BillG
2008-01-31, 16:57
Been going around in circles for 4 days. Spybot, Panda and Microsoft Live OneCare can all "find" traces of it, can all "fix" it, but none can "remove" it! Always comes back right away. Only way I seem to be able to go on line without being jerked all over the place is if I boot up in SafeMode.
Followed your forum's online step by step procedure. HJT log follows then the Kaspersky log. Kaspersky scan found a number of problems but forum instructions didn't say to fix anything, so I didn't.
Help!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:02:02 AM, on 1/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\AVENGINE.EXE
C:\WINNT\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\TPSrv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsCtrls.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
c:\program files\panda software\panda antivirus + firewall 2007\firewall\PSHOST.EXE
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsImSvc.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\APVXDWIN.EXE
C:\WINNT\system32\Rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\WebProxy.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\avciman.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\psimreal.exe
C:\WINNT\System32\svchost.exe
D:\Hijack\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINNT\System32\userinit.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [64e50835] rundll32.exe "C:\WINNT\system32\oevmekrd.dll",b
O4 - HKLM\..\Run: [BM67d63ba9] Rundll32.exe "C:\WINNT\system32\waxreovs.dll",s
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User '?')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User '?')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User '?')
O4 - HKUS\S-1-5-21-1292428093-1364589140-725345543-1000\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1 (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User '?')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://www.windowsupdate.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://ispe.sdc.hp.com/awebui/jsp/answerweb/applets/HPISWebManager.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1185916500250
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1185916458640
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AD233832-A5AD-4D0C-9786-758C676BCBD8}: NameServer = 24.158.63.8,24.158.63.9
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda software\panda antivirus + firewall 2007\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsImSvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\TPSrv.exe
O24 - Desktop Component 0: (no name) - http://us.i1.yimg.com/us.yimg.com/i/ww/bt1/ml.gif
--
End of file - 7724 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, January 30, 2008 9:19:55 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 30/01/2008
Kaspersky Anti-Virus database records: 538921
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 40301
Number of viruses found: 1
Number of infected objects: 8
Number of suspicious objects: 0
Duration of the scan process: 01:18:11
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Asus\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Asus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Asus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Asus\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Asus\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Asus\ntuser.dat Object is locked skipped
C:\Documents and Settings\Asus\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\cace2423dfb97c58fe7dd9f120557063PSK_NAMES Object is locked skipped
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\cace2423dfb97c58fe7dd9f120557063PSK_NAMES2 Object is locked skipped
C:\RECYCLER\NPROTECT\00000000.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000001.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000002.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000003.LIV Object is locked skipped
C:\RECYCLER\NPROTECT\00000006.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000007.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000015.edb Object is locked skipped
C:\RECYCLER\NPROTECT\00000016.dll Object is locked skipped
C:\RECYCLER\NPROTECT\00000021.rbf Object is locked skipped
C:\RECYCLER\NPROTECT\00000022.rbf Object is locked skipped
C:\RECYCLER\NPROTECT\00000023.rbf Object is locked skipped
C:\RECYCLER\NPROTECT\00000028.000 Object is locked skipped
C:\RECYCLER\NPROTECT\00000029.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000030.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000031.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000032.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000033.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000034.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000035.acs Object is locked skipped
C:\RECYCLER\NPROTECT\00000036.ISU Object is locked skipped
C:\RECYCLER\NPROTECT\00000037.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000038.chm Object is locked skipped
C:\RECYCLER\NPROTECT\00000039.dll Object is locked skipped
C:\RECYCLER\NPROTECT\00000040.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000041.dll Object is locked skipped
C:\RECYCLER\NPROTECT\00000042.sys Object is locked skipped
C:\RECYCLER\NPROTECT\00000046.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000047.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000054.PNF Object is locked skipped
C:\RECYCLER\NPROTECT\00000055.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000056.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000059.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000060.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000075.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000076.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000078.PNF Object is locked skipped
C:\RECYCLER\NPROTECT\00000086.386 Object is locked skipped
C:\RECYCLER\NPROTECT\00000087.DLL Object is locked skipped
C:\RECYCLER\NPROTECT\00000088.SYS Object is locked skipped
C:\RECYCLER\NPROTECT\00000089.386 Object is locked skipped
C:\RECYCLER\NPROTECT\00000090.DLL Object is locked skipped
C:\RECYCLER\NPROTECT\00000091.SYS Object is locked skipped
C:\RECYCLER\NPROTECT\00000092.INF Object is locked skipped
C:\RECYCLER\NPROTECT\00000093.CAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000094.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000095.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000096.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000097.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000098.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000099.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000100.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000101.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000102.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000103.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000104.LIV Object is locked skipped
C:\RECYCLER\NPROTECT\00000105.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000107.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000108.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000109.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000110.isu Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\change.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\system32\CatRoot2\edb.log Object is locked skipped
C:\WINNT\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINNT\system32\config\sam Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\security Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINNT\system32\h323log.txt Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000217.exe/RegistrySmart/RegistrySmart.exe Infected: not-a-virus:FraudTool.Win32.RegistrySmart.a skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000217.exe 7-Zip: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000217.exe UPX: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000217.exe PE_Patch.UPX: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000226.exe/RegistrySmart/RegistrySmart.exe Infected: not-a-virus:FraudTool.Win32.RegistrySmart.a skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000226.exe 7-Zip: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000226.exe UPX: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000226.exe PE_Patch.UPX: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\change.log Object is locked skipped
Scan process completed.
Followed your forum's online step by step procedure. HJT log follows then the Kaspersky log. Kaspersky scan found a number of problems but forum instructions didn't say to fix anything, so I didn't.
Help!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:02:02 AM, on 1/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\AVENGINE.EXE
C:\WINNT\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\TPSrv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsCtrls.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
c:\program files\panda software\panda antivirus + firewall 2007\firewall\PSHOST.EXE
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsImSvc.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\APVXDWIN.EXE
C:\WINNT\system32\Rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\WebProxy.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\avciman.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\psimreal.exe
C:\WINNT\System32\svchost.exe
D:\Hijack\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINNT\System32\userinit.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [64e50835] rundll32.exe "C:\WINNT\system32\oevmekrd.dll",b
O4 - HKLM\..\Run: [BM67d63ba9] Rundll32.exe "C:\WINNT\system32\waxreovs.dll",s
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User '?')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User '?')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User '?')
O4 - HKUS\S-1-5-21-1292428093-1364589140-725345543-1000\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1 (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User '?')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://www.windowsupdate.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://ispe.sdc.hp.com/awebui/jsp/answerweb/applets/HPISWebManager.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1185916500250
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1185916458640
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AD233832-A5AD-4D0C-9786-758C676BCBD8}: NameServer = 24.158.63.8,24.158.63.9
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda software\panda antivirus + firewall 2007\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsImSvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\TPSrv.exe
O24 - Desktop Component 0: (no name) - http://us.i1.yimg.com/us.yimg.com/i/ww/bt1/ml.gif
--
End of file - 7724 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, January 30, 2008 9:19:55 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 30/01/2008
Kaspersky Anti-Virus database records: 538921
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 40301
Number of viruses found: 1
Number of infected objects: 8
Number of suspicious objects: 0
Duration of the scan process: 01:18:11
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Asus\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Asus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Asus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Asus\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Asus\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Asus\ntuser.dat Object is locked skipped
C:\Documents and Settings\Asus\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\cace2423dfb97c58fe7dd9f120557063PSK_NAMES Object is locked skipped
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\cace2423dfb97c58fe7dd9f120557063PSK_NAMES2 Object is locked skipped
C:\RECYCLER\NPROTECT\00000000.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000001.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000002.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000003.LIV Object is locked skipped
C:\RECYCLER\NPROTECT\00000006.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000007.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000015.edb Object is locked skipped
C:\RECYCLER\NPROTECT\00000016.dll Object is locked skipped
C:\RECYCLER\NPROTECT\00000021.rbf Object is locked skipped
C:\RECYCLER\NPROTECT\00000022.rbf Object is locked skipped
C:\RECYCLER\NPROTECT\00000023.rbf Object is locked skipped
C:\RECYCLER\NPROTECT\00000028.000 Object is locked skipped
C:\RECYCLER\NPROTECT\00000029.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000030.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000031.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000032.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000033.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000034.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000035.acs Object is locked skipped
C:\RECYCLER\NPROTECT\00000036.ISU Object is locked skipped
C:\RECYCLER\NPROTECT\00000037.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000038.chm Object is locked skipped
C:\RECYCLER\NPROTECT\00000039.dll Object is locked skipped
C:\RECYCLER\NPROTECT\00000040.exe Object is locked skipped
C:\RECYCLER\NPROTECT\00000041.dll Object is locked skipped
C:\RECYCLER\NPROTECT\00000042.sys Object is locked skipped
C:\RECYCLER\NPROTECT\00000046.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000047.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000054.PNF Object is locked skipped
C:\RECYCLER\NPROTECT\00000055.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000056.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000059.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000060.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000075.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000076.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000078.PNF Object is locked skipped
C:\RECYCLER\NPROTECT\00000086.386 Object is locked skipped
C:\RECYCLER\NPROTECT\00000087.DLL Object is locked skipped
C:\RECYCLER\NPROTECT\00000088.SYS Object is locked skipped
C:\RECYCLER\NPROTECT\00000089.386 Object is locked skipped
C:\RECYCLER\NPROTECT\00000090.DLL Object is locked skipped
C:\RECYCLER\NPROTECT\00000091.SYS Object is locked skipped
C:\RECYCLER\NPROTECT\00000092.INF Object is locked skipped
C:\RECYCLER\NPROTECT\00000093.CAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000094.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000095.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000096.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000097.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000098.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000099.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000100.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000101.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000102.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000103.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000104.LIV Object is locked skipped
C:\RECYCLER\NPROTECT\00000105.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00000107.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000108.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000109.DAT Object is locked skipped
C:\RECYCLER\NPROTECT\00000110.isu Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\change.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\system32\CatRoot2\edb.log Object is locked skipped
C:\WINNT\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINNT\system32\config\sam Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\security Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINNT\system32\h323log.txt Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000217.exe/RegistrySmart/RegistrySmart.exe Infected: not-a-virus:FraudTool.Win32.RegistrySmart.a skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000217.exe 7-Zip: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000217.exe UPX: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000217.exe PE_Patch.UPX: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000226.exe/RegistrySmart/RegistrySmart.exe Infected: not-a-virus:FraudTool.Win32.RegistrySmart.a skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000226.exe 7-Zip: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000226.exe UPX: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\A0000226.exe PE_Patch.UPX: infected - 1 skipped
D:\System Volume Information\_restore{26E8A554-6586-42CC-ACC3-A92E700341E5}\RP1\change.log Object is locked skipped
Scan process completed.