and I thought my system was now clean!:spider:
In Spybot at System Startup, I have a blank Run and states Agobot-Ku Worm!!! Please help!!!
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 TeaTimer_original.exe (1.4.0.2)
2005-12-26 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-01-02 advcheck.dll (1.2.0.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-03-14 Includes\Cookies.sbi
2006-12-08 Includes\Dialer.sbi
2007-03-14 Includes\DialerC.sbi
2007-02-07 Includes\Hijackers.sbi
2007-03-14 Includes\HijackersC.sbi
2006-10-27 Includes\Keyloggers.sbi
2007-03-14 Includes\KeyloggersC.sbi
2004-11-29 Includes\LSP.sbi
2007-02-14 Includes\Malware.sbi
2007-03-14 Includes\MalwareC.sbi
2007-01-19 Includes\PUPS.sbi
2007-03-14 Includes\PUPSC.sbi
2007-03-14 Includes\Revision.sbi
2006-12-08 Includes\Security.sbi
2007-03-14 Includes\SecurityC.sbi
2007-02-02 Includes\Spybots.sbi
2007-03-14 Includes\SpybotsC.sbi
2005-02-17 Includes\Tracks.uti
2007-03-14 Includes\Trojans.sbi
2007-03-14 Includes\TrojansC.sbi
Located: HK_LM:Run, Adobe Photo Downloader
command: "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
file: C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
size: 57344
MD5: 617fa5be646b5e8d6670fd4710acd2d3
Located: HK_LM:Run, CallControl 4.5
command: C:\PROGRAM FILES\FAXTALK COMMUNICATOR\FTCtrl32.exe /autoload
file:
Located: HK_LM:Run, CTRegRun
command: C:\WINDOWS\CTRegRun.EXE
file: C:\WINDOWS\CTRegRun.EXE
size: 41984
MD5: 91980f1b3352db9ccd59d8aa640a5bb0
Located: HK_LM:Run, NeroFilterCheck
command: C:\WINDOWS\system32\NeroCheck.exe
file: C:\WINDOWS\system32\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90
Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff
Located: HK_LM:Run, SiSUSBRG
command: C:\WINDOWS\SiSUSBrg.exe
file: C:\WINDOWS\SiSUSBrg.exe
size: 102400
MD5: 52ceb84ac83d8c7b0ac0c40a3b734d64
Located: HK_LM:Run, TkBellExe
command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
size: 180269
MD5: f9b47f830dd55fedd6ef27d063c29a42
Located: HK_LM:Run, UserFaultCheck
command: %systemroot%\system32\dumprep 0 -u
file: C:\WINDOWS\system32\dumprep.exe
size: 10752
MD5: 13922eb54890c77005268882629a31fe
Located: HK_LM:Run, Windows Defender
command: "C:\Program Files\Windows Defender\MSASCui.exe" -hide
file: C:\Program Files\Windows Defender\MSASCui.exe
size: 866584
MD5: 77c03bf23ae56b0a31ae4d5bb4b3d0ac
Located: HK_LM:Run, SoundMan (DISABLED)
command: SOUNDMAN.EXE
file: C:\WINDOWS\SOUNDMAN.EXE
size: 57344
MD5: 59bc3e1af9ccc7e7c06d61877ca0a138
Located: HK_CU:Run,
command:
file:
Located: HK_CU:Run, NBJ
command: "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
file: C:\Program Files\Ahead\Nero BackItUp\NBJ.exe
size: 1871872
MD5: 829a54e0d5b6f619b784d727454d692b
Located: HK_CU:Run, realmon
command: C:\Program Files\CA\eTrust\InoculateIT\Realmon.exe
file: C:\Program Files\CA\eTrust\InoculateIT\Realmon.exe
size: 374584
MD5: 3684f128bc9b57c5e066ab1886c6087a
Located: HK_CU:Run, SpybotSD TeaTimer
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 1415824
MD5: 8f1862afc3c79c0ea37621e87cc2fe6e
Located: HK_CU:Run, swg
command: C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
file: C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
size: 171448
MD5: 0fa44ea8b03aba3e1d240b5a333d8e6a
Located: Startup (common), Adobe Reader Speed Launch.lnk
command: C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
file: C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
size: 40048
MD5: 54c88bfbd055621e2306534f445c0c8d
Located: Startup (common), Adobe Reader Synchronizer.lnk
command: C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
file: C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
size: 734872
MD5: 169c293ce9460a05646d17dc6aa2fb2c
Located: Startup (common), EPSON Status Monitor 3 Environment Check 2.lnk
command: C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
file: C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
size: 135680
MD5: 4508d0da06456fff34def785ba2e4d1e
Located: Startup (common), LevelOne Wireless Utility.lnk
command: C:\Program Files\LevelOne\Common\RaUI.exe
file: C:\Program Files\LevelOne\Common\RaUI.exe
size: 585728
MD5: 290b7d1b0909230e089d295d64fd387e
Located: Startup (common), Microsoft Office.lnk
command: C:\Program Files\Microsoft Office\Office\OSA9.EXE
file: C:\Program Files\Microsoft Office\Office\OSA9.EXE
size: 65588
MD5: 4da0e55a62d619811c5cbf57c0105f89
Located: System.ini, crypt32chain
command: crypt32.dll
file: crypt32.dll
Located: System.ini, cryptnet
command: cryptnet.dll
file: cryptnet.dll
Located: System.ini, cscdll
command: cscdll.dll
file: cscdll.dll
Located: System.ini, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
Located: System.ini, Schedule
command: wlnotify.dll
file: wlnotify.dll
Located: System.ini, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
Located: System.ini, SensLogn
command: WlNotify.dll
file: WlNotify.dll
Located: System.ini, termsrv
command: wlnotify.dll
file: wlnotify.dll
Located: System.ini, wlballoon
command: wlnotify.dll
file: wlnotify.dll
In Spybot at System Startup, I have a blank Run and states Agobot-Ku Worm!!! Please help!!!
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 TeaTimer_original.exe (1.4.0.2)
2005-12-26 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-01-02 advcheck.dll (1.2.0.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-03-14 Includes\Cookies.sbi
2006-12-08 Includes\Dialer.sbi
2007-03-14 Includes\DialerC.sbi
2007-02-07 Includes\Hijackers.sbi
2007-03-14 Includes\HijackersC.sbi
2006-10-27 Includes\Keyloggers.sbi
2007-03-14 Includes\KeyloggersC.sbi
2004-11-29 Includes\LSP.sbi
2007-02-14 Includes\Malware.sbi
2007-03-14 Includes\MalwareC.sbi
2007-01-19 Includes\PUPS.sbi
2007-03-14 Includes\PUPSC.sbi
2007-03-14 Includes\Revision.sbi
2006-12-08 Includes\Security.sbi
2007-03-14 Includes\SecurityC.sbi
2007-02-02 Includes\Spybots.sbi
2007-03-14 Includes\SpybotsC.sbi
2005-02-17 Includes\Tracks.uti
2007-03-14 Includes\Trojans.sbi
2007-03-14 Includes\TrojansC.sbi
Located: HK_LM:Run, Adobe Photo Downloader
command: "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
file: C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
size: 57344
MD5: 617fa5be646b5e8d6670fd4710acd2d3
Located: HK_LM:Run, CallControl 4.5
command: C:\PROGRAM FILES\FAXTALK COMMUNICATOR\FTCtrl32.exe /autoload
file:
Located: HK_LM:Run, CTRegRun
command: C:\WINDOWS\CTRegRun.EXE
file: C:\WINDOWS\CTRegRun.EXE
size: 41984
MD5: 91980f1b3352db9ccd59d8aa640a5bb0
Located: HK_LM:Run, NeroFilterCheck
command: C:\WINDOWS\system32\NeroCheck.exe
file: C:\WINDOWS\system32\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90
Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff
Located: HK_LM:Run, SiSUSBRG
command: C:\WINDOWS\SiSUSBrg.exe
file: C:\WINDOWS\SiSUSBrg.exe
size: 102400
MD5: 52ceb84ac83d8c7b0ac0c40a3b734d64
Located: HK_LM:Run, TkBellExe
command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
size: 180269
MD5: f9b47f830dd55fedd6ef27d063c29a42
Located: HK_LM:Run, UserFaultCheck
command: %systemroot%\system32\dumprep 0 -u
file: C:\WINDOWS\system32\dumprep.exe
size: 10752
MD5: 13922eb54890c77005268882629a31fe
Located: HK_LM:Run, Windows Defender
command: "C:\Program Files\Windows Defender\MSASCui.exe" -hide
file: C:\Program Files\Windows Defender\MSASCui.exe
size: 866584
MD5: 77c03bf23ae56b0a31ae4d5bb4b3d0ac
Located: HK_LM:Run, SoundMan (DISABLED)
command: SOUNDMAN.EXE
file: C:\WINDOWS\SOUNDMAN.EXE
size: 57344
MD5: 59bc3e1af9ccc7e7c06d61877ca0a138
Located: HK_CU:Run,
command:
file:
Located: HK_CU:Run, NBJ
command: "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
file: C:\Program Files\Ahead\Nero BackItUp\NBJ.exe
size: 1871872
MD5: 829a54e0d5b6f619b784d727454d692b
Located: HK_CU:Run, realmon
command: C:\Program Files\CA\eTrust\InoculateIT\Realmon.exe
file: C:\Program Files\CA\eTrust\InoculateIT\Realmon.exe
size: 374584
MD5: 3684f128bc9b57c5e066ab1886c6087a
Located: HK_CU:Run, SpybotSD TeaTimer
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 1415824
MD5: 8f1862afc3c79c0ea37621e87cc2fe6e
Located: HK_CU:Run, swg
command: C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
file: C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
size: 171448
MD5: 0fa44ea8b03aba3e1d240b5a333d8e6a
Located: Startup (common), Adobe Reader Speed Launch.lnk
command: C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
file: C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
size: 40048
MD5: 54c88bfbd055621e2306534f445c0c8d
Located: Startup (common), Adobe Reader Synchronizer.lnk
command: C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
file: C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
size: 734872
MD5: 169c293ce9460a05646d17dc6aa2fb2c
Located: Startup (common), EPSON Status Monitor 3 Environment Check 2.lnk
command: C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
file: C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
size: 135680
MD5: 4508d0da06456fff34def785ba2e4d1e
Located: Startup (common), LevelOne Wireless Utility.lnk
command: C:\Program Files\LevelOne\Common\RaUI.exe
file: C:\Program Files\LevelOne\Common\RaUI.exe
size: 585728
MD5: 290b7d1b0909230e089d295d64fd387e
Located: Startup (common), Microsoft Office.lnk
command: C:\Program Files\Microsoft Office\Office\OSA9.EXE
file: C:\Program Files\Microsoft Office\Office\OSA9.EXE
size: 65588
MD5: 4da0e55a62d619811c5cbf57c0105f89
Located: System.ini, crypt32chain
command: crypt32.dll
file: crypt32.dll
Located: System.ini, cryptnet
command: cryptnet.dll
file: cryptnet.dll
Located: System.ini, cscdll
command: cscdll.dll
file: cscdll.dll
Located: System.ini, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
Located: System.ini, Schedule
command: wlnotify.dll
file: wlnotify.dll
Located: System.ini, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
Located: System.ini, SensLogn
command: WlNotify.dll
file: WlNotify.dll
Located: System.ini, termsrv
command: wlnotify.dll
file: wlnotify.dll
Located: System.ini, wlballoon
command: wlnotify.dll
file: wlnotify.dll