my pc is infected. Here is the hijackthis log :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:45:30, on 03.04.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\mgmrwmrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\winlast.exe
C:\WINDOWS\system32\wnslogan.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Documents and Settings\Администратор\Local Settings\Application Data\cftmon.exe
C:\WINDOWS\system32\wind32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Администратор\Local Settings\Application Data\cftmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ru/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ссылки
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: NETWORK SERVICE - {3A4E6FF3-BF59-446E-9DC8-731BCE2F349A} - C:\WINDOWS\system32\msupdate.dll
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: C:\WINDOWS\system32\H4dj24g.dll - {B5AC49A2-94F2-42BD-F434-2604812C897D} - C:\WINDOWS\system32\H4dj24g.dll (file missing)
O2 - BHO: C:\WINDOWS\system32\Kf9467g.dll - {B5AF0562-94F3-42BD-F434-2604812C797D} - C:\WINDOWS\system32\Kf9467g.dll (file missing)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {F2F2A4CB-DAAD-4D0C-BDFC-E945647202C2} - c:\autoex.dll
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [advap32] "C:\WINDOWS\system32\bskl387.exe"/r
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\Администратор\Local Settings\Application Data\cftmon.exe
O4 - HKLM\..\Run: [windll] windll.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\wind32.exe
O4 - HKLM\..\Run: [Hhjg5jfd93dftdf] C:\WINDOWS\TEMP\winlogan.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Администратор\Local Settings\Application Data\cftmon.exe
O4 - HKCU\..\Run: [Hhjg5jfd93dftdf] C:\WINDOWS\TEMP\winlogan.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Hhjg5jfd93dftdf] C:\WINDOWS\TEMP\winlogan.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Jnskdfmf9eldfd] C:\WINDOWS\TEMP\csrssc.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{41E9DEB3-F8ED-4564-900F-2E5895CEC111}: NameServer = 139.7.30.125,139.7.30.126
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users\Документы\Settings\partnership.dll
O22 - SharedTaskScheduler: Hkjr94jdfdgj - {B5AC49A2-94F2-42BD-F434-2604812C897D} - C:\WINDOWS\system32\H4dj24g.dll (file missing)
O22 - SharedTaskScheduler: Hjkfj93dffd - {B5AF0562-94F3-42BD-F434-2604812C797D} - C:\WINDOWS\system32\Kf9467g.dll (file missing)
O23 - Service: Журнал событий (Eventlog) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Google Online Search Service - 2nd - Unknown owner - C:\WINDOWS\system32\winlast.exe
O23 - Service: Googles Onlines Search Services - Unknown owner - C:\WINDOWS\system32\wnslogan.exe
O23 - Service: Служба COM записи компакт-дисков IMAPI (ImapiService) - Корпорация Майкрософт - C:\WINDOWS\system32\imapi.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - Корпорация Майкрософт - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\mssrv32.exe
O23 - Service: Plug and Play (PlugPlay) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) - Корпорация Майкрософт - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Смарт-карты (SCardSvr) - Корпорация Майкрософт - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Планировщик заданий (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
O23 - Service: Журналы и оповещения производительности (SysmonLog) - Корпорация Майкрософт - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Теневое копирование тома (VSS) - Корпорация Майкрософт - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Адаптер производительности WMI (WmiApSrv) - Корпорация Майкрософт - C:\WINDOWS\system32\wbem\wmiapsrv.exe
--
End of file - 7106 bytes
For more info here is the log from McAfee( AccessProtectionLog ) :
03.04.2008 18:49:07 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:08 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:09 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:10 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:11 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:12 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:14 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:15 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:15 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:16 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:17 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:18 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:19 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:20 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:21 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:22 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:33 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:34 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:35 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:36 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:37 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:38 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:39 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:40 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:41 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:42 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:43 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffff0001-0002-101a-a3c9-08002b2f49fb}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:43 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{622cc208-b014-4fe0-801b-874a5e5e403a}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:43 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9c5b2f29-1f46-4639-a6b4-828942301d3e}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:43 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15651c7c-e812-44a2-a9ac-b467a2233e7d}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:44 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5dafd089-24b1-4c5e-bd42-8ca72550717b}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:44 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf021f40-3e14-23a5-cba2-717765728274}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:44 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8674aea0-9d3d-11d9-99dc-00600f9a01f1}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:44 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5929cd6e-2062-44a4-b2c5-2c7e78fbab38}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:44 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e1075f4-eec4-4a86-add7-cd5f52858c31}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:45 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e7bd74f-2b8d-469e-92c6-ce7eb590a94d}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:45 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fc3a74e5-f281-4f10-ae1e-733078684f3c}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:45 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000250-0320-4dd4-be4f-7566d2314352}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:45 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5fa6752a-c4a0-4222-88c2-928ae5ab4966}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:45 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{965a592f-8efa-4250-8630-7960230792f1}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:46 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{13197ace-6851-45c3-a7ff-c281324d5489}\@ Common Standard Protection:Prevent installation of Browser Helper Objects and Shell Extensions Action blocked : Create
03.04.2008 18:49:46 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
03.04.2008 18:49:46 Blocked by Access Protection rule GGGPC\Администратор C:\WINDOWS\system32\mgmrwmrv.exe \REGISTRY\USER\S-1-5-21-57989841-484763869-854245398-500\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr Anti-virus Standard Protection:Prevent registry editor and Task Manager from being disabled Action blocked : Create
I have copied the log files from the infected PC using a USB disk. After inserting the USB disk to the infected PC, i noticed that the *Trojan* has created two new files on the
USB disk :
First file autorun.inf , it contains the following:
Ycwvmpwl_
QjgnnGzgawvg?cwvmpwl,gzg
Second file autorun.exe , its size : 77,1 KB (79.039 Bytes)
Can you help me please to disinfect the PC?
Thanks in advance.