![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: May 2006
Posts: 8
OS: XP
|
HJT log - Pop-ups
I have had alot of pop-ups lately. Can you see anything on my log?
Logfile of HijackThis v1.99.1 Scan saved at 2 17 PM, on 10/20/2006Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5700.0006) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Hijack This\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate" O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Chckup] C:\WINDOWS\system32\Netverchk.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Save Flash In This Page by Flash Saver - C:\PROGRA~1\FLASHS~1\save.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204 O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://pcpitstop.com/internet/pcpConnCheck.cab O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.com/ist/softwares/...sb_regular.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by101fd.bay101.hotmail.msn.co...s/MsnPUpld.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource...scbase5059.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1155453559312 O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVCDownloadControl) - http://download.games.yahoo.com/game...oadControl.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{120B3144-77B0-4DA9-8A7D-7093B80DE88D}: NameServer = 192.168.1.254 O17 - HKLM\System\CS1\Services\Tcpip\..\{120B3144-77B0-4DA9-8A7D-7093B80DE88D}: NameServer = 192.168.1.254 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NPDOR File Monitor Service (NFMService) - Unknown owner - C:\WINDOWS\System32\NPDORNT.exe (file missing) |
|
|
|
|
#2 (permalink) |
|
Mentor, Analyst - Security Team
Join Date: May 2006
Location: Oregon
Posts: 2,503
OS: MacOS X, Debian, OpenBSD, Windows
|
Hello Cougar24, and welcome to TSF. You may wish to Subscribe to this thread so that you are notified when you receive a reply. To do this click Thread Tools (above the first post), then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.
Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions. If there is anything you don't understand, please ask BEFORE proceeding with the fixes. Please do these steps in order and do not skip any. Unhide Files Go to My Computer > Tools > Folder Options > View tab and select "Show hidden files and folders". Uncheck the "Hide protected operating system files (Recommended)" option. Also make sure there is no checkmark beside "Hide file extensions for known file types". Click OK. Antivirus Required I notice that you do not appear to have an active antivirus program. Connecting to the Internet without antivirus protection is a "Welcome" doormat for malware. It can take as little as eight seconds to infect an unprotected computer. Here are several very good free antivirus products which are available:
Download CleanUp! Download and install CleanUp! but do not run it yet. WARNING: CleanUp! deletes EVERYTHING out of temporary folders and does not make backups. If you have any documents or programs that are saved in any temporary folders, please make a backup of these before running CleanUp! WARNING: Do not run cleanup under Windows XP x64 Edition. If you're not sure if you have the 64-bit version of Windows then you probably do not; however, you can check by using IE to download the whichcpu tool and then running it. Download AVG Anti-Spyware Please download, install, and update AVG Anti-Spyware.
Disable Services Disable AntiSpyware Uninstall Click Start > Control Panel > Add / Remove Programs and uninstall the following programs (if they exist): VSToolbarPlease let me know if any of these were unable to uninstall. Reboot Reboot your system to Safe Mode by repeatedly tapping the F8 key until the menu appears and choosing Safe Mode from the list. On some systems, this may be the F5 key so try that if F8 doesn't work. Login on with your usual account. Make sure to close any open windows. HijackThis Fixes Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they still exist (make sure you do not miss any): R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =Please remember to close all other windows, including browsers then click Fix checked. Close HijackThis. Deletions Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist. C:\Program Files\VSToolbar Run CleanUp! Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
Run AVG Anti-Spyware
Reboot Reboot your system to Normal Mode. Online Scan Perform an online scan using Internet Explorer with Kaspersky WebScanner. Click on Launch Kaspersky Anti-Virus Web Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
With Your Next Post... Please paste the following with your next reply (in this order please):
__________________
The chance to begin again in a golden land of opportunity and adventure. Need HijackThis help? Please read MicroBell's Five Step Process before posting.
Please donate and help keep this site free to all. ![]() UNITE/ASAP: Proud member since 2006 |
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: May 2006
Posts: 8
OS: XP
|
Thanks for the quick reply. Here are my logs:
AVG ANTISPYWARE SCAN: --------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 6:43:25 PM 10/22/2006 + Scan result: C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP20\A0000193.dll -> Adware.WinAntiVirus : No action taken. ::Report end ---------------------------------------------- KAS LOG: Sunday, October 22, 2006 7:36:09 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 23/10/2006 Kaspersky Anti-Virus database records: 233865 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer C:\ D:\ E:\ Scan Statistics Total number of scanned objects 79143 Number of viruses found 3 Number of infected objects 9 / 0 Number of suspicious objects 0 Duration of the scan process 00:38:56 Infected Object Name Virus Name Last Action C:\!KillBox\YOINSI.exe/data0002 Infected: Trojan.Win32.Scapur.k skipped C:\!KillBox\YOINSI.exe NSIS: infected - 1 skipped C:\!KillBox\ysbactivex.dll Infected: Trojan-Downloader.Win32.IstBar.gen skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\WDLog-05072006-012739.log Object is locked skipped C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp Object is locked skipped C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Will McCracken\Application Data\Sun\Java\Deployment\log\plugin150_06.trace Object is locked skipped C:\Documents and Settings\Will McCracken\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Messenger\cougar_2424@hotmail.com\SharingMetadata\Logs\Dfsr.log Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Messenger\cougar_2424@hotmail.com\SharingMetadata\pending.dat Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Messenger\cougar_2424@hotmail.com\SharingMetadata\Working\database_DE98_491D_9848_F595\dfsr.db Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Messenger\cougar_2424@hotmail.com\SharingMetadata\Working\database_DE98_491D_9848_F595\fsr.log Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Messenger\cougar_2424@hotmail.com\SharingMetadata\Working\database_DE98_491D_9848_F595\fsrtmp.log Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Messenger\cougar_2424@hotmail.com\SharingMetadata\Working\database_DE98_491D_9848_F595\tmp.edb Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{CF02BD7E-DC02-4878-9F1C-7DDCFB7D8D96} Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Windows Live Contacts\Cougar_2424@hotmail.com\real\members.stg Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Application Data\Microsoft\Windows Live Contacts\Cougar_2424@hotmail.com\shadow\members.stg Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\History\History.IE5\MSHist012006102220061023\index.dat Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Temp\hsperfdata_Will McCracken\3740 Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Temp\~DF5983.tmp Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Temp\~DF59D2.tmp Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Temp\~DFA2C0.tmp Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Temp\~DFA5A9.tmp Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Temp\~DFF4F6.tmp Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Temp\~DFF831.tmp Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Temporary Internet Files\AntiPhishing\2997C193-A464-4307-88C9-F9C00083CD16.dat Object is locked skipped C:\Documents and Settings\Will McCracken\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Will McCracken\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Will McCracken\ntuser.dat.LOG Object is locked skipped C:\Program Files\Microsoft AntiSpyware\Quarantine\426E7C38-3B99-44B8-A21A-5E828B\ED3C5295-3619-4E07-B224-3B441D Infected: Trojan-Downloader.Win32.IstBar.gen skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000019.dll Object is locked skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000020.exe/data0002 Infected: Trojan.Win32.Scapur.k skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000020.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP37\A0000439.dll Object is locked skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP39\A0000535.dll Object is locked skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP39\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\justin2a.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.SideFind.a skipped C:\WINDOWS\justin2a.exe/stream Infected: not-a-virus:AdWare.Win32.SideFind.a skipped C:\WINDOWS\justin2a.exe NSIS: infected - 2 skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. ------------------------------------------ HJT log: Logfile of HijackThis v1.99.1 Scan saved at 7:42:17 PM, on 10/22/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5700.0006) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\svchost.exe C:\Hijack This\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\nfyqlnbg.dll (file missing) O2 - BHO: (no name) - {208DC7E7-BAF9-5AD9-BC54-0BD2C798850B} - C:\WINDOWS\system32\crvdyu.dll (file missing) O2 - BHO: (no name) - {34A5CC02-A1F3-4BD9-8033-596053114D57} - C:\WINDOWS\system32\ddcyv.dll (file missing) O2 - BHO: RunBus Class - {4865F155-CE00-4E93-A414-147844D7C81A} - C:\WINDOWS\system32\tcbljdhf.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSL encrypt - {746455FE-D059-47e7-AF0E-140E03F5A447} - C:\WINDOWS\system32\nsuD.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AD Rotator - {EEC590D8-0A3C-4464-BB20-25A4747992F9} - C:\WINDOWS\system32\adrotate.dll (file missing) O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Save Flash In This Page by Flash Saver - C:\PROGRA~1\FLASHS~1\save.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204 O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://pcpitstop.com/internet/pcpConnCheck.cab O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by101fd.bay101.hotmail.msn.co...s/MsnPUpld.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource...scbase5059.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1155453559312 O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVCDownloadControl) - http://download.games.yahoo.com/game...oadControl.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{120B3144-77B0-4DA9-8A7D-7093B80DE88D}: NameServer = 192.168.1.254 O17 - HKLM\System\CS1\Services\Tcpip\..\{120B3144-77B0-4DA9-8A7D-7093B80DE88D}: NameServer = 192.168.1.254 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: ddcyv - C:\WINDOWS\system32\ddcyv.dll (file missing) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: winbjv32 - winbjv32.dll (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NPDOR File Monitor Service (NFMService) - Unknown owner - C:\WINDOWS\System32\NPDORNT.exe (file missing) |
|
|
|
|
#4 (permalink) |
|
Mentor, Analyst - Security Team
Join Date: May 2006
Location: Oregon
Posts: 2,503
OS: MacOS X, Debian, OpenBSD, Windows
|
Looks like we got most of it, but there are still some left.
Download ComboFix Download ComboFix to your Desktop from one of the following links:
"%userprofile%\desktop\combofix.exe" /v ddcyv winbjv32Then go to Start > Run, paste it into the text field, and then click OK. ![]() Reboot Reboot your system to Safe Mode by repeatedly tapping the F8 key until the menu appears and choosing Safe Mode from the list. On some systems, this may be the F5 key so try that if F8 doesn't work. Login on with your usual account. Make sure to close any open windows. HijackThis Fixes Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they still exist (make sure you do not miss any): O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\nfyqlnbg.dll (file missing)Please remember to close all other windows, including browsers then click Fix checked. Close HijackThis. Deletions Delete the following Files indicated in RED if they still exist: C:\!KillBox\YOINSI.exe Reboot Reboot your system to Normal Mode. Online Scan Please perform an BitDefender Online Scan using Internet Explorer. Once finished, click on the Details button to view the results. To the upper right of the results you will see an option saying "Click here to export the scan results". Please do so and save it to your desktop. Post the results of the scan with your next post. With Your Next Post... Please paste the following with your next reply (in this order please):
__________________
The chance to begin again in a golden land of opportunity and adventure. Need HijackThis help? Please read MicroBell's Five Step Process before posting.
Please donate and help keep this site free to all. ![]() UNITE/ASAP: Proud member since 2006 |
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: May 2006
Posts: 8
OS: XP
|
Thank you so much for taking the time to help me with this. I really appreciate it. COMBO FIX: Will McCracken - 06-10-22 22:20:50.90 Service Pack 2 ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Will McCracken\desktop" Command switches used :: /v ddcyv winbjv32 ((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Program Files\data19 * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * (((((((((((((((((((((((((((((((((((((((((((((((( Vundo Log ))))))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\vycdd.bak1 C:\WINDOWS\system32\vycdd.bak2 C:\WINDOWS\system32\vycdd.ini * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\adrot-uninst.exe C:\WINDOWS\system32\wintsvsu.exe C:\WINDOWS\system32\atmtd.dll._ C:\Program Files\Inetget2 C:\WINDOWS\system32\components C:\Program Files\Common Files\{3848F595-0BB0-1033-0525-050405120001} C:\Program Files\Common Files\{9848F595-0BB0-1033-0525-050405120001} ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Folders Quarantined: C:\QooBox\Purity\Program Files\MCROSO~1.NET ((((((((((((((((((((((((((((((( Files Created from 2006-09-22 to 2006-10-22 )))))))))))))))))))))))))))))))))) 2006-10-22 04:31 816,288 --a------ C:\WINDOWS\system32\drivers\avg7core.sys 2006-10-22 04:31 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys 2006-10-22 04:31 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys 2006-10-22 04:31 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys 2006-10-20 01:56 67,604 --a------ C:\WINDOWS\system32\rtkykqmv.exe 2006-10-19 16:39 22,768 --a------ C:\WINDOWS\system32\drivers\usbser2k.sys 2006-10-16 03:55 44,888 --a------ C:\WINDOWS\system32\CAUnst.exe 2006-10-16 03:55 409,600 --a------ C:\WINDOWS\system32\tcbljdhf.dll 2006-10-16 03:55 36,864 --a------ C:\WINDOWS\system32\slimppho.exe 2006-10-12 23:13 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2006-10-12 20:26 53,248 --a------ C:\WINDOWS\system32\Process.exe 2006-10-12 20:26 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2006-10-12 20:26 135,168 --a------ C:\WINDOWS\system32\swreg.exe 2006-10-12 10:14 78,848 --a------ C:\WINDOWS\system32\nsuD.dll 2006-10-09 23:10 737,280 --a------ C:\WINDOWS\iun6002.exe 2006-10-03 02:21 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll 2006-10-03 02:21 0 --a------ C:\WINDOWS\system32\taskkill.exe 2006-10-02 15:04 806,912 --a------ C:\WINDOWS\system32\divx_xx0c.dll 2006-10-02 15:04 806,912 --a------ C:\WINDOWS\system32\divx_xx07.dll 2006-10-02 15:04 790,528 --a------ C:\WINDOWS\system32\divx_xx11.dll 2006-10-02 15:04 635,486 --a------ C:\WINDOWS\system32\DivX.dll 2006-09-28 13:31 121,856 --a------ C:\WINDOWS\system32\xmllite.dll (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-10-22 22:21 -------- d-------- C:\Program Files\Common Files 2006-10-22 18:46 -------- d-------- C:\Documents and Settings\Will McCracken\Application Data\AVG7 2006-10-22 04:42 -------- d-------- C:\Program Files\CleanUp! 2006-10-22 04:31 -------- d-------- C:\Program Files\Grisoft 2006-10-18 12:42 -------- d-------- C:\Documents and Settings\Will McCracken\Application Data\uTorrent 2006-10-17 16:41 -------- d-------- C:\Program Files\GustoSoft 2006-10-15 03:03 -------- d-------- C:\Program Files\Pocket Tanks Deluxe 2006-10-14 22:46 -------- d-------- C:\Program Files\Windows Media Player 2006-10-14 22:46 -------- d-------- C:\Program Files\Windows Defender 2006-10-14 22:46 -------- d-------- C:\Program Files\QuickTime 2006-10-14 22:45 -------- d-------- C:\Program Files\MSN Messenger 2006-10-14 22:37 -------- d-------- C:\Program Files\Internet Explorer 2006-10-14 02:10 -------- d-------- C:\Program Files\MSXML 4.0 2006-10-12 23:58 -------- d-------- C:\Program Files\Mozilla Firefox 2006-10-12 01:43 -------- d-------- C:\Program Files\Intelore 2006-10-11 23:40 -------- d-------- C:\Documents and Settings\Will McCracken\Application Data\DivX 2006-10-07 02:12 -------- d-------- C:\Program Files\utorrent 2006-10-07 01:05 -------- d-------- C:\Program Files\BitTorrent 2006-10-06 04:45 -------- d-------- C:\Program Files\DivX 2006-10-06 01:58 -------- d-------- C:\Program Files\LimeWire 2006-10-05 21:49 -------- d-------- C:\Documents and Settings\Will McCracken\Application Data\BitTorrent 2006-10-05 17:21 -------- d-------- C:\Program Files\Minefield 2006-09-30 22:52 -------- d--h----- C:\Program Files\InstallShield Installation Information 2006-09-30 16:28 -------- d-------- C:\Program Files\Zio 2006-09-28 14:34 -------- d-------- C:\Program Files\Flash Saver 2006-09-21 23:06 -------- d-------- C:\Program Files\coolpro2 2006-09-21 23:04 -------- d-------- C:\Documents and Settings\Will McCracken\Application Data\Syntrillium 2006-09-21 12:55 -------- d-------- C:\Documents and Settings\Will McCracken\Application Data\Seven Zip 2006-09-21 12:51 -------- d-------- C:\Program Files\AltoMP3 Gold 2006-09-21 12:46 356352 --a------ C:\WINDOWS\eSellerateEngine.dll 2006-09-21 12:46 -------- d-------- C:\Program Files\Deskshare 2006-09-17 23:45 -------- d-------- C:\Program Files\Motorola 2006-09-17 23:45 -------- d-------- C:\Program Files\Common Files\Motorola Shared 2006-09-16 02:10 -------- d-------- C:\Program Files\Yahoo! 2006-09-14 12:32 -------- d-------- C:\Program Files\Nmap 2006-09-13 20:08 -------- d-------- C:\Program Files\WinRAR 2006-09-13 19:13 -------- d-------- C:\Program Files\Google 2006-09-13 01:26 -------- d-------- C:\Program Files\Windows Media Connect 2 2006-09-13 01:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll 2006-09-12 22:32 98032 --a------ C:\Documents and Settings\Will McCracken\Application Data\GDIPFONTCACHEV1.DAT 2006-09-12 17:51 1245184 --a------ C:\WINDOWS\system32\msxml4.dll 2006-08-25 11:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll 2006-08-24 22:42 8704 --a------ C:\WINDOWS\system32\wdfmgr.exe 2006-08-24 22:42 8704 --a------ C:\WINDOWS\system32\uwdf.exe 2006-08-24 22:30 99840 --a------ C:\WINDOWS\system32\wmpshell.dll 2006-08-24 22:30 990208 --a------ C:\WINDOWS\system32\drmv2clt.dll 2006-08-24 22:30 937984 --a------ C:\WINDOWS\system32\WMNetMgr.dll 2006-08-24 22:30 8337920 --a------ C:\WINDOWS\system32\wmploc.dll 2006-08-24 22:30 790016 --a------ C:\WINDOWS\system32\WMVSENCD.dll 2006-08-24 22:30 757248 --a------ C:\WINDOWS\system32\WMADMOD.dll 2006-08-24 22:30 7168 --a------ C:\WINDOWS\system32\asferror.dll 2006-08-24 22:30 656896 --a------ C:\WINDOWS\system32\WMVXENCD.dll 2006-08-24 22:30 63488 --a------ C:\WINDOWS\system32\wpdmtpus.dll 2006-08-24 22:30 629760 --a------ C:\WINDOWS\system32\wpd_ci.dll 2006-08-24 22:30 611840 --a------ C:\WINDOWS\system32\wmpmde.dll 2006-08-24 22:30 603648 --a------ C:\WINDOWS\system32\WMSPDMOD.dll 2006-08-24 22:30 537600 --a------ C:\WINDOWS\system32\blackbox.dll 2006-08-24 22:30 532992 --a------ C:\WINDOWS\system32\wmdrmsdk.dll 2006-08-24 22:30 428032 --a------ C:\WINDOWS\system32\wmdrmdev.dll 2006-08-24 22:30 414208 --a------ C:\WINDOWS\system32\msscp.dll 2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll 2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll 2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\WMVADVE.DLL 2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\WMVADVD.dll 2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll 2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll 2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wdfapi.dll 2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\MPG4DMOD.dll 2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\MP4SDMOD.dll 2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\MP43DMOD.dll 2006-08-24 22:30 37376 --a------ C:\WINDOWS\system32\wmdmps.dll 2006-08-24 22:30 35840 --a------ C:\WINDOWS\system32\wpdconns.dll 2006-08-24 22:30 349184 --a------ C:\WINDOWS\system32\wpdsp.dll 2006-08-24 22:30 347648 --a------ C:\WINDOWS\system32\wmdrmnet.dll 2006-08-24 22:30 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll 2006-08-24 22:30 320512 --a------ C:\WINDOWS\system32\mswmdm.dll 2006-08-24 22:30 316928 --a------ C:\WINDOWS\system32\MP4SDECD.dll 2006-08-24 22:30 314368 --a------ C:\WINDOWS\system32\wmpdxm.dll 2006-08-24 22:30 305152 --a------ C:\WINDOWS\system32\MSDelta.dll 2006-08-24 22:30 295424 --a------ C:\WINDOWS\system32\wmpeffects.dll 2006-08-24 22:30 284160 --a------ C:\WINDOWS\system32\PortableDeviceApi.dll 2006-08-24 22:30 276480 --a------ C:\WINDOWS\system32\audiodev.dll 2006-08-24 22:30 27648 --a------ C:\WINDOWS\system32\mspmsnsv.dll 2006-08-24 22:30 259072 --a------ C:\WINDOWS\system32\MPG4DECD.dll 2006-08-24 22:30 2589184 --a------ C:\WINDOWS\system32\WpdShext.dll 2006-08-24 22:30 258560 --a------ C:\WINDOWS\system32\MP43DECD.dll 2006-08-24 22:30 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll 2006-08-24 22:30 242176 --a------ C:\WINDOWS\system32\wmpasf.dll 2006-08-24 22:30 228352 --a------ C:\WINDOWS\system32\cewmdm.dll 2006-08-24 22:30 227328 --a------ C:\WINDOWS\system32\wmerror.dll 2006-08-24 22:30 222208 --a------ C:\WINDOWS\system32\WMASF.dll 2006-08-24 22:30 211968 --a------ C:\WINDOWS\system32\MFPLAT.dll 2006-08-24 22:30 210432 --a------ C:\WINDOWS\system32\qasf.dll 2006-08-24 22:30 204800 --a------ C:\WINDOWS\system32\wmpsrcwp.dll 2006-08-24 22:30 198144 --a------ C:\WINDOWS\system32\PortableDeviceWMDRM.dll 2006-08-24 22:30 179712 --a------ C:\WINDOWS\system32\msnetobj.dll 2006-08-24 22:30 175104 --a------ C:\WINDOWS\system32\mspmsp.dll 2006-08-24 22:30 166912 --a------ C:\WINDOWS\system32\PortableDeviceTypes.dll 2006-08-24 22:30 1660416 --a------ C:\WINDOWS\system32\wmpencen.dll 2006-08-24 22:30 157184 --a------ C:\WINDOWS\system32\wmidx.dll 2006-08-24 22:30 154624 --a------ C:\WINDOWS\system32\wpdmtp.dll 2006-08-24 22:30 1539584 --a------ C:\WINDOWS\system32\WMVDECOD.dll 2006-08-24 22:30 1532416 --a------ C:\WINDOWS\system32\WMVENCOD.dll 2006-08-24 22:30 1392128 --a------ C:\WINDOWS\system32\WMVSDECD.dll 2006-08-24 22:30 133120 --a------ C:\WINDOWS\system32\WPDShServiceObj.dll 2006-08-24 22:30 1327616 --a------ C:\WINDOWS\system32\WMSPDMOE.dll 2006-08-24 22:30 132096 --a------ C:\WINDOWS\system32\PortableDeviceWiaCompat.dll 2006-08-24 22:30 130048 --a------ C:\WINDOWS\system32\wmpps.dll 2006-08-24 22:30 11264 --a------ C:\WINDOWS\system32\LAPRXY.dll 2006-08-24 22:30 1118208 --a------ C:\WINDOWS\system32\WMADMOE.dll 2006-08-24 22:30 101888 --a------ C:\WINDOWS\system32\PortableDeviceClassExtension.dll 2006-08-24 20:31 100864 --a------ C:\WINDOWS\system32\logagent.exe 2006-08-24 20:27 249344 --a------ C:\WINDOWS\system32\drmupgds.exe 2006-08-24 20:26 95288 --a------ C:\WINDOWS\system32\WUDFCoinstaller.dll 2006-08-24 20:26 38656 --a------ C:\WINDOWS\system32\drivers\wpdusb.sys 2006-08-24 20:26 17408 --a------ C:\WINDOWS\system32\wpdshextautoplay.exe 2006-08-24 19:22 90112 --a------ C:\WINDOWS\system32\drivers\WudfRd.sys 2006-08-24 19:19 316416 --a------ C:\WINDOWS\system32\WUDFx.dll 2006-08-24 19:19 145920 --a------ C:\WINDOWS\system32\WudfHost.exe 2006-08-24 19:18 84864 --a------ C:\WINDOWS\system32\drivers\WudfPf.sys 2006-08-24 19:18 56320 --a------ C:\WINDOWS\system32\WudfSvc.dll 2006-08-24 19:18 168448 --a------ C:\WINDOWS\system32\WudfPlatform.dll 2006-08-23 00:31 5906432 --a------ C:\WINDOWS\system32\ieframe.dll 2006-08-23 00:31 50688 --a------ C:\WINDOWS\system32\msfeedsbs.dll 2006-08-23 00:31 457728 --a------ C:\WINDOWS\system32\msfeeds.dll 2006-08-23 00:31 413696 --a------ C:\WINDOWS\system32\vbscript.dll 2006-08-23 00:31 225792 --a------ C:\WINDOWS\system32\webcheck.dll 2006-08-23 00:31 175616 --a------ C:\WINDOWS\system32\ieui.dll 2006-08-23 00:31 152064 --a------ C:\WINDOWS\system32\msls31.dll 2006-08-23 00:18 78336 --a------ C:\WINDOWS\system32\ieencode.dll 2006-08-23 00:18 206336 --a------ C:\WINDOWS\system32\WinFXDocObj.exe 2006-08-23 00:17 40448 --a------ C:\WINDOWS\system32\licmgr10.dll 2006-08-23 00:17 105472 --a------ C:\WINDOWS\system32\url.dll 2006-08-23 00:17 100352 --a------ C:\WINDOWS\system32\occache.dll 2006-08-23 00:16 16896 --a------ C:\WINDOWS\system32\corpol.dll 2006-08-23 00:14 378368 --a------ C:\WINDOWS\system32\iedkcs32.dll 2006-08-23 00:14 229376 --a------ C:\WINDOWS\system32\ieaksie.dll 2006-08-23 00:13 71680 --a------ C:\WINDOWS\system32\admparse.dll 2006-08-23 00:13 55296 --a------ C:\WINDOWS\system32\iesetup.dll 2006-08-23 00:13 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe 2006-08-23 00:13 43008 --a------ C:\WINDOWS\system32\iernonce.dll 2006-08-23 00:13 152064 --a------ C:\WINDOWS\system32\ieakeng.dll 2006-08-23 00:13 122880 --a------ C:\WINDOWS\system32\advpack.dll 2006-08-23 00:13 11776 --a------ C:\WINDOWS\system32\ieudinit.exe 2006-08-23 00:11 12288 --a------ C:\WINDOWS\system32\msfeedssync.exe 2006-08-23 00:10 61440 --a------ C:\WINDOWS\system32\icardie.dll 2006-08-23 00:10 35328 --a------ C:\WINDOWS\system32\imgutil.dll 2006-08-23 00:09 262656 --a------ C:\WINDOWS\system32\iertutil.dll 2006-08-23 00:07 45568 --a------ C:\WINDOWS\system32\mshta.exe 2006-08-22 23:37 48128 --a------ C:\WINDOWS\system32\mshtmler.dll 2006-08-22 23:36 380928 --a------ C:\WINDOWS\system32\ieapfltr.dll 2006-08-22 23:30 161792 --a------ C:\WINDOWS\system32\ieakui.dll 2006-08-21 08:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll 2006-08-21 05:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe 2006-08-16 16:53 1101904 --a------ C:\WINDOWS\vsapi32.dll 2006-08-16 07:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll 2006-08-10 19:46 22752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2006-08-10 19:03 73728 --a------ C:\WINDOWS\system32\dpl100.dll 2006-08-10 19:03 196608 --a------ C:\WINDOWS\system32\dtu100.dll 2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll 2006-07-27 13:28 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2006-07-27 09:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background" "LogitechSoftwareUpdate"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe" "IAAnotif"="C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\iaanotif.exe" "ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe" "CTSysVol"="C:\\Program Files\\Creative\\Sound Blaster Live! 24-bit\\Surround Mixer\\CTSysVol.exe /r" "UpdReg"="C:\\WINDOWS\\UpdReg.EXE" "DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\"" "ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup" "ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start" "DMXLauncher"="C:\\Program Files\\Dell\\Media Experience\\DMXLauncher.exe" "LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE" "LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe " "LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe" "Windows Media Connect 2"="\"C:\\Program Files\\Windows Media Connect 2\\WMCCFG.exe\" /StartQuiet" "dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe" "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "WatchDog"="C:\\Program Files\\mobile PhoneTools\\WatchDog.exe" "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" "{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] "strimo"="C:\\WINDOWS\\system32\\strimo.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\QuickBooks Update Agent.lnk" "backup"="C:\\WINDOWS\\pss\\QuickBooks Update Agent.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\COMMON~1\\Intuit\\QUICKB~1\\QBUpdate\\qbupdate.exe " "item"="QuickBooks Update Agent" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1pop06apelt2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="elitepop06" "hkey"="HKLM" "command"="C:\\WINDOWS\\elitepop06.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gjigddm.dll] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="gjigddm" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\gjigddm.dll,fywwrbd" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="msmsgs" "hkey"="HKCU" "command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "inimapping"="0" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\MP Scheduled Scan.job Completion time: 06-10-22 22:22:36.48 C:\ComboFix.txt ... 06-10-22 22:22 ------------------------------------------------------------------------- BIT DEFENDER: BitDefender Online Scanner Scan report generated at: Sun, Oct 22, 2006 - 23:29:37 Scan path: C:\;D:\;E:\; Statistics Time 00:49:44 Files 364136 Folders 5580 Boot Sectors 4 Archives 3885 Packed Files 39150 Results Identified Viruses 3 Infected Files 4 Suspect Files 0 Warnings 0 Disinfected 0 Deleted Files 4 Engines Info Virus Definitions 478195 Engine build AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38) Scan plugins 13 Archive plugins 38 Unpack plugins 6 E-mail plugins 6 System plugins 1 Scan Settings First Action Disinfect Second Action Delete Heuristics Yes Enable Warnings Yes Scanned Extensions *; Exclude Extensions Scan Emails Yes Scan Archives Yes Scan Packed Yes Scan Files Yes Scan Boot Yes Scanned File Status C:\Program Files\Microsoft AntiSpyware\Quarantine\426E7C38-3B99-44B8-A21A-5E828B\ED3C5295-3619-4E07-B224-3B441D Infected with: Generic.Istbar.8DC8186C C:\Program Files\Microsoft AntiSpyware\Quarantine\426E7C38-3B99-44B8-A21A-5E828B\ED3C5295-3619-4E07-B224-3B441D Disinfection failed C:\Program Files\Microsoft AntiSpyware\Quarantine\426E7C38-3B99-44B8-A21A-5E828B\ED3C5295-3619-4E07-B224-3B441D Deleted C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000020.exe Infected with: Trojan.Scapur.A C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000020.exe Disinfection failed C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000020.exe Deleted C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP40\A0000603.exe Infected with: Trojan.Scapur.A C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP40\A0000603.exe Disinfection failed C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP40\A0000603.exe Deleted C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP40\A0000604.dll Infected with: Generic.Istbar.613D71C1 C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP40\A0000604.dll Disinfection failed C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP40\A0000604.dll Deleted -------------------------------------------------------------------------- HIJACK THIS: Logfile of HijackThis v1.99.1 Scan saved at 11:34:00 PM, on 10/22/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5700.0006) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\wuauclt.exe C:\Hijack This\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Save Flash In This Page by Flash Saver - C:\PROGRA~1\FLASHS~1\save.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204 O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://pcpitstop.com/internet/pcpConnCheck.cab O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by101fd.bay101.hotmail.msn.co...s/MsnPUpld.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource...scbase5059.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1155453559312 O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - |