This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan.Vundo

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, i believe my computer is infected with the Trojan.Vundo virus. When my computer starts up I get two RunDLL errors as follows: Error loading C:\Windows\system32\zaniwimo.dll The Specified module could not be found. Error loading C:\windows\system32\nugedoka.dll The specified module could not be found. Also when the computer runs my symantec antivirus pops up and tells me that it keeps finding the threat Trojan.Vundo. This happens quite freaquently. I also get pop up adds while I am surfing on the internet. Here is my Hijackthis log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:22:21 AM, on 11/26/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\system32\VTtrayp.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\VIA\RAID\raid_tool.exe C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\userinit.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe C:\WINDOWS\system32\MsiExec.exe F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {542c1783-c53a-4a27-bc44-a6b17ef7518b} - C:\WINDOWS\system32\morogeti.dll (file missing) O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [HPWQTOOLBOX] C:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe "-i" O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [sanoteruhe] Rundll32.exe "C:\WINDOWS\system32\zaniwimo.dll",s O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [sanoteruhe] Rundll32.exe "C:\WINDOWS\system32\zaniwimo.dll",s (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sanoteruhe] Rundll32.exe "C:\WINDOWS\system32\zaniwimo.dll",s (User 'NETWORK SERVICE') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sjph.local O17 - HKLM\Software\..\Telephony: DomainName = sjph.local O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sjph.local O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sjph.local O20 - AppInit_DLLs: C:\WINDOWS\system32\newuyane.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Symantec Auto-upgrade Agent (Smcinst) - Unknown owner - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcLU\Setup\smcinst.exe (file missing) O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe – End of file - 4759 bytes Thank you for helping me out with this. Mitch
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Right click on the icon in the taskbar notification area & select "Disable Symantec EndPoint Protection".

[external image: Posted Image]

Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

I need to see another log from HijackThis.
  • Run Hijackthis.
  • Click on Open the Misc Tools section.
  • Next click on Open uninstall manager.
  • Press the Save list button.
  • Save the file to your desktop, with the default name of uninstall_list
  • Copy & Paste the entire contents of that file in your in your next post.
Thanks.
Hi jpshortstuff, thank you for responding so fast. Sorry for the delayed response on my end but the holidays held me up.

Here is everything that you requested.

I started off by running ATF cleaner. It freed up 171.934MBs.

Here is my combo fix log:

ComboFix 08-11-30.02 - nodonnell 2008-12-01 14:07:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.640 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\windows\system32\bezayedo.dll
c:\windows\system32\evuhemum.ini
c:\windows\system32\mumehuve.dll
c:\windows\system32\onaviror.ini

.
((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.

2008-11-26 10:41 . 2008-11-26 10:41 d——– C:\VundoFix Backups
2008-11-21 10:46 . 2008-11-21 10:46 d——– c:\documents and settings\Administrator\Application Data\Share-to-Web Upload Folder
2008-11-21 09:25 . 2008-11-21 09:25 d——– c:\program files\Trend Micro
2008-11-20 13:28 . 2008-11-20 13:28 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-20 13:28 . 2008-11-20 13:28 d——– c:\documents and settings\nodonnell\Application Data\Malwarebytes
2008-11-20 13:28 . 2008-11-20 13:28 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-20 13:28 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-20 13:28 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-18 10:38 . 2008-11-18 10:38 d——– c:\windows\system32\vim
2008-11-18 10:38 . 2008-11-18 10:38 d——– c:\windows\system32\ip
2008-11-18 10:38 . 2008-11-18 10:38 d——– c:\windows\system32\hdx
2008-11-18 10:38 . 2008-11-18 10:38 d——– c:\windows\system32\d
2008-11-18 10:38 . 2008-12-01 14:07 d——– C:\Temp
2008-11-13 14:35 . 2008-11-13 14:35 d——– c:\documents and settings\nodonnell\TOSHIBA
2008-11-06 13:01 . 2008-11-06 13:01 d——– c:\program files\Common Files\Nero
2008-11-06 13:00 . 2008-11-06 13:00 d——– c:\program files\Common Files\Ahead
2008-11-06 13:00 . 2008-11-06 13:00 d——– c:\program files\Ahead
2008-11-06 13:00 . 2004-07-26 17:16 1,568,768 ——— c:\windows\system32\ImagX7.dll
2008-11-06 13:00 . 2004-07-26 17:16 476,320 ——— c:\windows\system32\ImagXpr7.dll
2008-11-06 13:00 . 2004-07-26 17:16 471,040 ——— c:\windows\system32\ImagXRA7.dll
2008-11-06 13:00 . 2004-07-09 09:43 364,544 ——— c:\windows\system32\TwnLib4.dll
2008-11-06 13:00 . 2004-07-26 17:16 262,144 ——— c:\windows\system32\ImagXR7.dll
2008-11-06 13:00 . 2001-07-09 11:50 155,648 –a—— c:\windows\system32\NeroCheck.exe
2008-11-06 13:00 . 2000-06-26 11:45 106,496 –a—— c:\windows\system32\TwnLib20.dll
2008-11-06 12:57 . 2008-11-06 12:57 556 –a—— c:\windows\system32\mapisvc.inf
2008-11-06 12:57 . 2008-11-06 12:57 258 –a—— c:\windows\system32\BDEMERGE.INI
2008-11-06 12:56 . 2008-11-06 12:56 d——– c:\program files\Common Files\Borland Shared
2008-11-06 12:55 . 2008-11-06 12:56 d——– c:\program files\WordPerfect Office 11
2008-11-06 12:55 . 2008-11-06 12:56 d——– c:\program files\Common Files\Corel
2008-11-06 12:52 . 2004-08-03 22:58 15,104 –a—— c:\windows\system32\drivers\usbscan.sys
2008-11-06 12:52 . 2004-08-03 22:58 15,104 –a–c— c:\windows\system32\dllcache\usbscan.sys
2008-11-06 12:51 . 2008-11-06 12:51 d——– c:\program files\Common Files\Hewlett-Packard
2008-11-06 12:51 . 2008-11-06 12:51 d——– c:\documents and settings\nodonnell\Application Data\Share-to-Web Upload Folder
2008-11-06 12:50 . 2008-11-06 12:50 d——– C:\sj668
2008-11-06 11:20 . 2004-08-03 23:01 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-11-06 11:20 . 2004-08-03 23:01 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2008-11-06 11:19 . 2008-11-06 12:51 d——– c:\program files\Hewlett-Packard
2008-11-06 11:19 . 2005-06-02 17:26 102,400 –a—— c:\windows\scrub2k.exe
2008-11-06 11:19 . 2005-05-10 16:18 37,376 –a—— c:\windows\system32\hpz3l3xt.dll
2008-11-06 11:19 . 2005-06-02 17:26 397 –a—— c:\windows\hpw9800k.ini
2008-11-06 11:18 . 2008-11-06 11:20 2,803 –a—— c:\windows\mariner.his
2008-11-06 11:18 . 2008-11-06 11:20 1,467 –a—— c:\windows\mariner.ini
2008-11-06 11:18 . 2008-11-06 11:20 92 –a—— c:\windows\hpdj9800.ini
2008-11-06 11:18 . 2008-11-06 11:18 79 –a—— c:\windows\hpdj9800.his
2008-11-06 11:06 . 2006-03-06 15:29 152,624 –a—— c:\windows\system32\WIN2PDFS.DLL
2008-11-06 11:06 . 2006-03-19 15:15 15,360 –a—— c:\windows\system32\WIN2PDFM.DLL
2008-11-06 11:06 . 2008-12-01 10:24 2,559 –a—— c:\windows\1way.ini
2008-11-06 11:03 . 2007-07-24 16:25 62,608 –a—— c:\windows\eSTWFD.chm
2008-11-06 11:03 . 2007-07-24 16:16 62,221 –a—— c:\windows\eSTWLD.chm
2008-11-06 11:03 . 2000-06-27 15:05 1,078 –a—— c:\windows\Object Installerh.ico
2008-11-06 11:02 . 2008-11-06 11:02 d——– c:\program files\TOSHIBA
2008-11-06 11:02 . 2008-11-06 11:02 d——– c:\documents and settings\nodonnell\Application Data\InstallShield
2008-11-06 11:02 . 2007-06-04 10:35 286,720 –a—— c:\windows\system32\eSTsnmp.dll
2008-11-06 11:02 . 2008-11-06 11:02 286,720 –a—— c:\windows\eSTsnmp.dll
2008-11-06 11:02 . 2008-11-06 11:02 147,456 –a—— c:\windows\eSINLD.dll
2008-11-06 11:02 . 2008-11-06 11:02 24,576 –a—— c:\windows\SPortLG.dll
2008-11-06 11:02 . 2008-11-06 11:02 20,480 –a—— c:\windows\eSINLDLG.dll
2008-11-06 11:02 . 2008-11-06 11:02 17,505 –a—— c:\windows\K2_9.ini
2008-11-06 11:02 . 2008-11-06 11:02 1,110 –a—— c:\windows\V_eS3510c.ini
2008-11-06 10:59 . 2008-11-24 15:40 123,952 –a—— c:\windows\system32\drivers\SYMEVENT.SYS
2008-11-06 10:59 . 2008-11-24 15:40 60,800 –a—— c:\windows\system32\S32EVNT1.DLL
2008-11-06 10:59 . 2008-11-24 15:40 10,563 –a—— c:\windows\system32\drivers\SYMEVENT.CAT
2008-11-06 10:59 . 2008-11-24 15:40 805 –a—— c:\windows\system32\drivers\SYMEVENT.INF
2008-11-06 10:58 . 2008-11-24 15:40 d——– c:\program files\Symantec
2008-11-06 10:58 . 2008-11-24 15:41 d——– c:\program files\Common Files\Symantec Shared
2008-11-06 10:58 . 2008-11-24 15:41 d——– c:\documents and settings\All Users\Application Data\Symantec
2008-11-06 10:58 . 2007-03-21 20:39 1,060,864 –a—— c:\windows\system32\MFC71.DLL
2008-11-06 10:58 . 2007-03-21 20:33 503,808 –a—— c:\windows\system32\MSVCP71.DLL
2008-11-06 10:58 . 2007-03-21 20:33 348,160 –a—— c:\windows\system32\MSVCR71.DLL
2008-11-06 10:57 . 2008-11-06 10:57 d——– c:\program files\QuickTime
2008-11-06 10:57 . 2008-11-06 10:57 d——– c:\program files\Common Files\Apple
2008-11-06 10:57 . 2008-11-06 10:57 d——– c:\program files\Apple Software Update
2008-11-06 10:57 . 2008-11-06 10:57 d——– c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-06 10:57 . 2008-11-06 10:57 d——– c:\documents and settings\All Users\Application Data\Apple
2008-11-06 10:53 . 2008-11-06 10:53 d——– c:\program files\Common Files\Adobe AIR
2008-11-06 10:53 . 2008-11-06 10:53 d——– c:\program files\Common Files\Adobe
2008-11-06 10:51 . 2008-11-06 11:13 d——– c:\program files\NOS
2008-11-06 10:51 . 2008-11-06 11:13 d——– c:\documents and settings\All Users\Application Data\NOS
2008-11-06 10:47 . 2008-11-28 15:35 d——– C:\SISTERS
2008-11-06 09:51 . 2007-07-30 19:19 271,224 –a—— c:\windows\system32\mucltui.dll
2008-11-06 09:51 . 2007-07-30 19:19 207,736 –a—— c:\windows\system32\muweb.dll
2008-11-06 09:51 . 2007-07-30 19:19 30,072 –a—— c:\windows\system32\mucltui.dll.mui
2008-11-06 09:50 . 2008-11-06 09:50 d——– c:\windows\SchCache
2008-11-06 09:48 . 2008-11-25 17:01 d——– c:\documents and settings\nodonnell
2008-11-06 09:46 . 2008-11-06 09:46 d——– c:\windows\system32\CatRoot_bak
2008-11-06 09:43 . 2008-11-06 09:44 d–h—– c:\windows\$hf_mig$
2008-11-06 09:43 . 2005-02-24 22:35 22,752 –a—— c:\windows\system32\spupdsvc.exe
2008-11-06 09:39 . 2008-11-06 09:39 d——– c:\program files\MSBuild
2008-11-06 09:39 . 2008-11-06 09:39 d——– c:\program files\Microsoft Works
2008-11-06 09:37 . 2008-11-06 12:56 d——– c:\windows\SHELLNEW
2008-11-06 09:36 . 2008-11-06 09:36 dr-h—– C:\MSOCache
2008-11-06 09:36 . 2008-11-28 10:00 d——– c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-06 09:35 . 2004-08-03 23:08 26,496 –a–c— c:\windows\system32\dllcache\usbstor.sys
2008-11-06 09:34 . 2001-08-17 13:48 12,160 –a—— c:\windows\system32\drivers\mouhid.sys
2008-11-06 09:34 . 2001-08-17 13:48 12,160 –a–c— c:\windows\system32\dllcache\mouhid.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-06 17:56 ——— d—–w c:\program files\Common Files\InstallShield
2008-11-06 17:51 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-15 18:43 20,747 —-a-w c:\windows\system32\drivers\AegisP.sys
2008-10-15 18:43 ——— d—–w c:\program files\Hawking
2008-10-14 20:04 ——— d—–w c:\program files\VIA
2008-10-14 20:03 ——— d—–w c:\program files\Realtek AC97
2008-10-14 20:02 ——— d—–w c:\program files\AMD
2008-10-14 18:48 ——— d—–w c:\program files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [2005-04-21 589824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-11-24 115560]
"HPWQTOOLBOX"="c:\program files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe" [2005-06-03 335872]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"QuickFinder Scheduler"="c:\program files\WordPerfect Office 11\Programs\QFSCHD110.EXE" [2003-07-09 77887]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"VTTimer"="VTTimer.exe" [2005-03-07 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-01-11 c:\windows\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-01-11 c:\windows\soundman.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3716463455-1455960275-1856425994-1757\Scripts\Logon\0\0]
"Script"=sylinkdrop-sjph.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Deskjet 9800 Series\\Toolbox\\HPWQTBX.exe"=

S3 Smcinst;Symantec Auto-upgrade Agent;c:\program files\Symantec\Symantec Endpoint Protection\SmcLU\Setup\smcinst.exe []
.
- - - - ORPHANS REMOVED - - - -

BHO-{542c1783-c53a-4a27-bc44-a6b17ef7518b} - c:\windows\system32\morogeti.dll
HKLM-Run-sanoteruhe - c:\windows\system32\zaniwimo.dll
SafeBoot-Symantec Antvirus



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-01 14:12:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"="a"
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
c:\windows\system32\userinit.exe
.
**************************************************************************
.
Completion time: 2008-12-01 14:12:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-01 19:12:51

Pre-Run: 70,468,550,656 bytes free
Post-Run: 70,421,393,408 bytes free

198 — E O F — 2008-11-06 14:44:23

And last but not least here is the other HiJackThis log you requested:

Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9
Apple Software Update
Athlon 64 Processor Driver
Hawking Technologies HWPG1 Wireless-G PCI Card
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
HP Deskjet 9800
HP Deskjet 9800 Series
HP Precisionscan Pro 3.1
HP Share-to-Web
LiveUpdate 3.3 (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Nero Suite
QuickTime
Realtek AC'97 Audio
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB958644)
Symantec Endpoint Protection
TOSHIBA e-STUDIO3510c Series Client
Update for Windows XP (KB898461)
VIA Platform Device Manager
VIA/S3G Display Driver
Win2PDF 3.10
Windows Installer 3.1 (KB893803)
WordPerfect Office 11



Thank you again for helping me out.
Hi :)

That's looking a bit better. How's it running at the moment?

Please post a new HijackThis log.

Please download DirLook by jpshortstuff from one of the following mirrors:
Link 1
Link 2
Link 3
  • Double-click DirLook.exe to run it.
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the main textfield:

    c:\windows\system32\vim /s
    c:\windows\system32\ip /s
    c:\windows\system32\hdx /s
    c:\windows\system32\d /s
    C:\Temp /s
    C:\sj668 /s
  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\DirLook.txt)
Note: Scanning may take longer for large folders.


Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Thanks.
Hey I got everything done now that you asked for. The computer seems to be running a lot better. I am not getting the RunDLL errors on startup and I haven't received any pop up adds either while on the internet.

HiJackThis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:51, on 2008-12-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\userinit.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HPWQTOOLBOX] C:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe "-i"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sjph.local
O17 - HKLM\Software\..\Telephony: DomainName = sjph.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sjph.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sjph.local
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Auto-upgrade Agent (Smcinst) - Unknown owner - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcLU\Setup\smcinst.exe (file missing)
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe

–
End of file - 5204 bytes


DirLook Log


DirLook.exe v2.0 by jpshortstuff
Log created at 13:18 on 02/12/2008
==================================
Contents of "c:\windows\system32\vim"

—FOLDERS—

(none found)

—FILES—

(none found)

==================================
Contents of "c:\windows\system32\ip"

—FOLDERS—

(none found)

—FILES—

(none found)

==================================
Contents of "c:\windows\system32\hdx"

—FOLDERS—

(none found)

—FILES—

(none found)

==================================
Contents of "c:\windows\system32\d"

—FOLDERS—

(none found)

—FILES—

(none found)

==================================
Contents of "C:\Temp"

—FOLDERS—

(none found)

—FILES—

(none found)

==================================
Contents of "C:\sj668"

—FOLDERS—

English (Created on 06/11/2008 at 17:50) d—–
hppspro (Created on 06/11/2008 at 17:50) d—–
Media (Created on 06/11/2008 at 17:50) d—–

—FILES—

folder.cfg (322 bytes - created on 24/01/2000 at 10:43, modified on 24/01/2000 at 10:43) –a—
hpg4400.dll (40960 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpgblsti.cat (9653 bytes - created on 08/08/2001 at 12:41, modified on 08/08/2001 at 12:41) –a—
Hpgblsti.inf (30077 bytes - created on 24/07/2001 at 06:59, modified on 24/07/2001 at 06:59) –a—
hpgblt.dll (565248 bytes - created on 06/06/2001 at 02:42, modified on 06/06/2001 at 02:42) –a—
hpgtpusd.dll (221184 bytes - created on 23/05/2001 at 00:07, modified on 23/05/2001 at 00:07) –a—
hpgtulbl.dll (270336 bytes - created on 06/06/2001 at 00:04, modified on 06/06/2001 at 00:04) –a—
hpgtulbz.dll (253952 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpguapi.dll (118784 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpgud32.dll (249856 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpgumsti.cat (11251 bytes - created on 08/08/2001 at 16:32, modified on 08/08/2001 at 16:32) –a—
Hpgumsti.inf (37355 bytes - created on 17/07/2001 at 10:34, modified on 17/07/2001 at 10:34) –a—
hppnpins.dll (57344 bytes - created on 07/08/2001 at 17:57, modified on 07/08/2001 at 17:57) –a—
HPSJ95CI.DLL (19752 bytes - created on 22/03/2000 at 16:24, modified on 22/03/2000 at 16:24) –a—
hpsjvset.dll (118784 bytes - created on 07/08/2001 at 17:57, modified on 07/08/2001 at 17:57) –a—
IsInstallPending.exe (126976 bytes - created on 07/08/2001 at 17:52, modified on 07/08/2001 at 17:52) –a—
MSVCRT.DLL (266293 bytes - created on 01/03/1999 at 20:44, modified on 01/03/1999 at 20:44) –a—
README.doc (36762 bytes - created on 27/07/2001 at 17:41, modified on 27/07/2001 at 17:41) –a—
RTPP.vxd (100495 bytes - created on 08/10/2000 at 07:34, modified on 08/10/2000 at 07:34) –a—
rtpp2k.sys (87374 bytes - created on 30/04/2001 at 13:54, modified on 30/04/2001 at 13:54) –a—
RTS8891P.dll (397312 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
RTS8891U.dll (397312 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
Setup.exe (217088 bytes - created on 07/06/2001 at 12:18, modified on 07/06/2001 at 12:18) –a—
Setup.ini (160 bytes - created on 07/09/2001 at 07:36, modified on 07/09/2001 at 07:36) –a—
SKBZP.vxd (100575 bytes - created on 03/05/2001 at 18:05, modified on 03/05/2001 at 18:05) –a—
Stihp2k.sys (95902 bytes - created on 04/05/2001 at 15:04, modified on 04/05/2001 at 15:04) –a—
usbscan.sy_ (8944 bytes - created on 04/05/2000 at 08:09, modified on 04/05/2000 at 08:09) –a—
VOLINFO.TXT (165 bytes - created on 09/08/2001 at 11:32, modified on 09/08/2001 at 11:32) –a—

—Sub-Directories—

C:\sj668\English

SJSetupGuide.pdf (559762 bytes - created on 29/03/2001 at 15:24, modified on 29/03/2001 at 15:24) –a—

C:\sj668\hppspro

AutoLaunchEnable.Cab (187 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
BMgrEng.Cab (3067 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
ChassisEnglishHelp.Cab (4120253 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
ChassisLangIndHelp.Cab (142283 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
ChineseSOCRFiles.Cab (3353864 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
ChineseTOCRFiles.Cab (3324498 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
dcom95.exe (1229056 bytes - created on 22/02/2000 at 10:05, modified on 22/02/2000 at 10:05) –a—
Destinations.Cab (299365 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
HP Precisionscan Pro 3.1.Msi (1522392 bytes - created on 13/08/2001 at 14:52, modified on 13/08/2001 at 14:52) –a—
hpaol.dll.Cab (10016 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpbrz.inf.Cab (502 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpbze95.inf.Cab (508 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpbzesti.inf.Cab (507 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpgbl95.inf.Cab (573 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpgblsti.inf.Cab (6164 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpgblsti.inf_Migrate.Cab (6164 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpgbz95.inf.Cab (766 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpgclb.dll.Cab (11911 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
Hpgclbps.dll.Cab (2956 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpgih.dll.Cab (204512 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
Hpgihps.dll.Cab (1934 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpgreg32.dll.Cab (2811 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpgumsti.inf.Cab (6617 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpgumsti.inf_Mig.Cab (6617 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpgwiamd.dll.Cab (108773 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
HPLabsOCREngineFiles.Cab (400144 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
HPNVRResEng.Cab (497 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
HPPrecisionScanPro.exe.Cab (122974 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
Hppspres.eng.Cab (77664 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpsj32.dll.Cab (8520 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
hpsjrreg.exe.Cab (15100 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
instmsia.exe (1489152 bytes - created on 02/12/1999 at 14:56, modified on 02/12/1999 at 14:56) –a—
instmsiw.exe (1499904 bytes - created on 02/12/1999 at 14:58, modified on 02/12/1999 at 14:58) –a—
ISTechPlugins.Cab (310526 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
ISTechSystemFiles.Cab (430067 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
KoreanOCRFiles.Cab (2692064 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
lffpx.dll.Cab (148248 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM1.Cab (604957 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM10.Cab (8180 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM11.Cab (459212 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM12.Cab (810505 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM13.Cab (1116245 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM2.Cab (61905 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM3.Cab (37858 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM4.Cab (131667 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM5.Cab (464024 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM6.Cab (460401 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM7.Cab (23245 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM8.Cab (114712 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
MM9.Cab (22740924 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
ODBC32.dll_98.Cab (125002 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
Pietro.exe.Cab (561359 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
S2WENG.sjp.Cab (1590 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—
setup.exe (86016 bytes - created on 13/01/2000 at 20:53, modified on 13/01/2000 at 20:53) –a—
setup.ini (57522 bytes - created on 26/03/2001 at 12:44, modified on 26/03/2001 at 12:44) –a—
TaskLauncherEng.Cab (4628 bytes - created on 13/08/2001 at 14:51, modified on 13/08/2001 at 14:51) –a—

C:\sj668\hppspro\Common (Created on 06/11/2008 at 17:50) d—–

C:\sj668\hppspro\Common\Hewlett-Packard (Created on 06/11/2008 at 17:50) d—–

C:\sj668\hppspro\Common\Hewlett-Packard\Scanjet (Created on 06/11/2008 at 17:50) d—–

hp4400.spf (3512 bytes - created on 23/05/2001 at 13:14, modified on 23/05/2001 at 13:14) –a—
hp4470.spf (3512 bytes - created on 23/05/2001 at 13:14, modified on 23/05/2001 at 13:14) –a—
hp5400.spf (3439 bytes - created on 08/06/2001 at 07:35, modified on 08/06/2001 at 07:35) –a—
hp5470.spf (3439 bytes - created on 08/06/2001 at 07:35, modified on 08/06/2001 at 07:35) –a—
hp5490.spf (3439 bytes - created on 08/06/2001 at 07:35, modified on 08/06/2001 at 07:35) –a—
hpgscnsv.dll (86016 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—

C:\sj668\hppspro\program files (Created on 06/11/2008 at 17:50) d—–

C:\sj668\hppspro\program files\Hewlett-Packard (Created on 06/11/2008 at 17:50) d—–

C:\sj668\hppspro\program files\Hewlett-Packard\Precisionscan Pro 3.1 (Created on 06/11/2008 at 17:50) d—–

hpsjbmgr.exe (65536 bytes - created on 21/05/2001 at 00:08, modified on 21/05/2001 at 00:08) –a—
hpsrctul.dll (237568 bytes - created on 20/05/2001 at 19:46, modified on 20/05/2001 at 19:46) –a—
tasklauncher.exe (323584 bytes - created on 07/08/2001 at 17:48, modified on 07/08/2001 at 17:48) –a—
wiabtreg.dll (24576 bytes - created on 07/08/2001 at 17:56, modified on 07/08/2001 at 17:56) –a—

C:\sj668\hppspro\program files\Hewlett-Packard\Precisionscan Pro 3.1\Migrate (Created on 06/11/2008 at 17:50) d—–

hpg4400.dll (40960 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpgblsti.cat (9653 bytes - created on 08/08/2001 at 12:41, modified on 08/08/2001 at 12:41) –a—
hpgblt.dll (565248 bytes - created on 06/06/2001 at 02:42, modified on 06/06/2001 at 02:42) –a—
hpgtpusd.dll (221184 bytes - created on 23/05/2001 at 00:07, modified on 23/05/2001 at 00:07) –a—
hpgtulbl.dll (270336 bytes - created on 06/06/2001 at 00:04, modified on 06/06/2001 at 00:04) –a—
hpgtulbz.dll (253952 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpguapi.dll (118784 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpgud32.dll (249856 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpgumsti.cat (11251 bytes - created on 08/08/2001 at 16:32, modified on 08/08/2001 at 16:32) –a—
hppnpins.dll (57344 bytes - created on 07/08/2001 at 17:57, modified on 07/08/2001 at 17:57) –a—
hpsjvset.dll (118784 bytes - created on 07/08/2001 at 17:57, modified on 07/08/2001 at 17:57) –a—
RTPP.vxd (100495 bytes - created on 08/10/2000 at 07:34, modified on 08/10/2000 at 07:34) –a—
rtpp2k.sys (87374 bytes - created on 30/04/2001 at 13:54, modified on 30/04/2001 at 13:54) –a—
RTS8891P.dll (397312 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
RTS8891U.dll (397312 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
SKBZP.vxd (100575 bytes - created on 03/05/2001 at 18:05, modified on 03/05/2001 at 18:05) –a—
Stihp2k.sys (95902 bytes - created on 04/05/2001 at 15:04, modified on 04/05/2001 at 15:04) –a—
usbscan.sy_ (8944 bytes - created on 04/05/2000 at 08:09, modified on 04/05/2000 at 08:09) –a—

C:\sj668\hppspro\S2WEng (Created on 06/11/2008 at 17:50) d—–

data1.cab (462766 bytes - created on 03/07/2001 at 08:24, modified on 03/07/2001 at 08:24) –a—
data1.hdr (28343 bytes - created on 03/07/2001 at 08:24, modified on 03/07/2001 at 08:24) –a—
data2.cab (1519309 bytes - created on 03/07/2001 at 08:24, modified on 03/07/2001 at 08:24) –a—
ikernel.ex_ (339565 bytes - created on 05/10/2000 at 14:01, modified on 05/10/2000 at 14:01) –a—
layout.bin (454 bytes - created on 03/07/2001 at 06:36, modified on 03/07/2001 at 06:36) –a—
Setup.exe (54272 bytes - created on 05/10/2000 at 15:00, modified on 05/10/2000 at 15:00) –a—
Setup.ini (87 bytes - created on 31/05/2001 at 08:59, modified on 31/05/2001 at 08:59) –a—
setup.inx (171382 bytes - created on 29/06/2001 at 11:56, modified on 29/06/2001 at 11:56) –a—
setup.iss (265 bytes - created on 14/02/2001 at 09:44, modified on 14/02/2001 at 09:44) –a—
SSLaunch.exe (135168 bytes - created on 13/03/2001 at 09:41, modified on 13/03/2001 at 09:41) –a—

C:\sj668\hppspro\System32 (Created on 06/11/2008 at 17:50) d—–

HPBRZ.VXD (110257 bytes - created on 03/04/2001 at 13:36, modified on 03/04/2001 at 13:36) –a—
HPBZE95.VXD (100576 bytes - created on 15/05/2001 at 21:52, modified on 15/05/2001 at 21:52) –a—
Hpbzesti.vxd (100588 bytes - created on 15/05/2001 at 21:52, modified on 15/05/2001 at 21:52) –a—
hpg4400.dll (40960 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpgblt.dll (565248 bytes - created on 06/06/2001 at 02:42, modified on 06/06/2001 at 02:42) –a—
hpgtpusd.dll (221184 bytes - created on 23/05/2001 at 00:07, modified on 23/05/2001 at 00:07) –a—
hpgtulbl.dll (270336 bytes - created on 06/06/2001 at 00:04, modified on 06/06/2001 at 00:04) –a—
hpgtulbz.dll (253952 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpguapi.dll (118784 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpgud32.dll (249856 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
hpsjvset.dll (118784 bytes - created on 07/08/2001 at 17:57, modified on 07/08/2001 at 17:57) –a—
prntfix.exe (151552 bytes - created on 24/01/2001 at 06:31, modified on 24/01/2001 at 06:31) –a—
RTPP.vxd (100495 bytes - created on 08/10/2000 at 07:34, modified on 08/10/2000 at 07:34) –a—
RTS8891P.dll (397312 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
RTS8891U.dll (397312 bytes - created on 14/05/2001 at 00:08, modified on 14/05/2001 at 00:08) –a—
SKBZP.vxd (100575 bytes - created on 03/05/2001 at 18:05, modified on 03/05/2001 at 18:05) –a—

C:\sj668\hppspro\System32\drivers (Created on 06/11/2008 at 17:50) d—–

HPGDENT.sys (122416 bytes - created on 25/04/2001 at 08:59, modified on 25/04/2001 at 08:59) –a—
RTPP.SYS (191496 bytes - created on 26/09/2000 at 08:50, modified on 26/09/2000 at 08:50) –a—

C:\sj668\hppspro\Windows (Created on 06/11/2008 at 17:50) d—–

C:\sj668\hppspro\Windows\inf (Created on 06/11/2008 at 17:50) d—–

C:\sj668\hppspro\Windows\inf\catalog (Created on 06/11/2008 at 17:50) d—–

hpgblsti.cat (9653 bytes - created on 08/08/2001 at 12:41, modified on 08/08/2001 at 12:41) –a—
hpgumsti.cat (11251 bytes - created on 08/08/2001 at 16:32, modified on 08/08/2001 at 16:32) –a—

C:\sj668\Media

hpibrwsr.ini (1718 bytes - created on 13/08/2001 at 16:18, modified on 13/08/2001 at 16:18) –a—
MSVCRT.DLL (266293 bytes - created on 01/03/1999 at 20:44, modified on 01/03/1999 at 20:44) –a—
ScanConnect.exe (24576 bytes - created on 14/05/2001 at 00:07, modified on 14/05/2001 at 00:07) –a—

C:\sj668\Media\Icons (Created on 06/11/2008 at 17:50) d—–

acdsee.bmp (2102 bytes - created on 15/11/2000 at 10:19, modified on 15/11/2000 at 10:19) –a—
acrobat.bmp (3382 bytes - created on 23/04/1999 at 08:01, modified on 23/04/1999 at 08:01) –a—
cardiris.bmp (596 bytes - created on 29/03/2000 at 08:09, modified on 29/03/2000 at 08:09) –a—
director.bmp (4376 bytes - created on 16/01/1999 at 14:49, modified on 16/01/1999 at 14:49) –a—
efax.bmp (3128 bytes - created on 10/05/2000 at 08:52, modified on 10/05/2000 at 08:52) –a—
Fusion.bmp (449334 bytes - created on 10/01/2001 at 10:13, modified on 10/01/2001 at 10:13) –a—
printoffice.bmp (2102 bytes - created on 19/04/2000 at 15:25, modified on 19/04/2000 at 15:25) –a—
prntcre.bmp (2102 bytes - created on 01/02/2001 at 13:56, modified on 01/02/2001 at 13:56) –a—
psp.bmp (2266 bytes - created on 21/01/1999 at 14:39, modified on 21/01/1999 at 14:39) –a—
scansoft.BMP (630 bytes - created on 13/02/2001 at 13:20, modified on 13/02/2001 at 13:20) –a—
setup.bmp (121080 bytes - created on 02/04/1999 at 10:41, modified on 02/04/1999 at 10:41) –a—
vssver.scc (208 bytes - created on 07/08/2001 at 17:17, modified on 07/08/2001 at 17:17) –a—

C:\sj668\Media\languages (Created on 06/11/2008 at 17:50) d—–

English.cst (1833214 bytes - created on 13/08/2001 at 16:18, modified on 13/08/2001 at 16:18) –a—
English.ini (8177 bytes - created on 13/08/2001 at 16:18, modified on 13/08/2001 at 16:18) –a—

C:\sj668\Media\Xtras (Created on 06/11/2008 at 17:50) d—–

BMP Import Export.x32 (26624 bytes - created on 05/04/1999 at 15:22, modified on 05/04/1999 at 15:22) –a—
Budapi.x32 (137728 bytes - created on 30/09/1998 at 03:20, modified on 30/09/1998 at 03:20) –a—
Budapi32.dll (109056 bytes - created on 30/09/1998 at 03:20, modified on 30/09/1998 at 03:20) –a—
cfgmgr32.dll (23552 bytes - created on 29/01/1999 at 15:22, modified on 29/01/1999 at 15:22) –a—
checkhw.exe (57344 bytes - created on 07/08/2001 at 17:54, modified on 07/08/2001 at 17:54) –a—
FILEIO.X32 (25088 bytes - created on 01/12/1998 at 23:47, modified on 01/12/1998 at 23:47) –a—
Font Asset.x32 (49152 bytes - created on 23/05/1999 at 15:33, modified on 23/05/1999 at 15:33) –a—
Font Xtra.x32 (230400 bytes - created on 23/05/1999 at 15:33, modified on 23/05/1999 at 15:33) –a—
INetURL.x32 (28672 bytes - created on 23/05/1999 at 15:32, modified on 23/05/1999 at 15:32) –a—
MastrApp.x32 (126464 bytes - created on 01/03/1999 at 01:26, modified on 01/03/1999 at 01:26) –a—
Mix Services.x32 (64000 bytes - created on 23/05/1999 at 15:42, modified on 23/05/1999 at 15:42) –a—
NetFile.x32 (41472 bytes - created on 23/05/1999 at 15:31, modified on 23/05/1999 at 15:31) –a—
NetLingo.x32 (35328 bytes - created on 23/05/1999 at 15:31, modified on 23/05/1999 at 15:31) –a—
PMatic.x32 (351744 bytes - created on 22/09/1999 at 12:18, modified on 22/09/1999 at 12:18) –a—
Text Asset.x32 (50688 bytes - created on 23/05/1999 at 15:32, modified on 23/05/1999 at 15:32) –a—
TextXtra.x32 (333824 bytes - created on 23/05/1999 at 15:32, modified on 23/05/1999 at 15:32) –a—
vssver.scc (272 bytes - created on 07/08/2001 at 17:20, modified on 07/08/2001 at 17:20) –a—

C:\sj668\Media\Xtras\ShareIns (Created on 06/11/2008 at 17:50) d—–

DATA.TAG (78 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—
data1.cab (2075441 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—
data1.hdr (5152 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—
lang.dat (23541 bytes - created on 12/01/1999 at 10:34, modified on 12/01/1999 at 10:34) –a—
layout.bin (590 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—
os.dat (450 bytes - created on 27/07/1998 at 16:41, modified on 27/07/1998 at 16:41) –a—
Setup.exe (73728 bytes - created on 12/01/1999 at 11:42, modified on 12/01/1999 at 11:42) –a—
SETUP.INI (79 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—
setup.ins (57381 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—
setup.lid (49 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—
shareins.iss (152 bytes - created on 14/05/1999 at 09:41, modified on 14/05/1999 at 09:41) –a—
_inst32i.ex_ (296674 bytes - created on 23/02/1999 at 10:45, modified on 23/02/1999 at 10:45) –a—
_ISDel.exe (27648 bytes - created on 27/10/1998 at 12:06, modified on 27/10/1998 at 12:06) –a—
_Setup.dll (34816 bytes - created on 29/09/1998 at 16:34, modified on 29/09/1998 at 16:34) –a—
_sys1.cab (175466 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—
_sys1.hdr (3905 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—
_user1.cab (1175432 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—
_user1.hdr (4438 bytes - created on 13/08/2001 at 14:50, modified on 13/08/2001 at 14:50) –a—

==================================
=EOF=


And last but not least the Kaspersky Log

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, December 2, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, December 02, 2008 14:49:46
Records in database: 1431882
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
F:\
G:\
P:\

Scan statistics:
Files scanned: 59215
Threat name: 2
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 01:44:15


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\08240000.VBN Infected: Trojan.Win32.Agent.apvo 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\08240001.VBN Infected: Trojan.Win32.Agent.apvn 1

The selected area was scanned.
Hi :)

Follow instructions from this link to clean the contents of your Symantec Quarantine folder.

Please delete the following folders:
c:\windows\system32\vim
c:\windows\system32\ip
c:\windows\system32\hdx
c:\windows\system32\d
C:\Temp

Post one last HijackThis log and we'll see if we can wrap this up. Any more problems?

Thanks.
Hey

I deleted my symantec quaranties and those folders that you specified. Everything seems to be working excellent now.

Thanks again for helping me out. I would like to get more into fixing adware problems but I just havent had the time. I'm hoping that I can find some time here soon to take the online classroom that WTT has to offer so that I can give back to the community that has helped me several times.

My hats off to you jpshortstuff :notworthy:


Here is the HiJackThis log you requested.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:38, on 2008-12-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HPWQTOOLBOX] C:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe "-i"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sjph.local
O17 - HKLM\Software\..\Telephony: DomainName = sjph.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sjph.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sjph.local
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Auto-upgrade Agent (Smcinst) - Unknown owner - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcLU\Setup\smcinst.exe (file missing)
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe

–
End of file - 5125 bytes


thanks again,

Mitch
Hi Mitch

Log looks good :thumbup:


Click Start >> Run, and then type ComboFix /u and hit enter.
You can now delete any other tools I had you download and use, unless you wish to keep them.


You need to upgrade to Windows XP Service Pack 3. Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install Windows XP - Service Pack 3.


Now that your system appears to be clean, theres just a few steps I'd like you to take to prevent any future infections.
  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Use Mozilla Firefox or Opera as your internet browser.
    These are more secure than Internet Explorer and can be downloaded for free from here:
    Download Mozilla FireFox
    Download Opera

    Alternatively, update Internet Explorer to version 7 as this is more secure than the previous versions.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI