command service removal [with log&report]

kaspersky on-line scanner report

C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013811.exe Infected: Backdoor.Win32.PoeBot.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013812.exe Infected: Virus.Win32.Parite.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013813.exe Infected: Backdoor.Win32.PoeBot.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013814.exe Infected: Trojan-Downloader.Win32.Adload.l skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013825.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013854.exe Infected: Trojan-Downloader.Win32.Adload.t skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013861.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013874.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013929.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013934.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013935.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013936.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013938.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013953.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013954.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013964.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013965.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013966.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013968.EXE Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013969.EXE Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013970.EXE/unknown2.bin Infected: not-a-virus:AdWare.Win32.Ucmore.e skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013970.EXE/UCMTSAIE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore.a skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013970.EXE/IUCMORE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013970.EXE ZIP: infected - 3 skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013970.EXE WiseSFX Dropper: infected - 3 skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013971.dll Infected: not-a-virus:AdWare.Win32.Ucmore skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013972.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013973.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013974.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013975.DLL Infected: not-a-virus:AdWare.Win32.Softomate.j skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013976.dll Infected: not-a-virus:AdWare.Win32.Ucmore.a skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013977.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013978.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013979.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013980.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013981.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013982.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013983.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013984.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013985.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013986.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013987.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013988.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013989.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013990.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP64\A0013991.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
 
kaspersky on-line scanner report

C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013274.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013357.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013449.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013452.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013453.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013458.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013462.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013464.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013471.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013494.exe Infected: Trojan-Downloader.Win32.VB.vz skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013495.exe Infected: Trojan-Downloader.Win32.VB.wr skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP62\A0013507.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013552.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013558.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013564.exe Infected: Trojan-Downloader.Win32.Adload.t skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013565.exe Infected: Trojan-Downloader.Win32.Adload.u skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013567.exe Infected: not-a-virus:AdWare.Win32.AdURL.c skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013577.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013641.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013659.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.p skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013659.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013662.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013663.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013665.exe Infected: Trojan-Downloader.Win32.VB.ya skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013666.exe/unknown2.bin Infected: not-a-virus:AdWare.Win32.Ucmore.e skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013666.exe/UCMTSAIE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore.a skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013666.exe/IUCMORE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013666.exe ZIP: infected - 3 skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013666.exe WiseSFX Dropper: infected - 3 skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013668.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013676.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013683.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013691.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013699.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013705.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013713.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013721.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013729.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013736.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013738.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013774.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013801.exe Infected: Backdoor.Win32.Tompai.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013802.exe Infected: Backdoor.Win32.Tompai.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013803.exe Infected: Backdoor.Win32.Tompai.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013804.exe Infected: Backdoor.Win32.PoeBot.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013805.exe Infected: Backdoor.Win32.PoeBot.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013806.exe Infected: Backdoor.Win32.PoeBot.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013807.exe Infected: Virus.Win32.Parite.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013808.exe Infected: Backdoor.Win32.PoeBot.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013809.exe Infected: Backdoor.Win32.PoeBot.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP63\A0013810.exe Infected: Virus.Win32.Parite.b skipped
 
kaspersky on-line scanner report

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Sunday, March 19, 2006 9:36:35 AM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 18/03/2006
Kaspersky Anti-Virus database records: 182777
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
E:\

Scan Statistics:
Total number of scanned objects: 37175
Number of viruses found: 36
Number of infected objects: 199
Number of suspicious objects: 0
Duration of the scan process: 00:41:28

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00840000.VBN Infected: Backdoor.Win32.Tompai.b skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\024C0000.VBN Infected: Backdoor.Win32.Rbot.arm skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07DC0000.VBN Infected: Trojan-Downloader.Win32.VB.wg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E00000.VBN Infected: Backdoor.Win32.Rbot.aqj skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E00001.VBN Infected: Trojan-Downloader.Win32.VB.wy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E40000.VBN Infected: Backdoor.Win32.Rbot.arm skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E40001.VBN Infected: Trojan-Downloader.Win32.VB.wd skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08C00000.VBN Infected: Backdoor.Win32.Rbot.arm skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08C00001.VBN Infected: Backdoor.Win32.Rbot.arm skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E940000.VBN Infected: Backdoor.Win32.Rbot.arm skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E940002.VBN Infected: Trojan-Downloader.Win32.VB.wd skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E940004.VBN Infected: Trojan-Downloader.Win32.VB.wy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E940006.VBN Infected: Backdoor.Win32.Rbot.arm skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E940008.VBN Infected: Trojan-Downloader.Win32.VB.wg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E94000A.VBN Infected: Trojan-Clicker.Win32.VB.le skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E94000C.VBN Infected: Trojan-Clicker.Win32.VB.lg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E94000E.VBN Infected: Trojan-Clicker.Win32.VB.ld skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E940010.VBN Infected: Trojan.Win32.StartPage.ahg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E940012.VBN Infected: Backdoor.Win32.Rbot.arm skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E940013.VBN Infected: Backdoor.Win32.Rbot.aqj skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E940015.VBN Infected: Trojan-Downloader.Win32.VB.wg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E940017.VBN Infected: Trojan-Downloader.Win32.VB.wy skipped
C:\Documents and Settings\jag själv\Local Settings\Temporary Internet Files\Content.IE5\3TGD0KSO\mc-110-12-0000228[1].exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.p skipped
C:\Documents and Settings\jag själv\Local Settings\Temporary Internet Files\Content.IE5\3TGD0KSO\mc-110-12-0000228[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\jag själv\Local Settings\Temporary Internet Files\Content.IE5\JDNGQZEJ\launcher[1].exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.p skipped
C:\Documents and Settings\jag själv\Local Settings\Temporary Internet Files\Content.IE5\JDNGQZEJ\launcher[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\jag själv\Local Settings\Temporary Internet Files\Content.IE5\SK7TCU93\installer[1].exe/data0001 Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\Documents and Settings\jag själv\Local Settings\Temporary Internet Files\Content.IE5\SK7TCU93\installer[1].exe Inno: infected - 1 skipped
C:\Documents and Settings\jag själv\Local Settings\Temporary Internet Files\Content.IE5\SK7TCU93\keyboard1[1].exe Infected: Trojan-Downloader.Win32.VB.ys skipped
C:\Documents and Settings\jag själv\Local Settings\Temporary Internet Files\Content.IE5\VIIF58HI\freeprodtb[1].exe/stream/data0007 Infected: not-a-virus:AdWare.Win32.Softomate.j skipped
C:\Documents and Settings\jag själv\Local Settings\Temporary Internet Files\Content.IE5\VIIF58HI\freeprodtb[1].exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.j skipped
C:\Documents and Settings\jag själv\Local Settings\Temporary Internet Files\Content.IE5\VIIF58HI\freeprodtb[1].exe NSIS: infected - 2 skipped
C:\keyboard1.exe Infected: Trojan-Downloader.Win32.VB.ys skipped
C:\RECYCLER\S-1-5-21-682003330-1343024091-854245398-1003\Dc339.exe/stream/data0007 Infected: not-a-virus:AdWare.Win32.Softomate.j skipped
C:\RECYCLER\S-1-5-21-682003330-1343024091-854245398-1003\Dc339.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.j skipped
C:\RECYCLER\S-1-5-21-682003330-1343024091-854245398-1003\Dc339.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013055.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.h skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013063.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.p skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013063.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013064.exe Infected: Trojan-Dropper.Win32.Agent.aac skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013065.exe Infected: Trojan-Dropper.Win32.Agent.aac skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013067.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013068.dll Infected: not-a-virus:AdWare.Win32.Softomate.j skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013174.exe Infected: Trojan-Downloader.Win32.VB.vz skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013175.exe Infected: Trojan-Downloader.Win32.VB.wr skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013180.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.h skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013192.exe Infected: Trojan-Downloader.Win32.VB.vz skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013193.exe Infected: Trojan-Downloader.Win32.VB.wr skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013215.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013222.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013228.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013231.exe Infected: Backdoor.Win32.PoeBot.b skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013267.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013270.EXE/data0001 Infected: Trojan-Downloader.NSIS.Agent.p skipped
C:\System Volume Information\_restore{D6A7A5A6-B4D8-4ACE-B365-FD4C142AC5F5}\RP60\A0013270.EXE NSIS: infected - 1 skipped
 
hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 10:02:48, on 2006-03-19
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\On Screen Display\Hotkey.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Norton Utilities\SYSDOC32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\JAGSJL~1\LOCALS~1\Temp\Rar$EX01.380\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KeybdUtility] "C:\Program Files\On Screen Display\Hotkey.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ????? - {0713E8D2-850A-101B-AFC0-4210102A8DA7} - C:\ChineseLib\renyuannote.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: AutoLogin - {D04AA3F7-DEE7-479B-A153-24E6C36300C0} - C:\PROGRA~1\Q2\al2dll.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{F14FE083-7AF1-4807-B3DF-73D0271D8D23}: NameServer = 211.150.124.66 211.150.125.194
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\SW5ncmlk\command.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NProtect.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed Disk\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

-------------------------------------------
Perhaps I have sent the kaspersky on-line scanner report in a wrong order: from the last one to the first one.:( I am sorry...
 
hi

dont worry, i got the info

this file needs to be deleted:
C:\WINDOWS\system32\i



the kaspersky scan mentioned parite worm
download its removal tool from
http://www3.ca.com/Files/VirusInformationAndPrevention/ClnPinfi.zip
unzip and read the read me carefully. then run the tool

reboot if necessary

Please download delcmdservice (by Marckie), and save it to your Desktop.
http://users.telenet.be/marcvn/tools/delcmdservice.zip
Unzip the content to your Desktop (a folder named delcmdservice)
Double-click on the delcmdservice folder
Double-click on delreg.bat to launch the tool
When the tool has finished, please reboot your computer
Once rebooted, please scan with HijackThis! and post the new log, in your next reply

NOTE: your hijackthis seems to be in a temp directory. you must unzip it, to your desktop for example before we fix anything with it
 
the hijackthis.log

Logfile of HijackThis v1.99.1
Scan saved at 22:47:13, on 2006-03-19
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\On Screen Display\Hotkey.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Norton Utilities\SYSDOC32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KeybdUtility] "C:\Program Files\On Screen Display\Hotkey.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ????? - {0713E8D2-850A-101B-AFC0-4210102A8DA7} - C:\ChineseLib\renyuannote.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: AutoLogin - {D04AA3F7-DEE7-479B-A153-24E6C36300C0} - C:\PROGRA~1\Q2\al2dll.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{F14FE083-7AF1-4807-B3DF-73D0271D8D23}: NameServer = 211.150.124.66 211.150.125.194
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NProtect.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed Disk\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 
Hi! I have a problem

now. i disabled the

Realtime Protection in

Norton when i ran the

tool, but i can not scan

my computer with

Norton now. I got a

failermessage when i

tried to scan my

computer: Could not

start scan. Scan engine

returned error

0x20000058

I use Symantec

AntiVirus Corporate

Edition. Full version:

8.1.0.821

What do you think can

be the problem?

/Xiaojing
 
hi

i really think a reinstall of teh antivirus is in order.

the hjt log is clean ;)
are there other problems ?
 
As the problem appears to be resolved this topic will be archived.
If you need it re-opened please send me a pm and provide a link to the thread.
Glad we could help, thank you illukka.
 
Last edited:
Thanks!

Thank you very much! This is the new hijackthis log:
-------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 18:17:17, on 2006-03-28
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\On Screen Display\Hotkey.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Norton Utilities\SYSDOC32.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\JAGSJL~1\LOCALS~1\Temp\Rar$EX01.787\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KeybdUtility] "C:\Program Files\On Screen Display\Hotkey.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ????? - {0713E8D2-850A-101B-AFC0-4210102A8DA7} - C:\ChineseLib\renyuannote.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: AutoLogin - {D04AA3F7-DEE7-479B-A153-24E6C36300C0} - C:\PROGRA~1\Q2\al2dll.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NProtect.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed Disk\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 
hi

thanks for coming back :)

the log appears to be clean now, but is the problem with the antivirus program resolved now ?

also there are some things that need your immediate attention:


Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

you have an unpatched version of windows. its like an open door at night for thieves.. waiting to pick up viruses and malware through its countless security holes..

see this post by tashi:
http://forums.spybot.info/showthread.php?t=425

immediately download the necessary security patches
 
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  1. Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

    You can find instructions on how to enable and reenable system restore here:

    Managing Windows Millenium System Restore

    or

    Windows XP System Restore Guide

    Reenable system restore with instructions from tutorial above

  2. Make your Internet Explorer more secure - This can be done by following these simple instructions:
    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    5. Next press the Apply button and then the OK to exit the Internet Properties page.
  3. Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  4. Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  5. Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  6. Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  7. Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  8. Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  9. Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  10. Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

here are some additional utilities that will enhance your safety

  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software

also remember to keep your java updated, see this topic for instructions
http://forums.spybot.info/showthread.php?t=2559
 
Back
Top