PDA

View Full Version : Smitfraud & Virtumond



Sensimillia
2007-11-21, 06:45
I've been trying to remove smitfraud for a few days now and it keeps coming back. Also while running spybot I noticed that I still had virtumond. Can anyone help me get rid of these? I have a Kaspersky log but it is rather long. Here is my HijackThis log file.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:08:45 PM, on 11/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Internet Tools\No-IP\DUC20.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Internet Tools\Proxomitron\Proxomitron.exe
C:\Program Files\Media Tools\VibeStreamer\vibestreamer.exe
C:\Program Files\System Tools\YPOPs\YPOPs.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Media Tools\Winamp\winamp.exe
C:\Program Files\Internet Tools\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\divxsm.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SYSTEM~1\Spybot\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O3 - Toolbar: The jokwmp - {6BA27973-068D-4F85-BE84-1251E0B20FD3} - C:\WINDOWS\jokwmp.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: The Proxomitron.lnk = C:\Program Files\Internet Tools\Proxomitron\Proxomitron.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: VibeStreamer.lnk = C:\Program Files\Media Tools\VibeStreamer\vibestreamer.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: YPOPs.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: The Proxomitron.lnk = C:\Program Files\Internet Tools\Proxomitron\Proxomitron.exe (User 'Default user')
O4 - .DEFAULT Startup: VibeStreamer.lnk = C:\Program Files\Media Tools\VibeStreamer\vibestreamer.exe (User 'Default user')
O4 - .DEFAULT Startup: YPOPs.lnk = ? (User 'Default user')
O4 - Startup: The Proxomitron.lnk = C:\Program Files\Internet Tools\Proxomitron\Proxomitron.exe
O4 - Startup: VibeStreamer.lnk = C:\Program Files\Media Tools\VibeStreamer\vibestreamer.exe
O4 - Startup: YPOPs.lnk = ?
O4 - Global Startup: SIGuardian.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZK
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Temp\Visual Route\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Temp\Visual Route\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Hermit\Start Menu\Programs\Internet Tools\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://pcpitstop.com/mhLbl.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{80B9B84C-AD4F-4B02-B154-01E8F3EDD4C5}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: nnnonkj - C:\WINDOWS\
O20 - Winlogon Notify: pmnnm - C:\WINDOWS\
O20 - Winlogon Notify: wingsa32 - C:\WINDOWS\
O21 - SSODL: sapnet - {8A4D1A75-0247-43A7-8693-DFA12D5CDC23} - C:\WINDOWS\sapnet.dll (file missing)
O21 - SSODL: rmvgor - {05E9BD4A-8B13-4DDA-8FAA-02093D0B7B7B} - C:\WINDOWS\rmvgor.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Fastream IQ Web/FTP Server (NFService) - Fastream Technologies - C:\PROGRA~1\FASTRE~2\IQWebFTPServerEngine.exe
O23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\Internet Tools\No-IP\DUC20.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

--
End of file - 9660 bytes

Sensimillia
2007-11-21, 07:12
The Antivirus log is not as long as I thought, it will fit within 2 posts.

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, November 20, 2007 10:22:06 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/11/2007
Kaspersky Anti-Virus database records: 462474
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
F:\
I:\
J:\
K:\
L:\
M:\

Scan Statistics:
Total number of scanned objects: 179951
Number of viruses found: 18
Number of infected objects: 57
Number of suspicious objects: 2
Duration of the scan process: 04:23:45

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{15F4486D-A4B4-4A46-8ADA-982EF397B85A}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{260CA5F5-B1C9-4287-ABE4-EB8BBABA4B6D}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{260CA5F5-B1C9-4287-ABE4-EB8BBABA4B6D}.log-journal Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{42FA5E83-3B80-4344-BDAD-60C14DC659E5}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR1.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\SecTaskMan\popnetmtq.dll.q_2CF1004_q Infected: not-a-virus:AdWare.Win32.Vapsup.nc skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\YazzleSudoku.zip/Yazzle1162OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\YazzleSudoku.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Hermit\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\cert8.db Object is locked skipped
C:\Documents and Settings\Hermit\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Hermit\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\history.dat Object is locked skipped
C:\Documents and Settings\Hermit\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\key3.db Object is locked skipped
C:\Documents and Settings\Hermit\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\parent.lock Object is locked skipped
C:\Documents and Settings\Hermit\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Hermit\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Hermit\Desktop\backups\backup-20071119-211644-258.dll Infected: not-a-virus:AdWare.Win32.Vapsup.nc skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\framework-3.0_exe.vir/stream/data5279 Infected: not-a-virus:RemoteAdmin.Win32.NetCat skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\framework-3.0_exe.vir/stream/data5283 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\framework-3.0_exe.vir/stream Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\framework-3.0_exe.vir NSIS: infected - 3 skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\Possible Infection\SQLPing2.CAB/MSVBVM60.DLL Infected: HackTool.Win32.SQLScan.25 skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\Possible Infection\SQLPing2.CAB CAB: infected - 1 skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\Possible Infection\sqlping2.zip/SQLPing2.CAB/MSVBVM60.DLL Infected: HackTool.Win32.SQLScan.25 skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\Possible Infection\sqlping2.zip/SQLPing2.CAB Infected: HackTool.Win32.SQLScan.25 skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\Possible Infection\sqlping2.zip ZIP: infected - 2 skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\rainbowcrack-1.2-win.zip/rainbowcrack-1.2-win/rcrack.exe Infected: not-a-virus:PSWTool.Win32.Rainbow.12.a skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\rainbowcrack-1.2-win.zip/rainbowcrack-1.2-win/rtdump.exe Infected: not-a-virus:PSWTool.Win32.Rainbow.12.a skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\rainbowcrack-1.2-win.zip/rainbowcrack-1.2-win/rtgen.exe Infected: not-a-virus:PSWTool.Win32.Rainbow.12.a skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\rainbowcrack-1.2-win.zip/rainbowcrack-1.2-win/rtsort.exe Infected: not-a-virus:PSWTool.Win32.Rainbow.12.a skipped
C:\Documents and Settings\Hermit\Desktop\Hacking Tools 2007\rainbowcrack-1.2-win.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Hermit\Desktop\Nero-6.6.1.15d_wch.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\Hermit\Desktop\Nero-6.6.1.15d_wch.exe RAR: infected - 1 skipped
C:\Documents and Settings\Hermit\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Hermit\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Hermit\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Hermit\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Hermit\Desktop\SORT THIS FOLDER!\setup_exe.vir/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.buq skipped
C:\Documents and Settings\Hermit\Desktop\SORT THIS FOLDER!\setup_exe.vir/stream Infected: Trojan-Downloader.Win32.Zlob.buq skipped
C:\Documents and Settings\Hermit\Desktop\SORT THIS FOLDER!\setup_exe.vir NSIS: infected - 2 skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Microsoft\Messenger\fry057@hotmail.com\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Microsoft\Messenger\fry057@hotmail.com\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Microsoft\Messenger\fry057@hotmail.com\SharingMetadata\Working\database_D6C4_E959_C4E9_3C7D\dfsr.db Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Microsoft\Messenger\fry057@hotmail.com\SharingMetadata\Working\database_D6C4_E959_C4E9_3C7D\fsr.log Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Microsoft\Messenger\fry057@hotmail.com\SharingMetadata\Working\database_D6C4_E959_C4E9_3C7D\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Microsoft\Messenger\fry057@hotmail.com\SharingMetadata\Working\database_D6C4_E959_C4E9_3C7D\tmp.edb Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Microsoft\Windows Live Contacts\fry057@hotmail.com\real\members.stg Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Microsoft\Windows Live Contacts\fry057@hotmail.com\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\Cache\AE208952d01 Infected: not-virus:Hoax.Win32.Renos.rz skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Application Data\Mozilla\Firefox\Profiles\kyro8y6o.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\History\History.IE5\MSHist012007112020071121\index.dat Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Temp\~DF501D.tmp Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Temp\~DF505D.tmp Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Temp\~DFB9FA.tmp Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Temp\~DFBA0A.tmp Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Temp\~DFDFAC.tmp Object is locked skipped

Sensimillia
2007-11-21, 07:13
C:\Documents and Settings\Hermit\Local Settings\Temp\~DFF521.tmp Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Temp\~ROMFN_000008E8 Object is locked skipped
C:\Documents and Settings\Hermit\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hermit\My Documents\Downloads\Antivirus\AVG Anti-Virus Professional Edition 7.5.488 + Keygen\AVG Anti-Virus Professional Edition 7.5.488 + Keygen.rar/avg.7.5.x_keygen.exe Infected: Trojan.Win32.Pakes.de skipped
C:\Documents and Settings\Hermit\My Documents\Downloads\Antivirus\AVG Anti-Virus Professional Edition 7.5.488 + Keygen\AVG Anti-Virus Professional Edition 7.5.488 + Keygen.rar RAR: infected - 1 skipped
C:\Documents and Settings\Hermit\My Documents\Downloads\Real VNC Enterprise Edition v4.1.9 Including Keygen\setup.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\Hermit\My Documents\Downloads\Real VNC Enterprise Edition v4.1.9 Including Keygen\setup.exe Inno: infected - 1 skipped
C:\Documents and Settings\Hermit\ntuser.dat Object is locked skipped
C:\Documents and Settings\Hermit\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\Hermit\Tools\rcrack\rcrack.exe Object is locked skipped
C:\Documents and Settings\Hermit\Tools\rcrack\rtdump.exe Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Hacking\MetasploitF3\Framework3\framework\lib\rex\exploitation\.svn\text-base\heaplib.js.svn-base Infected: Trojan-Downloader.JS.Agent.gj skipped
C:\Program Files\Hacking\MetasploitF3\Framework3\framework\lib\rex\exploitation\heaplib.js Infected: Trojan-Downloader.JS.Agent.gj skipped
C:\Program Files\Hacking\MetasploitF3\Framework3\tools\nc.exe Infected: not-a-virus:RemoteAdmin.Win32.NetCat skipped
C:\Program Files\Hacking\MetasploitF3\Framework3\tools\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\Hacking\MetasploitF3\tools\nc.exe Infected: not-a-virus:RemoteAdmin.Win32.NetCat skipped
C:\Program Files\Hacking\MetasploitF3\tools\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\Internet Tools\Blocklist Manager\Tools\ipscan.exe Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Internet Tools\Mozilla Firefox\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Program Files\Internet Tools\No-IP\Service.log Object is locked skipped
C:\Program Files\MSN Messenger\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Program Files\MSN Messenger\riched20.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Program Files\System Tools\YPOPs\ypops.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP110\A0030874.exe/mwsSetup.CommonCodebase.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP110\A0030874.exe CAB: infected - 1 skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP148\A0050023.exe Object is locked skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP151\A0050264.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053128.exe/stream/data5279 Infected: not-a-virus:RemoteAdmin.Win32.NetCat skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053128.exe/stream/data5283 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053128.exe/stream Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053128.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053129.exe/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.buq skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053129.exe/stream Infected: Trojan-Downloader.Win32.Zlob.buq skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053129.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053130.exe Object is locked skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053131.exe Object is locked skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053132.exe Object is locked skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053133.dll Object is locked skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP160\A0053134.dll Object is locked skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP190\A0059144.dll Infected: not-a-virus:AdWare.Win32.Vapsup.nc skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP195\A0059166.exe Object is locked skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP195\A0059167.exe Object is locked skipped
C:\System Volume Information\_restore{C26E0085-2813-4872-B37A-0B5DA8F2F53E}\RP195\change.log Object is locked skipped
C:\temp\crack.exe/stream/data0003 Infected: Trojan-Downloader.Win32.Zlob.ekb skipped
C:\temp\crack.exe/stream Infected: Trojan-Downloader.Win32.Zlob.ekb skipped
C:\temp\crack.exe NSIS: infected - 2 skipped
C:\temp\rar password cracker\crack.exe/stream/data0003 Infected: Trojan-Downloader.Win32.Zlob.ekb skipped
C:\temp\rar password cracker\crack.exe/stream Infected: Trojan-Downloader.Win32.Zlob.ekb skipped
C:\temp\rar password cracker\crack.exe NSIS: infected - 2 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{7812C6F7-F348-451B-9515-DEDCEEA03D05}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcafee_2UGxSdECJt29E7g Object is locked skipped
C:\WINDOWS\Temp\mcafee_qXJnSYHeLFgtRjC Object is locked skipped
C:\WINDOWS\Temp\mcmsc_4UprkF37rfw5ouq Object is locked skipped
C:\WINDOWS\Temp\mcmsc_dx5tnjrQxj5d4NW Object is locked skipped
C:\WINDOWS\Temp\mcmsc_eBG426j8iCGQcD7 Object is locked skipped
C:\WINDOWS\Temp\mcmsc_eBG426j8iCGQcD7-journal Object is locked skipped
C:\WINDOWS\Temp\mcmsc_FCuWSL4ifHztjLd Object is locked skipped
C:\WINDOWS\Temp\mcmsc_gY8wzdrXbvtmLCs Object is locked skipped
C:\WINDOWS\Temp\mcmsc_nODViEWur0XIYUn Object is locked skipped
C:\WINDOWS\Temp\mcmsc_yzlvESOKWRadoPR Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{F1544A30-F2B7-4D4F-B6BB-E3F400611EDF}\RP386\A0149527.exe Object is locked skipped

Scan process completed.

Sensimillia
2007-12-02, 07:19
Just though I let everyone know that I no longer believe I have these problems. I don't know why they are gone (maybe Macafee fixed it). So no need to look at these logs. Thanks everyone!