PDA

View Full Version : Virtumonde and logs



john126
2007-12-24, 03:17
Been running counterspy, spybot and adware se but virtumonde is showing up. Below is hijack log and kaspersky log in next message.

Sincere & grateful thanks in advance.

John126

************

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:44:24 PM, on 12/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\S24EvMon.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\System32\DWRCS.EXE
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\System32\QCONSVC.EXE
C:\WINNT\System32\RegSrvc.exe
C:\WINNT\System32\RoamMgr.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\program files\Safeguard Easy\SafeGuard Easy\SgeCtl.exe
C:\WINNT\System32\SgLogPlayer.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\TpKmpSVC.exe
C:\WINNT\system32\ZCfgSvc.exe
C:\WINNT\System32\DWRCST.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\System32\1XConfig.exe
C:\WINNT\Logi_MwX.Exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINNT\System32\TpScrLk.exe
C:\WINNT\system32\TpShocks.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINNT\system32\RunDll32.exe
C:\WINNT\system32\rundll32.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\winnt\perl5\bin\PERL.EXE
C:\WINNT\system32\NWTRAY.EXE
C:\program files\Safeguard Easy\SafeGuard Easy\Ecview.exe
C:\WINNT\system32\ICO.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\FSRremoS.EXE
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\program files\Safeguard Easy\SafeGuard Easy\WKSCFGSRV.EXE
C:\Program Files\Quick ShutDown\qsd.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\WINNT\Explorer.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\WINNT\PCHealth\HelpCtr\Binaries\helpctr.exe
C:\WINNT\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINNT\PCHealth\HelpCtr\Binaries\HelpHost.exe
C:\WINNT\system32\cmd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by its.on
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [0AI_Run] guiperl.exe C:\SCRIPTS\0AI_Run.pl
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] "C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TPKBDLED] C:\WINNT\System32\TpScrLk.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\Thinkpad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] "C:\Program Files\Thinkpad\Utilities\BMMLREF.EXE"
O4 - HKLM\..\Run: [BMMMONWND] "rundll32.exe" C:\PROGRA~1\Thinkpad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPKMAPHELPER] "C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [Checklogon] C:\scripts\checklogon.pl
O4 - HKLM\..\Run: [SAPSETUP_PENDING_INST] "\\is1519.applications.degussanet.com\daten$\sapserver\en\gui.640c2\setup\sapsetup.exe" /p /continue /log:append
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [SgeEcView] "C:\program files\Safeguard Easy\SafeGuard Easy\Ecview.exe"
O4 - HKLM\..\Run: [EdWizard] "C:\program files\Safeguard Easy\SafeGuard Easy\EdWizard.exe" as
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKLM\..\Run: [8cac6c8a] rundll32.exe "C:\WINNT\system32\bffbhnuq.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Quick ShutDown.lnk = C:\Program Files\Quick ShutDown\qsd.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office Shortcut-Bar.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINNT\System32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\PROGRA~1\WebEx\WebEx\350\atonecli.dll (HKCU)
O9 - Extra 'Tools' menuitem: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\PROGRA~1\WebEx\WebEx\350\atonecli.dll (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://home.intranet.degussa.com/
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198283879246
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://degussa.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dhna.americas.degussa.com
O17 - HKLM\Software\..\Telephony: DomainName = dhna.americas.degussa.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dhna,degussa.com,mail.degussa.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dhna.americas.degussa.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = DHNA,degussa.com,mail.degussa.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = DHNA,degussa.com,mail.degussa.com
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AutoExNT - Unknown owner - C:\WINNT\system32\AutoExNT.Exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\System32\cusrvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\System32\DWRCS.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - C:\WINNT\SYSTEM32\LxrSG20s.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINNT\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINNT\System32\RegSrvc.exe
O23 - Service: RoamMgr - Intel Corporation - C:\WINNT\System32\RoamMgr.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINNT\System32\S24EvMon.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: SafeGuard Easy Control (SgeCtl) - Utimaco Safeware AG - C:\program files\Safeguard Easy\SafeGuard Easy\SgeCtl.exe
O23 - Service: SafeGuard SGLOG Player (SgLogPlayer) - Utimaco Safeware AG - C:\WINNT\System32\SgLogPlayer.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINNT\system32\TpKmpSVC.exe

--
End of file - 12311 bytes

john126
2007-12-24, 03:19
Kaspersky log

***************

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, December 23, 2007 8:12:46 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 24/12/2007
Kaspersky Anti-Virus database records: 492659
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
R:\

Scan Statistics:
Total number of scanned objects: 84356
Number of viruses found: 11
Number of infected objects: 21
Number of suspicious objects: 10
Duration of the scan process: 01:14:34

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_EMERSON0.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_EMERSON0.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdBreak21.zip/wbeInst$.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdBreak21.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdBreak4.zip/kvnab$.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdBreak4.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/vxddsk.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip/vxddsk.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1552OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\wnekj\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-3c602653-715b867c.zip/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\wnekj\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-3c602653-715b867c.zip ZIP: infected - 1 skipped
C:\Documents and Settings\wnekj\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-7cd0f8d4-4af46631.zip/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\wnekj\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-7cd0f8d4-4af46631.zip ZIP: infected - 1 skipped
C:\Documents and Settings\wnekj\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv570.jar-27053261-2b8311b1.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped
C:\Documents and Settings\wnekj\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv570.jar-27053261-2b8311b1.zip/Counter.class Infected: Trojan.Java.ClassLoader.h skipped
C:\Documents and Settings\wnekj\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv570.jar-27053261-2b8311b1.zip/Parser.class Infected: Trojan.Java.ClassLoader.d skipped
C:\Documents and Settings\wnekj\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv570.jar-27053261-2b8311b1.zip ZIP: infected - 3 skipped
C:\Documents and Settings\wnekj\ntuser.dat Object is locked skipped
C:\Documents and Settings\wnekj\NTUSER.DAT.LOG Object is locked skipped
C:\System Volume Information\_restore{7AD5ED1B-7DFF-494F-A488-394D62923E70}\RP604\A0206947.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{7AD5ED1B-7DFF-494F-A488-394D62923E70}\RP606\change.log Object is locked skipped
C:\TEMP\DB7.tmp/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\TEMP\DB7.tmp NSIS: infected - 1 skipped
C:\TEMP\DBC.tmp/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\TEMP\DBC.tmp/stream/data0002 Infected: not-a-virus:AdWare.Win32.AdBand.e skipped
C:\TEMP\DBC.tmp/stream Infected: not-a-virus:AdWare.Win32.AdBand.e skipped
C:\TEMP\DBC.tmp NSIS: infected - 3 skipped
C:\TEMP\iwatch.lck Object is locked skipped
C:\TEMP\Perflib_Perfdata_a0c.dat Object is locked skipped
C:\TEMP\~DF3EDD.tmp Object is locked skipped
C:\TEMP\~DF7C7F.tmp Object is locked skipped
C:\TEMP\~DF7D38.tmp Object is locked skipped
C:\TEMP\~DFF5CA.tmp Object is locked skipped
C:\TEMP\~DFF617.tmp Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\6to4svc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\inetmib1.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\iphlpapi.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\ipv6.exe Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\ipv6mon.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\netoc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\netsh.exe Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\tcpip6.sys Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\tunmp.sys Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\ws2_32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\wship6.dll Object is locked skipped
C:\WINNT\$NtUninstallKB818332$\serenum.sys Object is locked skipped
C:\WINNT\$NtUninstallKB824105$\netbt.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\accwiz.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\crypt32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\cryptsvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\hh.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\hhctrl.ocx Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\hhsetup.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\html32.cnv Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\itircl.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\itss.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\locator.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\magnify.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\migwiz.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\mrxsmb.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\msconv97.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\narrator.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\newdev.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\ntdll.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\ntkrnlpa.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\ntoskrnl.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\osk.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\pchshell.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\raspptp.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\shdocvw.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\shmedia.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\srrstr.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\srv.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\urlmon.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\user32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\win32k.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\winsrv.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\zipfldr.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\dhcpcsvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\ndis.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\ndisuio.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\netshell.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\wzcdlg.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\wzcsapi.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\wzcsvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\colbact.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comuid.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\es.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\ole32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\txflog.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\dao360.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\expsrv.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msexch40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msexcl40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjet40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjetol1.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjetoledb40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjint40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjter40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjtes40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msltus40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\mspbde40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msrd2x40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msrd3x40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msrepl40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\mstext40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\mswdat10.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\mswstr10.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msxbde40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\vbajet32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB833330$\Blastcln\blastcln.exe Object is locked skipped
C:\WINNT\$NtUninstallKB833987$\sxs.dll Object is locked skipped
C:\WINNT\$NtUninstallKB833998$\shell32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB833998$\sxs.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\dao360.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjet40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjetol1.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped
C:\WINNT\$NtUninstallQ322011$\fxsclnt.exe Object is locked skipped
C:\WINNT\$NtUninstallQ814995$\acgenral.dll Object is locked skipped
C:\WINNT\$NtUninstallQ814995$\apphelp.sdb Object is locked skipped
C:\WINNT\$NtUninstallQ814995$\apph_sp.sdb Object is locked skipped
C:\WINNT\$NtUninstallQ814995$\apps_sp.chm Object is locked skipped
C:\WINNT\$NtUninstallQ814995$\sysmain.sdb Object is locked skipped
C:\WINNT\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\Netlogon.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Internet Logs\tvDebug.log Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\WINNT\SoftwareDistribution\EventCache\{5FBA2DCD-A049-4937-907D-B26C999A9C81}.bin Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\system32\aoisemdd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\WINNT\system32\CatRoot2\edb.log Object is locked skipped
C:\WINNT\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\Internet.evt Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\system.LOG Object is locked skipped
C:\WINNT\system32\dkrjrolx.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\WINNT\system32\h323log.txt Object is locked skipped
C:\WINNT\system32\jpygjofl.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\WINNT\system32\mewrvwjm.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\WINNT\system32\nmevnfmo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINNT\Temp\Perflib_Perfdata_6e8.dat Object is locked skipped
C:\WINNT\Temp\~DF6781.tmp Object is locked skipped
C:\WINNT\Temp\~DF6846.tmp Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{7AD5ED1B-7DFF-494F-A488-394D62923E70}\RP606\change.log Object is locked skipped
D:\users\wnekj\Cookies\index.dat Object is locked skipped
D:\users\wnekj\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
D:\users\wnekj\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\users\wnekj\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\users\wnekj\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\users\wnekj\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
D:\users\wnekj\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\users\wnekj\Local Settings\Temporary Internet Files\Content.IE5\KQLNRG6V\gamadril20071203[1] Infected: Backdoor.Win32.Agent.dbm skipped

Scan process completed.

pskelley
2007-12-24, 17:37
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

HJT is not showing much but Kaspersky is showing a bunch of junk.
You have a Vundo infection which can be hard to remove. This will take some time and unless you are patient, understand how to follow directions and are comfortable working on your computer, you may want to seek local professional help. If you wish to proceed, read and follow the directions carefully.

Kaspersky:

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ <<< empty the Recovery folder
http://ict.cas.psu.edu/training/howto/util/removespybot.htm#1

C:\Documents and Settings\wnekj\Application Data\Sun\Java\Deployment\cache\ <<< clean the infected Java cache
http://support.f-secure.com/enu/home/virusproblem/howtoclean/cleanjavacache.shtml

Please keep the computer offline except when troubleshooting, this junk can morph and it can download more. I understand we are in the middle of holidays, so repond to the directions when you can. Please read and follow them carefully, the tools will not work unless you do.

We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:
* Run Spybot-S&D in Advanced Mode.
* If it is not already set to do this Go to the Mode menu select "Advanced Mode"
* On the left hand side, Click on Tools
* Then click on the Resident Icon in the List
* Uncheck "Resident TeaTimer" and OK any prompts.
* Restart your computer.

1) Thanks to Atribune and any others who helped with this fix.

http://vundofix.atribune.org/ <<< tutorial

"Download VundoFix" to your Desktop

http://www.atribune.org/ccount/click.php?id=4

Double-click VundoFix.exe to run it.
When VundoFix opens, click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will attempt run on reboot, simply follow the above instructions starting from "Click
the Scan for Vundo button." when VundoFix appears at reboot. Vundofix.txt will be on the C:\

(wait until you finish to post reports and logs)

2) Thanks to sUBs and anyone else who helped with this fix.

Download ComboFix from Here (http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe) or Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop

Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply

Note: Do not mouseclick combofix's window while its running. That may cause it to stall

Post the Vundofix.txt, combofix log and a new HJT log.

Thanks

john126
2007-12-24, 21:22
Thanks for the help-

I could not locate a recovery folder to empty for instruction-C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ <<< empty the Recovery folder-- and the link did not work.

If it is ok I will proceed with the rest of your instruction.

Will not post again until late tomorrow.

John

pskelley
2007-12-24, 21:32
The website must be down, do it this way...may be slightly different with 1.5.
Open Spybot S&D > Click on the the white case with the red cross > check all items and Purge them.

Thanks

http://www.bleepingcomputer.com/tutorials/tutorial43.html#restore

john126
2007-12-25, 18:39
Happy Holidays – able to run the scans and get this out of the way. The logs are below or in the following posts.


John126

************************************************
VundoFix V6.7.7

Checking Java version...

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Scan started at 8:42:51 PM 12/22/2007

Listing files found while scanning....

C:\WINNT\System32\byxxwvw.dll

Beginning removal...

Performing Repairs to the registry.
Done!

VundoFix V6.7.7

Checking Java version...

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Scan started at 8:17:37 AM 12/25/2007

Listing files found while scanning....

No infected files were found.

***************
ComboFix 07-12-21.4 - wnekj 2007-12-25 8:35:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.123 [GMT -5:00]
Running from: D:\users\wnekj\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\wnekj\g2mdlhlpx.exe
C:\WINNT\absolute key logger.lnk
C:\WINNT\aconti.exe
C:\WINNT\aconti.log
C:\WINNT\acontidialer.txt
C:\WINNT\adbar.dll
C:\WINNT\daxtime.dll
C:\WINNT\dp0.dll
C:\WINNT\eventlowg.dll
C:\WINNT\fhfmm-Uninstaller.exe
C:\WINNT\hotporn.exe
C:\WINNT\ie_32.exe
C:\WINNT\jd2002.dll
C:\WINNT\kkcomp$.exe
C:\WINNT\liqad$.exe
C:\WINNT\liqui-Uninstaller.exe
C:\WINNT\ngd.dll
C:\WINNT\spredirect.dll
C:\WINNT\system32\aoisemdd.dll
C:\WINNT\system32\bffbhnuq.dll
C:\WINNT\system32\cvseywfo.dll
C:\WINNT\system32\ddmesioa.ini
C:\WINNT\system32\din.ip
C:\WINNT\system32\djgswnaj.dll
C:\WINNT\system32\dkrjrolx.dll
C:\WINNT\system32\dpqaqlqx.bin
C:\WINNT\system32\drivers\cell_bg.gif
C:\WINNT\system32\drivers\cell_footer.gif
C:\WINNT\system32\drivers\cell_header_block.gif
C:\WINNT\system32\drivers\cell_header_remove.gif
C:\WINNT\system32\drivers\cell_header_scan.gif
C:\WINNT\system32\drivers\download_btn.jpg
C:\WINNT\system32\drivers\download_now_btn.gif
C:\WINNT\system32\drivers\header_2.gif
C:\WINNT\system32\drivers\header_red_bg.gif
C:\WINNT\system32\drivers\header_red_free_scan.gif
C:\WINNT\system32\drivers\header_red_free_scan_bg.gif
C:\WINNT\system32\drivers\header_red_protect_your_pc.gif
C:\WINNT\system32\drivers\rating.gif
C:\WINNT\system32\drivers\screenshot.jpg
C:\WINNT\system32\drivers\shadow_bg.gif
C:\WINNT\system32\drivers\spacer.gif
C:\WINNT\system32\drivers\star_small.gif
C:\WINNT\system32\drivers\style.css
C:\WINNT\system32\ESHOPEE.exe
C:\WINNT\system32\hbrptyll.dll
C:\WINNT\system32\instsrv.exe
C:\WINNT\system32\jpygjofl.dll
C:\WINNT\system32\llytprbh.ini
C:\WINNT\system32\mewrvwjm.dll
C:\WINNT\system32\mnnmp.ini
C:\WINNT\system32\mnnmp.ini2
C:\WINNT\system32\nmcxejtw.ini
C:\WINNT\system32\nmevnfmo.dll
C:\WINNT\system32\nsowxema.dll
C:\WINNT\system32\omfnvemn.ini
C:\WINNT\system32\pmnnm.dll
C:\WINNT\system32\qunhbffb.ini
C:\WINNT\system32\stfv.bin
C:\WINNT\system32\sznf.ascii
C:\WINNT\system32\wtjexcmn.dll
C:\WINNT\vxddsk.exe
C:\WINNT\xadbrk_.exe
C:\WINNT\xxxvideo.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_DOMAINSERVICE


((((((((((((((((((((((((( Files Created from 2007-11-25 to 2007-12-25 )))))))))))))))))))))))))))))))
.

2007-12-25 08:52 . 2007-12-25 08:52 16,384 --a----t- C:\TEMP\Perflib_Perfdata_df4.dat
2007-12-25 08:52 . 2007-12-25 08:52 16,384 --a----t- C:\TEMP\Perflib_Perfdata_ca4.dat
2007-12-25 08:42 . 2007-12-25 08:42 53,248 --a------ C:\TEMP\tffglexq.dll
2007-12-23 18:01 . 2007-12-23 18:33 <DIR> d-------- C:\TEMP\KAV Updater update files
2007-12-23 18:01 . 2007-12-23 18:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-23 18:00 . 2007-12-23 18:00 <DIR> d-------- C:\WINNT\system32\Kaspersky Lab
2007-12-23 17:42 . 2007-12-23 17:42 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-23 09:32 . 2007-12-23 09:33 <DIR> d-------- C:\Program Files\RogueRemover FREE
2007-12-22 20:58 . 2007-12-22 20:58 16,384 --a----t- C:\TEMP\Perflib_Perfdata_a0c.dat
2007-12-22 20:42 . 2007-12-25 08:16 <DIR> d-------- C:\VundoFix Backups
2007-12-22 19:37 . 2007-12-22 19:38 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-12-22 16:39 . 2007-12-22 16:39 16,384 --a----t- C:\TEMP\Perflib_Perfdata_8b4.dat
2007-12-22 16:39 . 2007-12-22 16:39 16,384 --a----t- C:\TEMP\Perflib_Perfdata_434.dat
2007-12-22 08:11 . 2007-12-22 08:11 2,572 --a------ C:\WINNT\system32\PerfStringBackup.TMP
2007-12-22 07:50 . 2007-12-22 07:50 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-12-22 07:36 . 2006-08-21 04:14 128,896 -----c--- C:\WINNT\system32\dllcache\fltmgr.sys
2007-12-22 07:36 . 2006-08-21 04:14 23,040 -----c--- C:\WINNT\system32\dllcache\fltmc.exe
2007-12-22 07:36 . 2006-08-21 07:21 16,896 -----c--- C:\WINNT\system32\dllcache\fltlib.dll
2007-12-22 01:30 . 2007-12-22 01:30 <DIR> d-------- C:\WINNT\LastGood(2)
2007-12-21 22:13 . 2007-07-09 08:09 584,192 -----c--- C:\WINNT\system32\dllcache\rpcrt4.dll
2007-12-21 20:24 . 2007-12-21 20:24 <DIR> d-------- C:\WINNT\provisioning
2007-12-21 20:19 . 2007-12-21 20:19 <DIR> d-------- C:\WINNT\ServicePackFiles
2007-12-21 20:05 . 2007-12-21 20:05 <DIR> d-------- C:\WINNT\EHome
2007-12-21 19:58 . 2002-04-15 21:11 67,866 --------- C:\WINNT\system32\drivers\netwlan5.img
2007-12-21 19:58 . 2004-08-04 00:56 11,776 --a------ C:\WINNT\system32\spnpinst.exe
2007-12-21 19:58 . 2004-08-02 14:20 7,208 --a------ C:\WINNT\system32\secupd.sig
2007-12-21 19:58 . 2004-08-02 14:20 4,569 --a------ C:\WINNT\system32\secupd.dat
2007-12-21 19:38 . 2007-07-30 19:18 34,136 --a------ C:\WINNT\system32\wucltui.dll.mui
2007-12-21 19:38 . 2007-07-30 19:19 25,944 --a------ C:\WINNT\system32\wuaucpl.cpl.mui
2007-12-21 19:38 . 2007-07-30 19:19 25,944 --a------ C:\WINNT\system32\wuapi.dll.mui
2007-12-21 19:38 . 2007-07-30 19:18 20,312 --a------ C:\WINNT\system32\wuaueng.dll.mui
2007-12-21 11:26 . 2007-12-21 11:26 16,384 --a----t- C:\TEMP\Perflib_Perfdata_1fd4.dat
2007-12-21 09:57 . 2007-12-22 08:10 534 --ahs---- C:\WINNT\system32\djielmlh.ini
2007-12-20 10:32 . 2007-12-20 10:32 16,384 --a----t- C:\TEMP\Perflib_Perfdata_728.dat
2007-12-20 08:25 . 2007-12-20 08:25 15,544 --a------ C:\WINNT\system32\drivers\sbhr.sys
2007-12-18 21:57 . 2007-12-18 21:57 0 --a------ C:\WINNT\system32\SBRC.dat
2007-12-18 21:57 . 2007-12-18 21:57 0 --a------ C:\WINNT\system32\SBFC.dat
2007-12-18 21:34 . 2007-12-18 21:34 <DIR> d-------- C:\Documents and Settings\wnekj\Application Data\Sunbelt Software
2007-12-18 21:34 . 2007-12-18 21:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software
2007-12-18 21:32 . 2007-12-18 21:32 <DIR> d-------- C:\Program Files\Sunbelt Software
2007-12-18 15:04 . 2007-12-18 15:04 263 --a------ C:\TEMP\install.dat
2007-12-18 14:55 . 2007-12-18 14:55 <DIR> d-------- C:\TEMP\temp.frFC88
2007-12-18 14:55 . 2007-12-18 14:55 <DIR> d-------- C:\TEMP\temp.fr473E
2007-12-18 12:11 . 2007-12-18 12:11 16,384 --a----t- C:\TEMP\Perflib_Perfdata_f84.dat
2007-12-18 12:03 . 2007-12-18 12:03 <DIR> d-------- C:\WINNT\Google Toolbar
2007-12-18 11:38 . 2007-12-18 11:38 <DIR> d-------- C:\TEMP\temp.frF739
2007-12-18 11:38 . 2007-12-18 11:38 <DIR> d-------- C:\TEMP\temp.fr0835
2007-12-18 10:23 . 2007-12-18 10:23 16,384 --a----t- C:\TEMP\Perflib_Perfdata_fa0.dat
2007-12-18 10:23 . 2007-12-18 10:23 16,384 --a----t- C:\TEMP\Perflib_Perfdata_1f4.dat
2007-12-18 09:30 . 2007-12-18 09:30 16,384 --a----t- C:\TEMP\Perflib_Perfdata_d30.dat
2007-12-18 09:30 . 2007-12-18 09:30 16,384 --a----t- C:\TEMP\Perflib_Perfdata_b6c.dat
2007-12-18 09:27 . 2007-12-18 09:27 <DIR> d-------- C:\Documents and Settings\wnekj\Application Data\Lavasoft
2007-12-18 09:20 . 2007-12-18 09:20 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-18 09:19 . 2004-10-12 11:14 57,344 --a------ C:\TEMP\InstHelp.dll
2007-12-18 09:15 . 2007-12-18 09:15 <DIR> d-------- C:\Documents and Settings\wnekj\Application Data\U3
2007-12-17 21:42 . 2007-12-18 10:13 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-17 21:37 . 2007-12-18 09:24 <DIR> d-------- C:\TEMP\~nsu.tmp
2007-12-17 21:30 . 2007-12-18 09:21 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-17 21:29 . 2007-12-17 21:29 <DIR> d-------- C:\WINNT\system32\runtime
2007-12-17 21:12 . 2007-12-17 21:30 <DIR> d-------- C:\Program Files\amsys(3)
2007-12-17 21:12 . 2007-12-17 21:30 <DIR> d-------- C:\Program Files\akl(3)
2007-12-17 18:16 . 2007-12-17 18:16 16,384 --a----t- C:\TEMP\Perflib_Perfdata_81c.dat
2007-12-17 09:14 . 2007-12-22 16:33 143 --a------ C:\WINNT\system32\mcrh.tmp
2007-12-16 20:20 . 2007-12-22 19:28 148 --a------ C:\WINNT\wininit.ini
2007-12-16 19:38 . 2007-12-22 20:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-16 13:51 . 2007-12-16 13:54 <DIR> d-------- C:\TEMP\is-Q8028.tmp
2007-12-16 13:51 . 2005-09-23 08:29 626,688 --a------ C:\WINNT\system32\msvcr80.dll
2007-12-15 22:26 . 2007-12-15 22:26 4 --a------ C:\WINNT\system32\jpewocmz.ini
2007-12-15 11:31 . 2007-12-15 11:31 <DIR> d-------- C:\TEMP\WER73.tmp.dir00
2007-12-15 11:31 . 2007-12-15 11:31 <DIR> d-------- C:\TEMP\WER72.tmp.dir00
2007-12-15 11:31 . 2007-12-15 11:31 <DIR> d-------- C:\TEMP\WER71.tmp.dir00
2007-12-15 11:07 . 2007-12-15 11:07 16,384 --a----t- C:\TEMP\Perflib_Perfdata_ba4.dat
2007-12-13 22:31 . 2007-12-13 22:31 16,384 --a----t- C:\TEMP\Perflib_Perfdata_f68.dat
2007-12-12 12:58 . 2007-12-12 12:58 16,384 --a----t- C:\TEMP\Perflib_Perfdata_8bc.dat
2007-12-06 00:04 . 2007-12-06 00:04 16,384 --a----t- C:\TEMP\Perflib_Perfdata_9b8.dat
2007-12-06 00:04 . 2007-12-06 00:04 16,384 --a----t- C:\TEMP\Perflib_Perfdata_9b0.dat
2007-12-02 07:36 . 2007-12-02 07:36 16,384 --a----t- C:\TEMP\Perflib_Perfdata_5fc.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-18 17:08 --------- d-----w C:\Program Files\Google
2007-12-18 14:38 --------- d-----w C:\Program Files\AccessManager
2007-12-18 14:37 --------- d-----w C:\Program Files\SmartPipes
2007-12-18 02:37 --------- d-----w C:\Program Files\Common Files\Real
2007-12-17 16:06 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-13 10:25 20,480 ----a-w C:\WINNT\system32\drivers\secdrv.sys
2007-11-09 12:32 69,920 ----a-w C:\WINNT\system32\drivers\LxrSG20d.sys
2007-11-07 02:08 --------- d-----w C:\Documents and Settings\wnekj\Application Data\Ceedo
2007-11-06 14:53 --------- d-----w C:\Program Files\WebEx
2007-11-06 14:53 --------- d-----w C:\Documents and Settings\wnekj\Application Data\webex
2005-10-24 18:50 21,296 ----a-w C:\Documents and Settings\wnekj\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SgeIconOvl]
@={ba930330-a721-11d3-a7b9-00500464ee16}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SgeIconOvl2]
@={2030D939-54A7-4fea-9B06-49EA77EFC87F}

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 02:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-02-13 11:25]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-01 08:26]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Utility"="Logi_MwX.Exe" [2004-05-06 21:11 C:\WINNT\Logi_MwX.Exe]
"0AI_Run"="guiperl.exe" []
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-06-08 06:49]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-06-08 06:49]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-05-28 16:21]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2003-09-29 06:10]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2005-08-31 15:50]
"TPKBDLED"="C:\WINNT\System32\TpScrLk.exe" [2003-04-02 10:45]
"TpShocks"="TpShocks.exe" [2004-03-26 17:16 C:\WINNT\system32\TpShocks.exe]
"QCWLICON"="C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2004-05-19 02:21]
"BMMGAG"="RunDll32 C:\PROGRA~1\Thinkpad\UTILIT~1\pwrmonit.dll" []
"BMMLREF"="C:\Program Files\Thinkpad\Utilities\BMMLREF.EXE" [2004-06-08 07:54]
"BMMMONWND"="rundll32.exe" [2004-08-04 02:56 C:\WINNT\system32\rundll32.exe]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2004-06-08 08:50]
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 17:39]
"TP4EX"="tp4ex.exe" [2002-09-04 00:05 C:\WINNT\system32\TP4EX.exe]
"TPHOTKEY"="C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2004-06-08 09:03]
"Checklogon"="C:\scripts\checklogon.pl" [2004-11-03 10:40]
"SAPSETUP_PENDING_INST"="\\is1519.applications.degussanet.com\daten$\sapserver\en\gui.640c2\setup\sapsetup.exe" []
"NWTRAY"="NWTRAY.EXE" [2002-03-12 10:37 C:\WINNT\system32\nwtray.exe]
"SgeEcView"="C:\program files\Safeguard Easy\SafeGuard Easy\Ecview.exe" [2004-09-20 11:50]
"EdWizard"="C:\program files\Safeguard Easy\SafeGuard Easy\EdWizard.exe" [2004-09-20 11:30]
"Mouse Suite 98 Daemon"="ICO.EXE" [2003-11-20 14:08 C:\WINNT\system32\ico.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 18:05]
"QCTray"="C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe" [2004-05-19 02:21]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" []
"SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-06-15 15:17]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINNT\System32\CTFMON.EXE" [2004-08-04 02:56]

C:\Documents and Settings\wnekj\Start Menu\Programs\Startup\
Quick ShutDown.lnk - C:\Program Files\Quick ShutDown\qsd.exe [2003-02-18 12:19:06]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2005-09-30 20:32:05]
Microsoft Office Shortcut-Bar.lnk - C:\WINNT\Installer\{90120409-6000-11D3-8CFE-0050048383C9}\misc.exe [2005-09-30 21:59:59]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-12 18:01:04]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Btn_Back"= 0 (0x0)
"Btn_Forward"= 0 (0x0)
"Btn_Stop"= 0 (0x0)
"Btn_Refresh"= 0 (0x0)
"Btn_Home"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"Btn_History"= 0 (0x0)
"Btn_Favorites"= 0 (0x0)
"Btn_Media"= 0 (0x0)
"Btn_Folders"= 0 (0x0)
"Btn_Fullscreen"= 0 (0x0)
"Btn_Tools"= 0 (0x0)
"Btn_MailNews"= 0 (0x0)
"Btn_Size"= 0 (0x0)
"Btn_Print"= 0 (0x0)
"Btn_Edit"= 0 (0x0)
"Btn_Discussions"= 0 (0x0)
"Btn_Cut"= 0 (0x0)
"Btn_Copy"= 0 (0x0)
"Btn_Paste"= 0 (0x0)
"Btn_Encoding"= 0 (0x0)
"Btn_PrintPreview"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoSetActiveDesktop"= 0 (0x0)
"NoRecentDocsMenu"= 0 (0x0)
"NoRecentDocsHistory"= 0 (0x0)
"NoLogoff"= 0 (0x0)
"NoSetFolders"= 0 (0x0)
"NoTrayContextMenu"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxxwvw]
byxxwvw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NotLog]
SGLogEx.dll 2002-01-22 14:28 110592 C:\WINNT\system32\SGLogEx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina]
QConGina.dll 2004-05-19 02:21 94208 C:\WINNT\system32\QConGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
C:\WINNT\System32\LgNotify.dll 2003-06-20 06:03 110592 C:\WINNT\system32\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SGLogNotification]
SGLogNotification.dll 2004-08-26 13:18 69632 C:\WINNT\system32\SGLogNotification.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\0\0]
"Script"=LA.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=LA.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=AddAdm.bat

R0 AES-256;AES-256;C:\WINNT\system32\DRIVERS\AES256.SYS [2004-09-20 11:49]
R0 SBHR;SBHR;C:\WINNT\system32\drivers\sbhr.sys [2007-12-20 08:25]
R0 SgeFlt;SgeFlt;C:\WINNT\system32\DRIVERS\SGEFLT.SYS [2004-09-20 11:50]
R0 Shockprf;Shockprf;C:\WINNT\system32\drivers\Shockprf.sys [2003-12-17 12:50]
R1 ANC;ANC;C:\WINNT\system32\drivers\ANC.SYS [2004-05-19 02:21]
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;C:\WINNT\system32\DRIVERS\dwvkbd.sys [2007-02-15 07:00]
R1 IBMTPCHK;IBMTPCHK;C:\WINNT\system32\drivers\IBMBLDID.SYS [2004-05-19 02:21]
R1 ShockMgr;ShockMgr;C:\WINNT\system32\drivers\ShockMgr.sys [2003-12-15 16:29]
R1 TPPWR;TPPWR;C:\WINNT\system32\drivers\Tppwr.sys [2004-06-08 07:54]
R2 ATNT40K;ActiveTouch NT Appsharing Driver;C:\WINNT\system32\DRIVERS\ATNT40K.SYS [2006-03-01 09:36]
R2 AutoExNT;AutoExNT;C:\WINNT\system32\AutoExNT.Exe [1996-02-29 18:00]
R3 DwMirror;DwMirror;C:\WINNT\system32\DRIVERS\DamewareMini.sys [2007-02-07 07:00]
R3 SBAPIFS;SBAPIFS;C:\WINNT\system32\drivers\sbapifs.sys []
S3 BWNDIS5;BWNDIS5 NDIS Protocol Driver;C:\WINNT\System32\BWNDIS5.SYS []
S3 LxrSG20d;LxrSG20d;C:\WINNT\System32\Drivers\LxrSG20d.sys [2007-11-09 07:32]
S3 NAL;Nal Service ;C:\WINNT\System32\Drivers\iqvw32.sys [2002-11-22 19:01]
S3 pelmouse;Mouse Suite Driver;C:\WINNT\system32\DRIVERS\pelmouse.sys [2003-01-10 13:55]
S3 pelusblf;USB Mouse Low Filter Driver;C:\WINNT\system32\DRIVERS\pelusblf.sys [2003-02-11 13:25]
S3 QCNDISIF;QCNDISIF;C:\WINNT\system32\drivers\qcndisif.SYS [2004-05-19 02:21]

*Newly Created Service* - SBAPIFS
.
Contents of the 'Scheduled Tasks' folder
"2007-12-16 15:48:52 C:\WINNT\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-10-01 02:31:30 C:\WINNT\Tasks\BMMTask.job"
- C:\PROGRA~1\Thinkpad\UTILIT~1\BMMTASK.EXE
.

(Rest of scan in next post)

john126
2007-12-25, 18:42
(Rest of Combo Fix scan - last few lines- followed by HJL)

**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 08:52:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINNT\system32\winlogon.exe
C:\program files\Safeguard Easy\SafeGuard Easy\SGUICL.MSG
-> C:\program files\Safeguard Easy\SafeGuard Easy\SGE_ERR0409.DLL
-> C:\program files\Safeguard Easy\SafeGuard Easy\SGE_MSG0409.DLL
-> C:\program files\Safeguard Easy\SafeGuard Easy\SGE_INFO0409.DLL
-> C:\program files\Safeguard Easy\SafeGuard Easy\SGHTMHLP0409.dll
-> C:\program files\Safeguard Easy\SafeGuard Easy\SecClassFactoryPS.dll
-> C:\program files\Safeguard Easy\SafeGuard Easy\wkscfgsrvps.dll
.
Completion time: 2007-12-25 8:53:58 - machine was rebooted

******************************************
**********************************
***********
****
HJL

*********************************

Hijack Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:59, on 2007-12-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\S24EvMon.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\System32\DWRCS.EXE
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\System32\QCONSVC.EXE
C:\WINNT\System32\RegSrvc.exe
C:\WINNT\System32\RoamMgr.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\program files\Safeguard Easy\SafeGuard Easy\SgeCtl.exe
C:\WINNT\System32\SgLogPlayer.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\TpKmpSVC.exe
C:\WINNT\system32\ZCfgSvc.exe
C:\WINNT\System32\DWRCST.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\1XConfig.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\Logi_MwX.Exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINNT\System32\TpScrLk.exe
C:\WINNT\system32\TpShocks.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINNT\system32\RunDll32.exe
C:\WINNT\system32\rundll32.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\WINNT\system32\NWTRAY.EXE
C:\program files\Safeguard Easy\SafeGuard Easy\Ecview.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINNT\system32\ICO.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\FSRremoS.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\program files\Safeguard Easy\SafeGuard Easy\WKSCFGSRV.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Quick ShutDown\qsd.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
c:\winnt\perl5\bin\PERL.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [0AI_Run] guiperl.exe C:\SCRIPTS\0AI_Run.pl
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] "C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TPKBDLED] C:\WINNT\System32\TpScrLk.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\Thinkpad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] "C:\Program Files\Thinkpad\Utilities\BMMLREF.EXE"
O4 - HKLM\..\Run: [BMMMONWND] "rundll32.exe" C:\PROGRA~1\Thinkpad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPKMAPHELPER] "C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [Checklogon] C:\scripts\checklogon.pl
O4 - HKLM\..\Run: [SAPSETUP_PENDING_INST] "\\is1519.applications.degussanet.com\daten$\sapserver\en\gui.640c2\setup\sapsetup.exe" /p /continue /log:append
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [SgeEcView] "C:\program files\Safeguard Easy\SafeGuard Easy\Ecview.exe"
O4 - HKLM\..\Run: [EdWizard] "C:\program files\Safeguard Easy\SafeGuard Easy\EdWizard.exe" as
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Quick ShutDown.lnk = C:\Program Files\Quick ShutDown\qsd.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office Shortcut-Bar.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINNT\System32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\PROGRA~1\WebEx\WebEx\350\atonecli.dll (HKCU)
O9 - Extra 'Tools' menuitem: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\PROGRA~1\WebEx\WebEx\350\atonecli.dll (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://home.intranet.degussa.com/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198283879246
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://degussa.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dhna.americas.degussa.com
O17 - HKLM\Software\..\Telephony: DomainName = dhna.americas.degussa.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dhna,degussa.com,mail.degussa.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dhna.americas.degussa.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = DHNA,degussa.com,mail.degussa.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = DHNA,degussa.com,mail.degussa.com
O20 - Winlogon Notify: byxxwvw - byxxwvw.dll (file missing)
O20 - Winlogon Notify: NotLog - C:\WINNT\SYSTEM32\SGLogEx.dll
O20 - Winlogon Notify: SGLogNotification - C:\WINNT\SYSTEM32\SGLogNotification.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AutoExNT - Unknown owner - C:\WINNT\system32\AutoExNT.Exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\System32\cusrvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\System32\DWRCS.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - C:\WINNT\SYSTEM32\LxrSG20s.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINNT\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINNT\System32\RegSrvc.exe
O23 - Service: RoamMgr - Intel Corporation - C:\WINNT\System32\RoamMgr.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINNT\System32\S24EvMon.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: SafeGuard Easy Control (SgeCtl) - Utimaco Safeware AG - C:\program files\Safeguard Easy\SafeGuard Easy\SgeCtl.exe
O23 - Service: SafeGuard SGLOG Player (SgLogPlayer) - Utimaco Safeware AG - C:\WINNT\System32\SgLogPlayer.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINNT\system32\TpKmpSVC.exe

--
End of file - 12724 bytes

pskelley
2007-12-25, 19:49
Thanks for returning your information. I need some information, I just don't know some of your programs.

Tell me if you know what these are, evidence is not conclusive and I don't want to remove the wrong thing.
O20 - Winlogon Notify: NotLog - C:\WINNT\SYSTEM32\SGLogEx.dll
O20 - Winlogon Notify: SGLogNotification - C:\WINNT\SYSTEM32\SGLogNotification.dll

http://www.runscanner.net/getmd5.aspx?md5=F96FA868536B7C08DF88E4011F1C2D02&process=sglogex.dll
BUT >>> http://www.incodesolutions.com/threats/System32Rootsglognotificationdll.php
assure me you run that program: Utimaco Safeware AG company

Let's move on with the cleanup while you do that:

1) Please download ATF Cleaner by Atribune
http://www.atribune.org/content/view/25/2/
Save it to your Desktop. We will use this later.

2) Open Vundofix by Doubleclicking on it, then point your mouse to the white box above the buttons and right click, then click on Add More Files. When the next window opens, copy and paste the files into the boxes and click on Add File(s), then click on Close Window. Then click Remove Vundo.

(files to add)

C:\WINNT\system32\djielmlh.ini
C:\WINNT\system32\mcrh.tmp
C:\WINNT\system32\jpewocmz.ini

3) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O20 - Winlogon Notify: byxxwvw - byxxwvw.dll (file missing)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

4) Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Restart and post a new HJT log, the information I requested and tell me how the computer is running.

Thanks

john126
2007-12-26, 05:55
Hello PS-

The computer runs Utimaco Safeguarg Easy file encryption. The ‘Utimaco’ reference programs are ok and I expect ‘SG’ designated files are also ok for ‘SafeGuard’. I did simple google searches for the suspect files and the hits were related to Utimaco.

The computer boots and runs fine. I need to spend time on-line to check it since this is where the problem came up-- random webpages opening.

Question on my security software- I run McAfee virus scan (company supplied), Counterspy with active protection and periodically search with spybot. Is this ok or should I just run McAfee with Spybot in immunize mode?

Thanks for the help and the donation is on the way. Very grateful on this end.

John126


Here is the Hijack file-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:27, on 2007-12-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\S24EvMon.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\AutoExNT.Exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\System32\DWRCS.EXE
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\System32\QCONSVC.EXE
C:\WINNT\System32\RegSrvc.exe
C:\WINNT\System32\RoamMgr.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\program files\Safeguard Easy\SafeGuard Easy\SgeCtl.exe
C:\WINNT\System32\SgLogPlayer.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\TpKmpSVC.exe
C:\WINNT\system32\ZCfgSvc.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\System32\DWRCST.exe
C:\WINNT\System32\1XConfig.exe
C:\WINNT\Explorer.EXE
C:\WINNT\Logi_MwX.Exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINNT\System32\TpScrLk.exe
C:\WINNT\system32\TpShocks.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINNT\system32\RunDll32.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\WINNT\system32\rundll32.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\winnt\perl5\bin\PERL.EXE
C:\WINNT\system32\NWTRAY.EXE
C:\program files\Safeguard Easy\SafeGuard Easy\Ecview.exe
C:\WINNT\system32\ICO.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\FSRremoS.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\program files\Safeguard Easy\SafeGuard Easy\WKSCFGSRV.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Quick ShutDown\qsd.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [0AI_Run] guiperl.exe C:\SCRIPTS\0AI_Run.pl
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] "C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TPKBDLED] C:\WINNT\System32\TpScrLk.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\Thinkpad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] "C:\Program Files\Thinkpad\Utilities\BMMLREF.EXE"
O4 - HKLM\..\Run: [BMMMONWND] "rundll32.exe" C:\PROGRA~1\Thinkpad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPKMAPHELPER] "C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [Checklogon] C:\scripts\checklogon.pl
O4 - HKLM\..\Run: [SAPSETUP_PENDING_INST] "\\is1519.applications.degussanet.com\daten$\sapserver\en\gui.640c2\setup\sapsetup.exe" /p /continue /log:append
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [SgeEcView] "C:\program files\Safeguard Easy\SafeGuard Easy\Ecview.exe"
O4 - HKLM\..\Run: [EdWizard] "C:\program files\Safeguard Easy\SafeGuard Easy\EdWizard.exe" as
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Quick ShutDown.lnk = C:\Program Files\Quick ShutDown\qsd.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office Shortcut-Bar.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINNT\System32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\PROGRA~1\WebEx\WebEx\350\atonecli.dll (HKCU)
O9 - Extra 'Tools' menuitem: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\PROGRA~1\WebEx\WebEx\350\atonecli.dll (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://home.intranet.degussa.com/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198283879246
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://degussa.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dhna.americas.degussa.com
O17 - HKLM\Software\..\Telephony: DomainName = dhna.americas.degussa.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dhna,degussa.com,mail.degussa.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dhna.americas.degussa.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = DHNA,degussa.com,mail.degussa.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = DHNA,degussa.com,mail.degussa.com
O20 - Winlogon Notify: NotLog - C:\WINNT\SYSTEM32\SGLogEx.dll
O20 - Winlogon Notify: SGLogNotification - C:\WINNT\SYSTEM32\SGLogNotification.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AutoExNT - Unknown owner - C:\WINNT\system32\AutoExNT.Exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\System32\cusrvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\System32\DWRCS.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - C:\WINNT\SYSTEM32\LxrSG20s.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINNT\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINNT\System32\RegSrvc.exe
O23 - Service: RoamMgr - Intel Corporation - C:\WINNT\System32\RoamMgr.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINNT\System32\S24EvMon.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: SafeGuard Easy Control (SgeCtl) - Utimaco Safeware AG - C:\program files\Safeguard Easy\SafeGuard Easy\SgeCtl.exe
O23 - Service: SafeGuard SGLOG Player (SgLogPlayer) - Utimaco Safeware AG - C:\WINNT\System32\SgLogPlayer.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINNT\system32\TpKmpSVC.exe

--
End of file - 12543 bytes

pskelley
2007-12-26, 12:55
Thanks for returning your log and the feedback. Good to hear your computer is running fine:bigthumb: As far as questions, I will post some links from experts, after you review that information, if you still have questions, please post them.

Let's run one last Kaspersky scan to be sure nothing is hiding, please use these setting.

Make sure to remove combofix, C:\qoobox\quarantine\, Vundofix and the C:\VundoFix Backups before you scan.

Run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.

* The program will launch and then begin downloading the latest definition files:
* Once the files have been downloaded click on NEXT
* Now click on Scan Settings
* In the scan settings make that the following are selected:
* Scan using the following Anti-Virus database:
* Standard
* Scan Options:
* Scan Archives
* Scan Mail Bases
* Click OK
* Now under select a target to scan:
* Select My Computer
* This will program will start and scan your system.
* The scan will take a while so be patient and let it run.
* Once the scan is complete it will display if your system has been infected.
* Now click on the Save as Text button:
* Save the file to your desktop.

Then post it here. <<< I do not need to see the sacan unless you have questions.

Happy Holidays:santa:

For your information:
http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/mcgill1.mspx

Some good information for you:
http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html

Here is some great information from experts in this field that will help you stay clean and safe online.
http://users.telenet.be/bluepatchy/miekiemoes/prevention.html
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

Thanks...pskelley
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.

john126
2007-12-26, 19:12
Hello PS

First - I formally thank a teacher and a soilder. I come from a family that had 11 uncles in WWII.

Second- Still a virus and here is the Kaspersky Log

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2007-12-26 12:06
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/12/2007
Kaspersky Anti-Virus database records: 462179
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
R:\

Scan Statistics:
Total number of scanned objects: 71475
Number of viruses found: 1
Number of infected objects: 6
Number of suspicious objects: 0
Duration of the scan process: 01:14:35

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_EMERSON0.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_EMERSON0.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\wnekj\ntuser.dat Object is locked skipped
C:\Documents and Settings\wnekj\NTUSER.DAT.LOG Object is locked skipped
C:\Recycler\S-1-5-21-1267101234-1802396302-1845911597-10776\Dc3\WINNT\system32\bffbhnuq.dll.vir Infected: Backdoor.Win32.Agent.dlj skipped
C:\Recycler\S-1-5-21-1267101234-1802396302-1845911597-10776\Dc3\WINNT\system32\hbrptyll.dll.vir Infected: Backdoor.Win32.Agent.dlj skipped
C:\Recycler\S-1-5-21-1267101234-1802396302-1845911597-10776\Dc3\WINNT\system32\wtjexcmn.dll.vir Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{7AD5ED1B-7DFF-494F-A488-394D62923E70}\RP608\A0208987.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{7AD5ED1B-7DFF-494F-A488-394D62923E70}\RP608\A0208991.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{7AD5ED1B-7DFF-494F-A488-394D62923E70}\RP608\A0208996.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{7AD5ED1B-7DFF-494F-A488-394D62923E70}\RP608\change.log Object is locked skipped
C:\TEMP\iwatch.lck Object is locked skipped
C:\TEMP\Perflib_Perfdata_248.dat Object is locked skipped
C:\TEMP\~DFF899.tmp Object is locked skipped
C:\TEMP\~DFF8A4.tmp Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\6to4svc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\inetmib1.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\iphlpapi.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\ipv6.exe Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\ipv6mon.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\netoc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\netsh.exe Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\tcpip6.sys Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\tunmp.sys Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\ws2_32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB817778$\wship6.dll Object is locked skipped
C:\WINNT\$NtUninstallKB818332$\serenum.sys Object is locked skipped
C:\WINNT\$NtUninstallKB824105$\netbt.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\accwiz.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\crypt32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\cryptsvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\hh.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\hhctrl.ocx Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\hhsetup.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\html32.cnv Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\itircl.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\itss.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\locator.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\magnify.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\migwiz.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\mrxsmb.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\msconv97.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\narrator.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\newdev.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\ntdll.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\ntkrnlpa.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\ntoskrnl.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\osk.exe Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\pchshell.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\raspptp.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\shdocvw.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\shmedia.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\srrstr.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\srv.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\urlmon.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\user32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\win32k.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\winsrv.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826939$\zipfldr.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\dhcpcsvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\ndis.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\ndisuio.sys Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\netshell.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\wzcdlg.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\wzcsapi.dll Object is locked skipped
C:\WINNT\$NtUninstallKB826942$\wzcsvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\colbact.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comuid.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\es.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\ole32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\txflog.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\dao360.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\expsrv.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msexch40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msexcl40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjet40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjetol1.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjetoledb40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjint40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjter40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msjtes40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msltus40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\mspbde40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msrd2x40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msrd3x40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msrepl40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\mstext40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\mswdat10.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\mswstr10.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\msxbde40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB829558$\vbajet32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB833330$\Blastcln\blastcln.exe Object is locked skipped
C:\WINNT\$NtUninstallKB833987$\sxs.dll Object is locked skipped
C:\WINNT\$NtUninstallKB833998$\shell32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB833998$\sxs.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\dao360.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjet40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjetol1.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped
C:\WINNT\$NtUninstallQ322011$\fxsclnt.exe Object is locked skipped
C:\WINNT\$NtUninstallQ814995$\acgenral.dll Object is locked skipped
C:\WINNT\$NtUninstallQ814995$\apphelp.sdb Object is locked skipped
C:\WINNT\$NtUninstallQ814995$\apph_sp.sdb Object is locked skipped
C:\WINNT\$NtUninstallQ814995$\apps_sp.chm Object is locked skipped
C:\WINNT\$NtUninstallQ814995$\sysmain.sdb Object is locked skipped
C:\WINNT\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\Netlogon.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Internet Logs\tvDebug.log Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\WINNT\SoftwareDistribution\EventCache\{E3C1AC5C-9CAB-45D7-A64C-08427BAB73DE}.bin Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\Internet.evt Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\system.LOG Object is locked skipped
C:\WINNT\system32\h323log.txt Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINNT\Temp\Perflib_Perfdata_6b8.dat Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{7AD5ED1B-7DFF-494F-A488-394D62923E70}\RP608\change.log Object is locked skipped
D:\users\wnekj\Cookies\index.dat Object is locked skipped
D:\users\wnekj\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\users\wnekj\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\users\wnekj\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\users\wnekj\Local Settings\History\History.IE5\MSHist012007122620071227\index.dat Object is locked skipped
D:\users\wnekj\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

Scan process completed.

pskelley
2007-12-26, 19:32
Thanks for the information, let's proceed like this:

C:\Recycler\ <<< three items in the Recycle Bin on your Desktop, empty it like this:
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/windows_waste_empty_bskt.mspx?mfr=true

Three infected System Restore files, clean those like this:

MANUAL INSTRUCTIONS FOR SYSTEM RESTORE
Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Reboot

Turn ON System Restore,
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

Follow those directions, the next Kaspersky will be clean. Don't post a clean scan.

Thanks...Phil

john126
2007-12-27, 01:04
Kaspersky is clean and I think we are done unless a problem develops.

Wonderful support through the holiday and actually learned a few things.

Spent the day working on home computers doing Windows updates, running Cleanup!, setting up Spyblaster & Spybot w/o immunize. Hopefully this will keep 4 more people off your boards.

Thanks again

John126