

This time i was able to do everything on it all went perfectly..well i hope ;)

Here is my hijackthis log :


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:42, on 2008-03-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\NETGEAR\WG111T\wlan111t.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_CA&c=64&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O24 - Desktop Component 1: (no name) - http://www.justin.tv/habstv

–
End of file - 8671 bytes
Hi novaprospect, Your log looks good, does Windows Defender still find malware on your machine? How is your machine running now?
Hi again silver,my friend Computer's working fine so far! Only thing that changed,when i reboot my computer ,they ask me for my password to login into windows now :huh: I didnt change anything regarding that,it's not a big deal..but do you have any clues? I didnt run windows defender yet..i wanted to respond to you right away,and it takes about an hour and a half to run a complete scan ;) I'm still gonna run windows defender after this post and tell you if i find anything.
Hi novaprospect,

You're most welcome :) I think your machine is now clean of malware, just a couple of things to do to finish up:

Please delete dss.exe from your Desktop, and also this folder:

C:\Deckard


Re-enable Windows Defender real-time protection:
  • Right-click on the Windows Defender icon in the system tray and select Open
  • Click on Tools from the top menu, then press Options
  • Scroll down to Real-time protection options, check Use real-time protection and press Save
  • Close Windows Defender

Re-enable Spybot's TeaTimer
  • Open Spybot S&D
  • Click Mode, check Advanced Mode
  • Go To Left Panel, Click Tools, then also in left panel, click Resident
  • If your firewall raises a question, say OK
  • Check the box labeled Resident TeaTimer and OK any prompts.
  • Use File, Exit to terminate Spybot.
  • Reboot your machine for the changes to take effect.


Here are some tips to help you keep your computer clean:

I recommend you install a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
Also: subscribe to the mailing list to get update notifications.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins or ActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
Allright, dss.exe is remove from desktop and folder Windows defender real-time protection enable Tea-timer enable WinPatrol has been installed. I'm gonna wait a bit to install MVPS HOSTS. Its really nice that my machine will be a lot more save from malware and stuff,but won't all those programs running (AVG,Windows defender,Spy S&D,WinPatrol and MVPS latter on..) will considerably slow down my computer?? It was one of my main goal to speed it up… :smack:
Hi novaprospect,

You are correct that the more protection programs you have running, the more impact there will be on performance. My recommendation would be as follows:

You should have real-time antivirus and antispyware protection, as well as some registry/autostart monitoring. This can be handled by AVG Antivirus, Windows Defender and WinPatrol. I would disable Tea Timer as you have adequate protection. If you have the paid-for version of AVG Antispyware then I would use it's real-time protection instead of Windows Defender.

The MVPS hosts file provides excellent protection and it does not 'run' so will not slow your computer down at all. I recommend you install it immediately, but do follow the instructions for disabling the DNS Client service before you do this.

You should also have some sort of firewall protection. Your DSS log shows Norton Internet Worm Protection is installed but disabled, however it doesn't look like it's actually present. If this is the case, you can clean up the old Norton installation by using the Norton Removal Tool. To do so, open this page:
http://service1.symantec.com/SUPPORT/tsgen…005033108162039
and follow the instructions for Download and run the Norton Removal Tool
You will download a tool and run it from your Desktop, this will clean up the Norton installation.

Even if you are behind a NAT router, I recommend you use firewall software as it will improve the security of your computer by monitoring and controlling outbound connections to the internet as well as inbound. There are various free packages available, one I can recommend is Comodo:
http://www.personalfirewall.comodo.com/
A tutorial on firewalls to help you get started:
http://www.bleepingcomputer.com/tutorials/tutorial60.html

I suggest you try this out and then see how your computer performs. If you have any questions or difficulties please let me know.
Hi silver! Ok, MVPS HOSTS file downloaded and installed correctly..(i think) i wasn't too sure about disabling the DNS Client.What i did is set it to manual,install the HOST file and i let it to manual,but before it was set to disable.It was disable because of an internet site explaining all the services that could be disable to speed up my machine.Tell me what you think about it.(disabling it) I used to Norton removal tool,so i should be clean of any traces of it. I am not behind not on a router ,so i guess staying with the windows firewall should be allright. Thanks :yeah:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI