This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virus ALert! in tray

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Gurus,

I also got this thing.. Ran Ad-Aware and Spybot - they found some stuff. Removed that and now ran HijackThis. There is the log for it:

Logfile of HijackThis v1.99.1
Scan saved at 09:52: VIRUS ALERT!, on 6/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\uptime software\uptime4\wrapper.exe
C:\PROGRA~1\UPTIME~1\uptime4\mysql\bin\mysqld-nt.exe
C:\Program Files\uptime software\uptime4\jre\bin\java.exe
C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe
C:\Program Files\Xobni\XobniService.exe
C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\uptime software\uptime4\agent\uptmagnt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Security Task Manager\TaskMan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Quest Software\SQL Navigator 5.5\SQLNav5.exe
C:\My Downloads\Net\hijackthis_sfx\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ecampus.emerson.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O1 - Hosts: 199.94.92.50 tds.erp.emerson.edu tds
O1 - Hosts: 199.94.92.51 pds1.erp.emerson.edu pds1
O1 - Hosts: 199.94.92.52 pds2.erp.emerson.edu pds2
O1 - Hosts: 199.94.92.53 tcas.erp.emerson.edu tcas
O1 - Hosts: 199.94.92.54 pcas1.erp.emerson.edu pcas1
O1 - Hosts: 199.94.92.55 pcas2.erp.emerson.edu pcas2
O1 - Hosts: 199.94.92.58 was.erp.emerson.edu was
O1 - Hosts: 199.94.67.31 mtds.emerson.edu mtds
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {085F4BDB-254B-407D-A985-C8E10C0438A0} - C:\WINDOWS\system32\pmnkHYOG.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: rtsplgob - {4564780C-A9CF-47BF-A268-BB081BB8EE9A} - C:\WINDOWS\rtsplgob.dll (file missing)
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnVir Virus Destroyer] "C:\Program Files\AnVir Virus Destroyer\AnVir.exe" Minimized
O4 - Global Startup: MyCabinet.lnk = C:\IT\MyCabinet.vbs
O4 - Global Startup: MyPages.lnk = C:\IT\MyPages.vbs
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://southwick.emerson.edu
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194294762656
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194294709828
O16 - DPF: {A6CE5E42-7491-43B0-A73C-7FB76F5FA9B6} (MAP Client Universal Launcher) - http://maps.erp.emerson.edu:8080/MapClientLaunch.cab
O16 - DPF: {CAFECAFE-0013-0001-0026-ABCDEFABCDEF} (JInitiator 1.3.1.26) -
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - http://rx.emerson.edu/emerson_test/webinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\Software\..\Telephony: DomainName = emerson.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = emerson.edu
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: qcom - {B8DBD265-42C3-43E6-B439-E968C71984C6} - C:\PROGRA~1\COMMON~1\QUESTS~1\CODEXP~1\qcom.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: fccBqrQJ - fccBqrQJ.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: rnopbfgt - {06EE104E-996E-4523-B1CA-35F775CFBB30} - C:\WINDOWS\rnopbfgt.dll (file missing)
O21 - SSODL: xkefqtgs - {9BBDA0EE-D8C5-47F5-BFAA-3657D7B6A918} - C:\WINDOWS\xkefqtgs.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BrlAPI - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: up.time 4 Data Collector - Unknown owner - C:\Program Files\uptime software\uptime4\wrapper.exe" -s wrapper.conf (file missing)
O23 - Service: up.time 4 Data Store - Unknown owner - C:\PROGRA~1\UPTIME~1\uptime4\mysql\bin\mysqld-nt.exe
O23 - Service: up.time agent - uptime software inc. - C:\Program Files\uptime software\uptime4\agent\uptmagnt.exe
O23 - Service: up.time 4 Web Server (up.time4WebServer) - Unknown owner - C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe" -k runservice (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe


Please, help me to get rid of it. This is my work desk-top and i'm an employee at huuge college, if this carp** will move ahead, I can loose my work :(

PS: I don't see my drive C: in My Computer tab in explorer.exe I have to type it manually in the address bar.. Not a big deal, but pretty annoyingly..

I appreciate any help beforehand!

Sincerely,
Maria.

Attachments:

Hi margur and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • I recommend you make a backup of any data that you have created, such as documents, pictures, music, ect… before we begin the fix.

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here. We also need you to post a new HijackThis log
Hello Dave,

Thank you SO MUCH for your work and time. I appreciate your help!!

I did all the suggested steps and here is the log file from SDFix that I ran in save mode (NOTE!: it DID NOT allow me to log in with my regular account to SAVE MODE. Only Administrator can do it in our company. So all SDFix fixing I ran as Administrator):

Here is the log:


SDFix: Version 1.193
Run by [removed] on Mon 06/16/2008 at 11:31 AM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value
Restoring Windows ProductId To Remove Fake Virus Alert

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\pebgkxwq.exe - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-16 11:50:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Documents and Settings\\maria_gurenich\\Local Settings\\Temp\\OraInstall2008-05-01_02-41-40PM\\jre\\1.4.2\\bin\\javaw.exe"="C:\\Documents and Settings\\maria_gurenich\\Local Settings\\Temp\\OraInstall2008-05-01_02-41-40PM\\jre\\1.4.2\\bin\\javaw.exe:*:Enabled:javaw"
"C:\\Documents and Settings\\maria_gurenich\\Local Settings\\Temp\\OraInstall2008-05-02_03-05-49PM\\jre\\1.4.2\\bin\\javaw.exe"="C:\\Documents and Settings\\maria_gurenich\\Local Settings\\Temp\\OraInstall2008-05-02_03-05-49PM\\jre\\1.4.2\\bin\\javaw.exe:*:Enabled:javaw"
"C:\\cygwin\\usr\\X11R6\\bin\\XWin.exe"="C:\\cygwin\\usr\\X11R6\\bin\\XWin.exe:*:Enabled:XWin"
"C:\\Program Files\\uptime software\\uptime4\\apache\\bin\\Apache.exe"="C:\\Program Files\\uptime software\\uptime4\\apache\\bin\\Apache.exe:*:Enabled:Apache HTTP Server"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Documents and Settings\\maria_gurenich\\Local Settings\\Temp\\OraInstall2008-05-29_11-56-52AM\\jre\\1.4.2\\bin\\javaw.exe"="C:\\Documents and Settings\\maria_gurenich\\Local Settings\\Temp\\OraInstall2008-05-29_11-56-52AM\\jre\\1.4.2\\bin\\javaw.exe:*:Enabled:javaw"
"C:\\OWB\\jdk\\jre\\bin\\javaw.exe"="C:\\OWB\\jdk\\jre\\bin\\javaw.exe:*:Enabled:javaw"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Mon 28 Jan 2008 1,404,240 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR — "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 7 Feb 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 5 May 2008 23,040 …H. — "C:\Documents and Settings\maria_gurenich\Application Data\Microsoft\Word\~WRL0797.tmp"
Tue 6 May 2008 22,528 …H. — "C:\Documents and Settings\maria_gurenich\Application Data\Microsoft\Word\~WRL2859.tmp"

Finished!

And here is the log from HJT:

O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnVir Virus Destroyer] "C:\Program Files\AnVir Virus Destroyer\AnVir.exe" Minimized
O4 - Global Startup: MyCabinet.lnk = C:\IT\MyCabinet.vbs
O4 - Global Startup: MyPages.lnk = C:\IT\MyPages.vbs
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://southwick.emerson.edu
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194294762656
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194294709828
O16 - DPF: {A6CE5E42-7491-43B0-A73C-7FB76F5FA9B6} (MAP Client Universal Launcher) - http://maps.erp.emerson.edu:8080/MapClientLaunch.cab
O16 - DPF: {CAFECAFE-0013-0001-0026-ABCDEFABCDEF} (JInitiator 1.3.1.26) -
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - http://rx.emerson.edu/emerson_test/webinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\Software\..\Telephony: DomainName = emerson.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = emerson.edu
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: qcom - {B8DBD265-42C3-43E6-B439-E968C71984C6} - C:\PROGRA~1\COMMON~1\QUESTS~1\CODEXP~1\qcom.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: fccBqrQJ - fccBqrQJ.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BrlAPI - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: up.time 4 Data Collector - Unknown owner - C:\Program Files\uptime software\uptime4\wrapper.exe" -s wrapper.conf (file missing)
O23 - Service: up.time 4 Data Store - Unknown owner - C:\PROGRA~1\UPTIME~1\uptime4\mysql\bin\mysqld-nt.exe
O23 - Service: up.time agent - uptime software inc. - C:\Program Files\uptime software\uptime4\agent\uptmagnt.exe
O23 - Service: up.time 4 Web Server (up.time4WebServer) - Unknown owner - C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe" -k runservice (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe


The VIRUS ALERT! msg is still in the tray and C: drive doesn't come up in explorer.exe

Thanks a LOT for help, guys. You are rock.
Logfile of HijackThis v1.99.1
Scan saved at 13:30, on 6/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\uptime software\uptime4\wrapper.exe
C:\PROGRA~1\UPTIME~1\uptime4\mysql\bin\mysqld-nt.exe
C:\Program Files\uptime software\uptime4\jre\bin\java.exe
C:\Program Files\uptime software\uptime4\agent\uptmagnt.exe
C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe
C:\Program Files\Xobni\XobniService.exe
C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AnVir Virus Destroyer\AnVir.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Security Task Manager\TaskMan.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Quest Software\SQL Navigator 5.5\SQLNav5.exe
C:\PROGRA~1\ULTRAE~1\uedit32.exe
C:\oracle\product\10.2.0\client_1\BIN\sqlplus.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\My Downloads\Net\putty.exe
\cabinet\nd$\PasswordSafe\pwsafe.exe
C:\My Downloads\Net\hijackthis_sfx\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ecampus.emerson.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O1 - Hosts: 199.94.92.50 tds.erp.emerson.edu tds
O1 - Hosts: 199.94.92.51 pds1.erp.emerson.edu pds1
O1 - Hosts: 199.94.92.52 pds2.erp.emerson.edu pds2
O1 - Hosts: 199.94.92.53 tcas.erp.emerson.edu tcas
O1 - Hosts: 199.94.92.54 pcas1.erp.emerson.edu pcas1
O1 - Hosts: 199.94.92.55 pcas2.erp.emerson.edu pcas2
O1 - Hosts: 199.94.92.58 was.erp.emerson.edu was
O1 - Hosts: 199.94.92.59 ods.erp.emerson.edu ods
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnVir Virus Destroyer] "C:\Program Files\AnVir Virus Destroyer\AnVir.exe" Minimized
O4 - Global Startup: MyCabinet.lnk = C:\IT\MyCabinet.vbs
O4 - Global Startup: MyPages.lnk = C:\IT\MyPages.vbs
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://southwick.emerson.edu
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194294762656
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194294709828
O16 - DPF: {A6CE5E42-7491-43B0-A73C-7FB76F5FA9B6} (MAP Client Universal Launcher) - http://maps.erp.emerson.edu:8080/MapClientLaunch.cab
O16 - DPF: {CAFECAFE-0013-0001-0026-ABCDEFABCDEF} (JInitiator 1.3.1.26) -
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - http://rx.emerson.edu/emerson_test/webinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\Software\..\Telephony: DomainName = emerson.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = emerson.edu
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: qcom - {B8DBD265-42C3-43E6-B439-E968C71984C6} - C:\PROGRA~1\COMMON~1\QUESTS~1\CODEXP~1\qcom.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: fccBqrQJ - fccBqrQJ.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BrlAPI - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: up.time 4 Data Collector - Unknown owner - C:\Program Files\uptime software\uptime4\wrapper.exe" -s wrapper.conf (file missing)
O23 - Service: up.time 4 Data Store - Unknown owner - C:\PROGRA~1\UPTIME~1\uptime4\mysql\bin\mysqld-nt.exe
O23 - Service: up.time agent - uptime software inc. - C:\Program Files\uptime software\uptime4\agent\uptmagnt.exe
O23 - Service: up.time 4 Web Server (up.time4WebServer) - Unknown owner - C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe" -k runservice (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe
Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
Hi Dave,

here is my ComboFix log file. Thanks a lot for helping me with that!!

ComboFix 08-06-15.4 - Maria_Gurenich 2008-06-16 18:09:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1049 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\elnb.exe
C:\WINDOWS\system32\GOYHknmp.ini
C:\WINDOWS\system32\GOYHknmp.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MUFhNXyb.ini
C:\WINDOWS\system32\MUFhNXyb.ini2
C:\WINDOWS\system32\vunrxyhq.ini
C:\WINDOWS\system32\xevohyld.ini
C:\WINDOWS\system32\ybvcxegb.ini

—– BITS: Possible infected sites —–

hxxp://windowsupdate.emerson.edu
.
((((((((((((((((((((((((( Files Created from 2008-05-16 to 2008-06-16 )))))))))))))))))))))))))))))))
.

2008-06-16 13:53 . 2008-06-16 13:52 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-16 13:52 . 2008-06-16 13:55 d——– C:\Documents and Settings\maria_gurenich\.housecall6.6
2008-06-16 11:20 . 2008-06-16 11:20 d——– C:\WINDOWS\ERUNT
2008-06-16 11:08 . 2008-06-16 12:11 d——– C:\SDFix
2008-06-14 19:29 . 2008-06-14 19:29 d——– C:\Deckard
2008-06-14 18:24 . 2008-06-14 18:26 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-14 18:23 . 2008-06-14 18:23 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-14 17:15 . 2008-06-14 17:15 d——– C:\Program Files\Spybot - Search & Destroy
2008-06-14 17:15 . 2008-06-14 18:09 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-13 18:35 . 2008-06-14 17:21 d——– C:\Program Files\Security Task Manager
2008-06-13 18:35 . 2008-06-16 13:51 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-06-13 18:33 . 2008-06-13 18:33 d——– C:\Documents and Settings\maria_gurenich\Application Data\Uniblue
2008-06-13 18:09 . 2008-06-13 18:09 d——– C:\Program Files\Enigma Software Group
2008-06-13 17:00 . 2008-06-14 18:13 d——– C:\Program Files\Data Loader Trial Edition 3.0
2008-06-13 17:00 . 2000-05-22 20:28 608,448 –a—— C:\WINDOWS\system32\comctl32.ocx
2008-06-13 17:00 . 1998-06-24 00:00 244,024 –a—— C:\WINDOWS\system32\MSFLXGRD.OCX
2008-06-13 17:00 . 1999-12-07 02:30 184,592 –a—— C:\WINDOWS\system32\msadox.dll
2008-06-13 17:00 . 2000-05-22 01:00 140,488 –a—— C:\WINDOWS\system32\COMDLG32.OCX
2008-06-13 17:00 . 2004-08-03 22:21 61,440 –a—— C:\WINDOWS\system32\msado20.tlb
2008-06-11 17:30 . 2008-06-13 18:26 d——– C:\Program Files\AnVir Virus Destroyer
2008-06-11 00:03 . 2008-04-14 07:01 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 00:03 . 2008-04-14 07:01 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-10 13:33 . 2008-06-10 13:33 d——– C:\Documents and Settings\maria_gurenich\Application Data\Sonic
2008-06-10 13:33 . 2008-06-10 13:33 d——– C:\Documents and Settings\maria_gurenich\Application Data\Leadertech
2008-06-04 14:25 . 2008-06-04 16:48 d——– C:\FF
2008-06-03 16:01 . 2008-06-03 16:01 d——– C:\Documents and Settings\maria_gurenich\Application Data\ATI
2008-06-03 15:34 . 2008-06-03 15:34 d——– C:\Documents and Settings\sofia_belenky\Application Data\ATI
2008-06-03 15:34 . 2008-06-03 15:34 d——– C:\Documents and Settings\All Users\Application Data\ATI
2008-06-03 15:24 . 2008-06-03 15:24 d——– C:\Program Files\Common Files\ATI Technologies
2008-06-03 15:24 . 2007-10-16 21:05 593,920 –a—— C:\WINDOWS\system32\ati2sgag.exe
2008-06-03 15:23 . 2008-06-03 15:27 d——– C:\Program Files\ATI Technologies
2008-06-03 15:22 . 2008-06-03 15:22 d——– C:\AMD
2008-06-03 15:04 . 2008-06-03 15:04 d——– C:\Documents and Settings\sofia_belenky\Application Data\Windows Desktop Search
2008-06-03 15:04 . 2004-08-04 00:56 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-06-03 15:03 . 2007-02-07 14:12 d–hs—- C:\Documents and Settings\sofia_belenky\UserData
2008-06-03 15:03 . 2007-02-08 11:52 d——– C:\Documents and Settings\sofia_belenky\IT
2008-06-03 15:03 . 2008-06-03 16:01 d——– C:\Documents and Settings\sofia_belenky
2008-06-03 14:40 . 2008-06-03 14:40 d——– C:\Documents and Settings\maria_gurenich\Application Data\Evisions
2008-06-03 13:56 . 2008-06-04 09:38 d——– C:\WINDOWS\Downloaded Installations
2008-06-03 13:56 . 2008-06-04 09:38 d——– C:\Program Files\Inter-Tel
2008-06-03 13:56 . 2008-06-04 09:38 1,238,007 –a—— C:\Documents and Settings\maria_gurenich\setup.exe
2008-06-03 10:44 . 2008-06-03 10:44 d——– C:\Documents and Settings\maria_gurenich\Application Data\webex
2008-06-02 14:26 . 2008-06-02 14:26 202,314 –a—— C:\WINDOWS\system32\atasnt40.dll
2008-06-02 14:26 . 2008-06-02 14:26 51,304 –a—— C:\WINDOWS\system32\drivers\atnt40k.sys
2008-06-02 11:37 . 2008-06-04 14:25 d——– C:\OneShield
2008-05-29 11:57 . 2008-05-29 12:38 d——– C:\OWB
2008-05-23 16:53 . 2008-05-23 16:53 d——– C:\WINDOWS\Sun
2008-05-23 09:59 . 2008-05-23 09:59 d——– C:\Xobni
2008-05-22 14:27 . 2008-05-22 14:27 d——– C:\Program Files\DNA
2008-05-22 14:27 . 2008-05-22 14:27 d——– C:\Program Files\BitTorrent
2008-05-22 14:27 . 2008-06-13 17:53 d——– C:\Documents and Settings\maria_gurenich\Application Data\DNA
2008-05-22 14:27 . 2008-05-22 15:16 d——– C:\Documents and Settings\maria_gurenich\Application Data\BitTorrent
2008-05-21 18:27 . 2008-05-21 18:27 d——– C:\Program Files\Safari
2008-05-16 11:58 . 2008-05-16 11:58 12,632 –a—— C:\WINDOWS\system32\lsdelete.exe
2008-05-16 11:14 . 2008-05-16 11:14 1,409 –a—— C:\WINDOWS\QTFont.for
2008-05-16 11:13 . 2008-05-16 11:13 d——– C:\Program Files\iTunes
2008-05-16 11:13 . 2008-05-16 11:13 d——– C:\Program Files\iPod
2008-05-16 11:09 . 2008-05-16 11:10 d——– C:\Program Files\QuickTime
2008-05-16 11:05 . 2008-05-16 11:05 d——– C:\Program Files\Apple Software Update
2008-05-16 09:44 . 2008-06-10 14:26 d——– C:\linux_software

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-16 22:19 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-06-14 22:24 ——— d—–w C:\Program Files\Lavasoft
2008-06-03 19:25 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-03 17:19 ——— d—–w C:\Program Files\Xobni
2008-06-02 16:32 ——— d—–w C:\Program Files\Common Files\Adobe
2008-05-29 20:41 ——— d—–w C:\Program Files\Unlocker
2008-05-29 16:32 ——— d—–w C:\Documents and Settings\maria_gurenich\Application Data\Apple Computer
2008-05-29 15:34 ——— d—–w C:\Program Files\Google
2008-05-15 07:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-14 21:53 ——— d—–w C:\Program Files\Java
2008-05-14 21:52 ——— d—–w C:\Program Files\Common Files\Java
2008-05-14 18:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\{972128BA-D9A2-4DF8-B973-4E77550F50CB}
2008-05-14 15:42 ——— d—–w C:\Program Files\PremiumSoft
2008-05-14 15:08 ——— d—–w C:\Program Files\MySQL
2008-05-12 19:42 ——— d—–w C:\Program Files\uptime software
2008-05-12 14:16 ——— d—–w C:\Documents and Settings\maria_gurenich\Application Data\Windows Desktop Search
2008-05-12 14:14 ——— d—–w C:\Program Files\Evisions
2008-05-12 13:42 ——— d—–w C:\Program Files\Windows Desktop Search
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-05 15:52 ——— d—–w C:\Program Files\Microsoft Visual Studio .NET 2003
2008-05-05 13:34 ——— d—–w C:\Program Files\UltraEdit
2008-05-02 21:04 ——— d—–w C:\Documents and Settings\maria_gurenich\Application Data\IsolatedStorage
2008-05-02 20:10 ——— d—–w C:\Program Files\IrfanView
2008-05-02 19:04 ——— d—–w C:\Program Files\WinSCP3
2008-05-02 19:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2008-05-01 21:25 ——— d—–w C:\Program Files\Dell
2008-05-01 19:25 ——— d—–w C:\Documents and Settings\maria_gurenich\Application Data\Quest Software
2008-05-01 19:19 ——— d—–w C:\Program Files\MSXML 4.0
2008-05-01 19:19 ——— d—–w C:\Documents and Settings\maria_gurenich\Application Data\Software
2008-05-01 19:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Quest Software
2008-05-01 19:18 ——— d—–w C:\Program Files\Quest Software
2008-05-01 19:18 ——— d—–w C:\Program Files\Common Files\Quest Shared
2008-05-01 18:46 ——— d—–w C:\Program Files\Oracle
2008-04-30 15:24 ——— d—–w C:\Program Files\Microsoft Visual Studio 8
2008-04-30 15:20 ——— d—–w C:\Program Files\Microsoft SQL Server
2008-04-30 15:01 ——— d—–w C:\Program Files\Microsoft.NET
2008-04-30 14:59 ——— d—–w C:\Program Files\SQLXML 4.0
2008-04-30 14:59 ——— d—–w C:\Program Files\Microsoft Analysis Services
2008-04-30 14:54 ——— d—–w C:\Program Files\Common Files\Merge Modules
2008-04-30 14:11 ——— d—–w C:\Program Files\MSBuild
2008-04-30 14:11 ——— d—–w C:\Program Files\Microsoft Works
2008-04-29 15:20 15,648 —-a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 —-a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 —-a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2007-02-07 19:01 454,656 —-a-w C:\Program Files\putty.exe
2008-06-02 18:26 44,624 —-a-w C:\Program Files\mozilla firefox\plugins\atgpcdec.dll
2008-06-02 18:26 108,192 —-a-w C:\Program Files\mozilla firefox\plugins\atgpcext.dll
2008-06-02 18:26 93,856 —-a-w C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"AnVir Virus Destroyer"="C:\Program Files\AnVir Virus Destroyer\AnVir.exe" [2006-06-25 23:17 415744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 17:50 221184]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 20:26 52896]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 21:33 125168]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 13:19 15872]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-04 00:56 143360]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 17:48 479232]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
MyCabinet.lnk - C:\IT\MyCabinet.vbs [2007-02-08 11:40:34 1880]
MyPages.lnk - C:\IT\MyPages.vbs [2007-02-08 11:40:34 2624]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 15:40:46 118784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccBqrQJ]
fccBqrQJ.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 up.time 4 Data Collector;up.time 4 Data Collector;"C:\Program Files\uptime software\uptime4\wrapper.exe" -s wrapper.conf []
R2 up.time 4 Data Store;up.time 4 Data Store;C:\PROGRA~1\UPTIME~1\uptime4\mysql\bin\mysqld-nt.exe [2007-09-19 12:26]
R2 up.time agent;up.time agent;"C:\Program Files\uptime software\uptime4\agent\uptmagnt.exe" [2007-09-19 12:26]
R2 up.time4WebServer;up.time 4 Web Server;"C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe" -k runservice []
R2 XobniService;XobniService;"C:\Program Files\Xobni\XobniService.exe" [2008-05-29 12:09]
S3 BrlAPI;BrlAPI;C:\cygwin\bin\cygrunsrv.exe [2008-03-18 06:28]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c992770f-b69e-11db-b87a-806d6172696f}]
\Shell\AutoRun\command - D:\Setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-06-16 18:18:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-16 18:18:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\MySQL]
"ImagePath"="\"C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" –defaults-file=\"C:\Program Files\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll

PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\uptime software\uptime4\jre\bin\java.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Completion time: 2008-06-16 18:27:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-16 22:27:56

Pre-Run: 120,810,041,344 bytes free
Post-Run: 121,685,995,520 bytes free

226 — E O F — 2008-06-11 07:02:26
Hi Dave, I'm at home right now, but can say, that after ComboFix running, C:\ drive came back home. VIRUS ALERT! i disabled through control panel -> regions -> time settings.. I will post HJT log tomorrow. Thank you so much, Dave & crew. You made my job :-) Sincerely, M.
Hi Dave,

This is my HJT log after I ran ComboFix yesterday evening..

Logfile of HijackThis v1.99.1
Scan saved at 09:47, on 2008-06-17
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\uptime software\uptime4\wrapper.exe
C:\PROGRA~1\UPTIME~1\uptime4\mysql\bin\mysqld-nt.exe
C:\Program Files\uptime software\uptime4\jre\bin\java.exe
C:\Program Files\uptime software\uptime4\agent\uptmagnt.exe
C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe
C:\Program Files\Xobni\XobniService.exe
C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AnVir Virus Destroyer\AnVir.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Symantec AntiVirus\vpc32.exe
C:\Program Files\Quest Software\SQL Navigator 5.5\SQLNav5.exe
C:\oracle\product\10.2.0\client_1\BIN\sqlplus.exe
C:\WINDOWS\explorer.exe
C:\My Downloads\Net\hijackthis_sfx\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ecampus.emerson.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O1 - Hosts: 199.94.92.50 tds.erp.emerson.edu tds
O1 - Hosts: 199.94.92.51 pds1.erp.emerson.edu pds1
O1 - Hosts: 199.94.92.52 pds2.erp.emerson.edu pds2
O1 - Hosts: 199.94.92.53 tcas.erp.emerson.edu tcas
O1 - Hosts: 199.94.92.54 pcas1.erp.emerson.edu pcas1
O1 - Hosts: 199.94.92.55 pcas2.erp.emerson.edu pcas2
O1 - Hosts: 199.94.92.58 was.erp.emerson.edu was
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnVir Virus Destroyer] "C:\Program Files\AnVir Virus Destroyer\AnVir.exe" Minimized
O4 - Global Startup: MyCabinet.lnk = C:\IT\MyCabinet.vbs
O4 - Global Startup: MyPages.lnk = C:\IT\MyPages.vbs
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://southwick.emerson.edu
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194294762656
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194294709828
O16 - DPF: {A6CE5E42-7491-43B0-A73C-7FB76F5FA9B6} (MAP Client Universal Launcher) - http://maps.erp.emerson.edu:8080/MapClientLaunch.cab
O16 - DPF: {CAFECAFE-0013-0001-0026-ABCDEFABCDEF} (JInitiator 1.3.1.26) -
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - http://rx.emerson.edu/emerson_test/webinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\Software\..\Telephony: DomainName = emerson.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = emerson.edu
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = emerson.edu
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: qcom - {B8DBD265-42C3-43E6-B439-E968C71984C6} - C:\PROGRA~1\COMMON~1\QUESTS~1\CODEXP~1\qcom.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: fccBqrQJ - fccBqrQJ.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BrlAPI - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: up.time 4 Data Collector - Unknown owner - C:\Program Files\uptime software\uptime4\wrapper.exe" -s wrapper.conf (file missing)
O23 - Service: up.time 4 Data Store - Unknown owner - C:\PROGRA~1\UPTIME~1\uptime4\mysql\bin\mysqld-nt.exe
O23 - Service: up.time agent - uptime software inc. - C:\Program Files\uptime software\uptime4\agent\uptmagnt.exe
O23 - Service: up.time 4 Web Server (up.time4WebServer) - Unknown owner - C:\Program Files\uptime software\uptime4\apache\bin\Apache.exe" -k runservice (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe



Thanks a lot for help!
Maria
Hi,

Run HijackThis. Click Do a System Scan Only. Put a Check in the box on the left side on this:

O20 - Winlogon Notify: fccBqrQJ - fccBqrQJ.dll (file missing)

Then close all windows except HijackThis and press Fix checked.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a Hijackthis log.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Also post a new HJT log and let me know how it's running.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI