PDA

View Full Version : Help needed malware (not sure noob)



stella
2008-01-25, 10:04
Ive run the spybot search and destory it detected a few things which keeps coming back.
explorer.exe also keeps restarting or shutting down,
"Warning your computer may be infected...." also have that message coming up, pop-up ads.
help is needed thank you

The HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:21:01 PM, on 25/01/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Outerinfo\Outerinfo.exe
C:\Program Files\Outerinfo\OuterinfoUpdate.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O3 - Toolbar: ¶oμð¿A(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [MSDrive] rundll32.exe C:\WINDOWS\System32\drvdud.dll,startup
O4 - HKLM\..\Run: [Winupdate Engine] C:\WINDOWS\System32\wupeng.exe
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java ?? - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {04E7BADF-F3B9-420D-B82D-8D8CADEFE4F9} (CyImage2Ctl Class) - http://cyimg8.cyworld.com/ImageUpload/CyImageUpload_10217.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4B48CEDD-EB09-4FD3-AA22-5BDE98EDEF90} (EZXSActiveX Control) - http://www.globalwindow.org/wps/ezxssso/install/ezxsactivex.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://xscan.malwarecrush.com/install484.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CDF26594-A9E2-4E41-87F9-6E79DD38CFE3} (AutoTrustHTTPControl Control) - http://www.eugenes.co.kr/eng/investor/file/AutoTrustHTTP.cab
O16 - DPF: {E75386B4-C629-11DB-8338-444553544200} (PcubeSet Class) - http://cyimg7.cyworld.com/cymusic/package/cyinstal.cab
O16 - DPF: {F82C37EC-935C-11DC-A25B-006097755A02} (avchatAtx Class) - http://ohmylove.co.jp/japan/avchatatx.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\System32\wgbqgswe.exe (file missing)
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

--
End of file - 7978 bytes


Kaspersky log report
is still scanning its at 35% and its been 40mins, the scan has slowed down dramatically i think its because of the malware cpu is running above 90% close to 100%

stella
2008-01-25, 11:18
KASPERSKY ONLINE SCANNER REPORT
Friday, January 25, 2008 8:15:03 PM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/01/2008
Kaspersky Anti-Virus database records: 531970


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
F:\

Scan Statistics
Total number of scanned objects 79016
Number of viruses found 18
Number of infected objects 58
Number of suspicious objects 0
Duration of the scan process 01:16:13

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-01-25_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Shin\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Shin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Shin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Shin\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Shin\Local Settings\Temporary Internet Files\Content.IE5\6XCFA9E5\gamadril20071203[1] Infected: Backdoor.Win32.Agent.dbm skipped

C:\Documents and Settings\Shin\Local Settings\Temporary Internet Files\Content.IE5\ARYZULQV\iphone[1].swf Object is locked skipped

C:\Documents and Settings\Shin\Local Settings\Temporary Internet Files\Content.IE5\CBB7ISTT\ADCFreeInstaller[1].exe Infected: not-a-virus:Downloader.Win32.AdvancedCleaner.c skipped

C:\Documents and Settings\Shin\Local Settings\Temporary Internet Files\Content.IE5\CBB7ISTT\tr[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped

C:\Documents and Settings\Shin\Local Settings\Temporary Internet Files\Content.IE5\CDK5QZOH\apst377[1] Infected: not-a-virus:AdWare.Win32.SuperJuan.ez skipped

C:\Documents and Settings\Shin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Shin\Local Settings\Temporary Internet Files\Content.IE5\WPARSDAN\0[1].htm Infected: Trojan.HTML.Agent.e skipped

C:\Documents and Settings\Shin\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Shin\NTUSER.DAT.LOG Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped

C:\Program Files\Helper\Helper9.dll Infected: Trojan-Downloader.Win32.BHO.cf skipped

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped

C:\Program Files\Outerinfo\FF\components\FF.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped

C:\Program Files\Outerinfo\OiUninstaller.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.gn skipped

C:\Program Files\Outerinfo\OiUninstaller.exe NSIS: infected - 1 skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc23.exe Infected: Trojan-PSW.Win32.Gamec.ck skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc53.exe Infected: Trojan-Downloader.Win32.Agent.hst skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc66\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc70\OinFP.exe Infected: Trojan-Downloader.Win32.Agent.hjs skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc70\OiUninstaller.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.gn skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc70\OiUninstaller.exe NSIS: infected - 1 skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc850.exe Infected: Trojan.Win32.Dialer.yz skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc854\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc855.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc855.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\RECYCLER\S-1-5-21-343818398-2111687655-682003330-1003\Dc855.exe RarSFX: infected - 2 skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP110\A0035869.exe Infected: Trojan-PSW.Win32.Gamec.ck skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP160\A0047703.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP160\A0048699.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP160\A0048700.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP160\A0048705.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP161\A0049704.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP161\A0049772.exe Infected: Trojan-Downloader.Win32.Agent.hst skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP161\A0049773.exe Infected: Trojan-Downloader.Win32.Agent.hst skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP163\A0050700.exe Infected: Trojan-Downloader.Win32.Agent.hat skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP163\A0050703.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP163\A0050705.exe/data0006 Infected: not-a-virus:FraudTool.Win32.MalwareCrush.c skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP163\A0050705.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP163\A0052862.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP164\A0052877.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.gn skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP164\A0052877.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP164\A0052878.exe Infected: Trojan-Downloader.Win32.Agent.hjs skipped

C:\System Volume Information\_restore{B1C9BFF6-2940-4609-8AED-5B5E008E62C0}\RP164\change.log Object is locked skipped

C:\WINDOWS\Debug\oakley.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped

C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\WINDOWS\system32\drvdip.dll Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\system32\drvdud.dll Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\system32\drvnut.dll Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\system32\drvpil.dll Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\system32\drvsip.dll Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\qngvrnvf.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped

C:\WINDOWS\system32\vkbcvljg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\winemx32.dll Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\system32\winjvd32.dll Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\system32\winzzd32.dll Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\Temp\gos1E7.tmp Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\Temp\gos1F2.tmp Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\Temp\gos202.tmp Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\Temp\gos218.tmp Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\Temp\gos28.tmp Infected: Trojan.Win32.Dialer.yz skipped

C:\WINDOWS\Temp\Perflib_Perfdata_7e4.dat Object is locked skipped

C:\WINDOWS\Temp\win1DA.tmp Object is locked skipped

C:\WINDOWS\Temp\win1E7.exe/data0004/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.gn skipped

C:\WINDOWS\Temp\win1E7.exe/data0004 Infected: not-a-virus:AdWare.Win32.PurityScan.gn skipped

C:\WINDOWS\Temp\win1E7.exe/data0005 Infected: Trojan-Downloader.Win32.Agent.hjs skipped

C:\WINDOWS\Temp\win1E7.exe/data0006/data0007 Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped

C:\WINDOWS\Temp\win1E7.exe/data0006 Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped

C:\WINDOWS\Temp\win1E7.exe NSIS: infected - 5 skipped

C:\WINDOWS\Temp\win22.exe Infected: Trojan-Dropper.Win32.Agent.dvf skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

Scan process completed.

Blade81
2008-01-29, 18:58
Hi

Please see post #4 in Before you post topic (http://forums.spybot.info/showthread.php?t=288)

Blade81
2008-02-03, 20:56
Due to inactivity, this thread will now be closed.

Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.