MGTcomputerdoc
New member
I was downloading some travel directions for a friend, got a quick popup and for 2 weeks, have been unable to get rid of this thing. Have run Spybot 1.5.2 multiple times in Safe mode but whenever I try to run Windows, I get the same files on system. Can you help?
HiJack and Kaspersky files below:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 29, 2008 5:18:04 AM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/04/2008
Kaspersky Anti-Virus database records: 729371
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 81912
Number of viruses found: 29
Number of infected objects: 99
Number of suspicious objects: 0
Duration of the scan process: 05:34:53
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/LMIinit.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe/data.rar Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe RarSFX: infected - 5 skipped
C:\Documents and Settings\Mike\Local Settings\Temp\asmfiles.cab/asm.exe Infected: not-a-virus:AdWare.Win32.Altnet.l skipped
C:\Documents and Settings\Mike\Local Settings\Temp\asmfiles.cab/asmps.dll Infected: not-a-virus:AdWare.Win32.Altnet.t skipped
C:\Documents and Settings\Mike\Local Settings\Temp\asmfiles.cab CAB: infected - 2 skipped
C:\Documents and Settings\Mike\Local Settings\Temp\__unin__.exe Infected: not-a-virus:AdWare.Win32.Altnet.g skipped
C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\Content.IE5\NN9RFPCW\Cool%20edit%20pro%202.0[1].exe/data.rar/microbyte.vbs Infected: Trojan.VBS.Agent.u skipped
C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\Content.IE5\NN9RFPCW\Cool%20edit%20pro%202.0[1].exe/data.rar Infected: Trojan.VBS.Agent.u skipped
C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\Content.IE5\NN9RFPCW\Cool%20edit%20pro%202.0[1].exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/LMIinit.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe/data.rar Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe RarSFX: infected - 5 skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Microsoft Keyfinder.zip/keyfinder.exe/data.rar/xpkey.exe Infected: not-a-virus
SWTool.Win32.RAS.g skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Microsoft Keyfinder.zip/keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Microsoft Keyfinder.zip/keyfinder.exe/data.rar Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Microsoft Keyfinder.zip/keyfinder.exe Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Microsoft Keyfinder.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temp\~DF285C.tmp Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temp\~DFDD75.tmp Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temporary Internet Files\Content.IE5\IB6N0NED\CAPSM99R Infected: Packed.Win32.Monder.gen skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temporary Internet Files\Content.IE5\IB6N0NED\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pjx skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\ntuser.dat.LOG Object is locked skipped
C:\Games\santafree2.exe/swshop.exe/BSAVEINST.EXE/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.e skipped
C:\Games\santafree2.exe/swshop.exe/BSAVEINST.EXE/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Games\santafree2.exe/swshop.exe/BSAVEINST.EXE/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Games\santafree2.exe/swshop.exe/BSAVEINST.EXE Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Games\santafree2.exe/swshop.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Games\santafree2.exe ZIP: infected - 5 skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe/v2.0.4.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe/v2.0.4.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe/v2.0.4.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe/v2.0.4.cab Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Games\SuperEB_install_22.exe Vise: infected - 6 skipped
C:\microbyte.vbs Infected: Trojan.VBS.Agent.u skipped
C:\Program Files\CA\SharedComponents\PPRT\logs\2008-04-28.csv Object is locked skipped
C:\TEMP\ja.com Infected: Trojan-Dropper.Win32.Agent.atn skipped
C:\Upgrades\DivXPro502GAINBundle.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped
C:\Upgrades\DivXPro502GAINBundle.exe Vise: infected - 1 skipped
C:\Upgrades\dolphinfree.exe/WISE0036.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Upgrades\dolphinfree.exe/WISE0037.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Upgrades\dolphinfree.exe/WISE0038.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar/whAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.351 skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.381 skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar/whSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.370 skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\dolphinfree.exe/WISE0040.BIN Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
C:\Upgrades\dolphinfree.exe WiseSFX: infected - 11 skipped
C:\Upgrades\dolphinfree.exe WiseSFXDropper: infected - 11 skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe/v2.0.4.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe/v2.0.4.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe/v2.0.4.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe/v2.0.4.cab Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Upgrades\HEMI_install.exe Vise: infected - 6 skipped
C:\Upgrades\santafree.exe/WISE0049.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0049.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0049.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0052.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0052.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0052.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0053.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar/WhAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar/WhSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar/Webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0055.BIN Infected: not-a-virus:Server-Proxy.Win32.MarketScore.h skipped
C:\Upgrades\santafree.exe/WISE0056.BIN Infected: not-a-virus:Server-Proxy.Win32.MarketScore.i skipped
C:\Upgrades\santafree.exe WiseSFX: infected - 16 skipped
C:\Upgrades\santafree.exe WiseSFXDropper: infected - 16 skipped
C:\Upgrades\snowfree2.exe/snowy.exe/BSAVEINST.EXE/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.e skipped
C:\Upgrades\snowfree2.exe/snowy.exe/BSAVEINST.EXE/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\snowfree2.exe/snowy.exe/BSAVEINST.EXE/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\snowfree2.exe/snowy.exe/BSAVEINST.EXE Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\snowfree2.exe/snowy.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\snowfree2.exe ZIP: infected - 5 skipped
C:\Upgrades\turkeyfree.exe/turkeyfreesetup.exe/BSAVEINST.EXE/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.e skipped
C:\Upgrades\turkeyfree.exe/turkeyfreesetup.exe/BSAVEINST.EXE/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\turkeyfree.exe/turkeyfreesetup.exe/BSAVEINST.EXE/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\turkeyfree.exe/turkeyfreesetup.exe/BSAVEINST.EXE Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\turkeyfree.exe/turkeyfreesetup.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\turkeyfree.exe ZIP: infected - 5 skipped
C:\Upgrades\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Resources\DriveSrv.dll Infected: Trojan.Win32.Agent.keu skipped
C:\WINNT\Resources\DrvAvp.dll Infected: Trojan.Win32.Agent.keu skipped
C:\WINNT\Resources\ServiceVolume.dll Infected: Trojan.Win32.Agent.keu skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\hgGyywxW.dll Infected: Packed.Win32.Monder.gen skipped
C:\WINNT\system32\Perflib_Perfdata_3f4.dat Object is locked skipped
C:\WINNT\system32\yayaXPhE.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pjw skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:25:54 AM, on 4/29/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Documents and Settings\All Users.WINNT\Application Data\dyzitsfm\fsbopsxw.exe
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\system32\spool\DRIVERS\W32X86\hpoopm07.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINNT\System32\DLA\DLACTRLW.EXE
C:\WINNT\system32\ctfmon.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\explorer.exe
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temporary Internet Files\Content.IE5\9VNBH1CE\HiJackThis[1].exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {14CE45C5-2B48-408F-9BF0-11C34E85F9FD} - C:\WINNT\system32\hgGyywxW.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINNT\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {92264836-839F-46F0-A4FC-CF10207FB3B1} - C:\WINNT\system32\pmnkHWOE.dll (file missing)
O2 - BHO: (no name) - {FCBABDA2-801E-4F51-B6E8-0122032FB16B} - C:\WINNT\system32\yayaXPhE.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: qtvglped - {74E5E4E8-79DD-49AC-B64B-E74822D5F3CD} - C:\DOCUME~1\MIKE~1.GAM\LOCALS~1\Temp\ac8zt2\qtvglped.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINNT\system32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [DLA] C:\WINNT\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R200 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /M "Stylus Photo R200" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [R4xqMScv9w] C:\Documents and Settings\All Users.WINNT\Application Data\dyzitsfm\fsbopsxw.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1194506362750
O20 - Winlogon Notify: yayaXPhE - C:\WINNT\SYSTEM32\yayaXPhE.dll
O21 - SSODL: ServiceVolume - {3ba238aa-aa55-416f-bbae-c30056ac7730} - C:\WINNT\Resources\ServiceVolume.dll
O21 - SSODL: zip - {6a63b924-4984-448e-9258-054e502d5c9d} - C:\WINNT\Installer\{6a63b924-4984-448e-9258-054e502d5c9d}\zip.dll (file missing)
O21 - SSODL: omlbpkaw - {636EBCD6-6EB2-41BD-8DF0-6E0B18A747AA} - C:\WINNT\omlbpkaw.dll (file missing)
O21 - SSODL: pmsoarbf - {42F7DCD7-0C95-4307-85EE-F7B133D5A9B6} - C:\WINNT\pmsoarbf.dll (file missing)
O21 - SSODL: DrvAvp - {3f913173-538c-4148-8c47-2bed89337667} - C:\WINNT\Resources\DrvAvp.dll
O21 - SSODL: DriveSrv - {3617afb0-a8e4-4949-82d7-6fb575f616dd} - C:\WINNT\Resources\DriveSrv.dll
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINNT\privacy_danger\index.htm
--
End of file - 8111 bytes
HiJack and Kaspersky files below:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 29, 2008 5:18:04 AM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/04/2008
Kaspersky Anti-Virus database records: 729371
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 81912
Number of viruses found: 29
Number of infected objects: 99
Number of suspicious objects: 0
Duration of the scan process: 05:34:53
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/LMIinit.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe/data.rar Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike\Desktop\Flash Drive\LogMeIn.exe RarSFX: infected - 5 skipped
C:\Documents and Settings\Mike\Local Settings\Temp\asmfiles.cab/asm.exe Infected: not-a-virus:AdWare.Win32.Altnet.l skipped
C:\Documents and Settings\Mike\Local Settings\Temp\asmfiles.cab/asmps.dll Infected: not-a-virus:AdWare.Win32.Altnet.t skipped
C:\Documents and Settings\Mike\Local Settings\Temp\asmfiles.cab CAB: infected - 2 skipped
C:\Documents and Settings\Mike\Local Settings\Temp\__unin__.exe Infected: not-a-virus:AdWare.Win32.Altnet.g skipped
C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\Content.IE5\NN9RFPCW\Cool%20edit%20pro%202.0[1].exe/data.rar/microbyte.vbs Infected: Trojan.VBS.Agent.u skipped
C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\Content.IE5\NN9RFPCW\Cool%20edit%20pro%202.0[1].exe/data.rar Infected: Trojan.VBS.Agent.u skipped
C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\Content.IE5\NN9RFPCW\Cool%20edit%20pro%202.0[1].exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/LMIinit.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe/data.rar/LogMeIn.msi Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe/data.rar Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Flash Drive\LogMeIn.exe RarSFX: infected - 5 skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Microsoft Keyfinder.zip/keyfinder.exe/data.rar/xpkey.exe Infected: not-a-virus

C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Microsoft Keyfinder.zip/keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus

C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Microsoft Keyfinder.zip/keyfinder.exe/data.rar Infected: not-a-virus

C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Microsoft Keyfinder.zip/keyfinder.exe Infected: not-a-virus

C:\Documents and Settings\Mike.GAMING-MONSTER\Desktop\Microsoft Keyfinder.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temp\~DF285C.tmp Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temp\~DFDD75.tmp Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temporary Internet Files\Content.IE5\IB6N0NED\CAPSM99R Infected: Packed.Win32.Monder.gen skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temporary Internet Files\Content.IE5\IB6N0NED\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pjx skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Mike.GAMING-MONSTER\ntuser.dat.LOG Object is locked skipped
C:\Games\santafree2.exe/swshop.exe/BSAVEINST.EXE/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.e skipped
C:\Games\santafree2.exe/swshop.exe/BSAVEINST.EXE/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Games\santafree2.exe/swshop.exe/BSAVEINST.EXE/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Games\santafree2.exe/swshop.exe/BSAVEINST.EXE Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Games\santafree2.exe/swshop.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Games\santafree2.exe ZIP: infected - 5 skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe/v2.0.4.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe/v2.0.4.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe/v2.0.4.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe/v2.0.4.cab Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Games\SuperEB_install_22.exe/cccc20030730.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Games\SuperEB_install_22.exe Vise: infected - 6 skipped
C:\microbyte.vbs Infected: Trojan.VBS.Agent.u skipped
C:\Program Files\CA\SharedComponents\PPRT\logs\2008-04-28.csv Object is locked skipped
C:\TEMP\ja.com Infected: Trojan-Dropper.Win32.Agent.atn skipped
C:\Upgrades\DivXPro502GAINBundle.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped
C:\Upgrades\DivXPro502GAINBundle.exe Vise: infected - 1 skipped
C:\Upgrades\dolphinfree.exe/WISE0036.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Upgrades\dolphinfree.exe/WISE0037.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Upgrades\dolphinfree.exe/WISE0038.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar/whAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.351 skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.381 skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar/whSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.370 skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\dolphinfree.exe/WISE0039.BIN Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\dolphinfree.exe/WISE0040.BIN Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
C:\Upgrades\dolphinfree.exe WiseSFX: infected - 11 skipped
C:\Upgrades\dolphinfree.exe WiseSFXDropper: infected - 11 skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe/v2.0.4.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe/v2.0.4.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe/v2.0.4.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe/v2.0.4.cab Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Upgrades\HEMI_install.exe/cccc20030730.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Upgrades\HEMI_install.exe Vise: infected - 6 skipped
C:\Upgrades\santafree.exe/WISE0049.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0049.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0049.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0052.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0052.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0052.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Upgrades\santafree.exe/WISE0053.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar/WhAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar/WhSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar/Webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0054.BIN Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Upgrades\santafree.exe/WISE0055.BIN Infected: not-a-virus:Server-Proxy.Win32.MarketScore.h skipped
C:\Upgrades\santafree.exe/WISE0056.BIN Infected: not-a-virus:Server-Proxy.Win32.MarketScore.i skipped
C:\Upgrades\santafree.exe WiseSFX: infected - 16 skipped
C:\Upgrades\santafree.exe WiseSFXDropper: infected - 16 skipped
C:\Upgrades\snowfree2.exe/snowy.exe/BSAVEINST.EXE/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.e skipped
C:\Upgrades\snowfree2.exe/snowy.exe/BSAVEINST.EXE/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\snowfree2.exe/snowy.exe/BSAVEINST.EXE/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\snowfree2.exe/snowy.exe/BSAVEINST.EXE Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\snowfree2.exe/snowy.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\snowfree2.exe ZIP: infected - 5 skipped
C:\Upgrades\turkeyfree.exe/turkeyfreesetup.exe/BSAVEINST.EXE/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.e skipped
C:\Upgrades\turkeyfree.exe/turkeyfreesetup.exe/BSAVEINST.EXE/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\turkeyfree.exe/turkeyfreesetup.exe/BSAVEINST.EXE/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\turkeyfree.exe/turkeyfreesetup.exe/BSAVEINST.EXE Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\turkeyfree.exe/turkeyfreesetup.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
C:\Upgrades\turkeyfree.exe ZIP: infected - 5 skipped
C:\Upgrades\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Resources\DriveSrv.dll Infected: Trojan.Win32.Agent.keu skipped
C:\WINNT\Resources\DrvAvp.dll Infected: Trojan.Win32.Agent.keu skipped
C:\WINNT\Resources\ServiceVolume.dll Infected: Trojan.Win32.Agent.keu skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\hgGyywxW.dll Infected: Packed.Win32.Monder.gen skipped
C:\WINNT\system32\Perflib_Perfdata_3f4.dat Object is locked skipped
C:\WINNT\system32\yayaXPhE.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pjw skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:25:54 AM, on 4/29/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Documents and Settings\All Users.WINNT\Application Data\dyzitsfm\fsbopsxw.exe
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\system32\spool\DRIVERS\W32X86\hpoopm07.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINNT\System32\DLA\DLACTRLW.EXE
C:\WINNT\system32\ctfmon.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\explorer.exe
C:\Documents and Settings\Mike.GAMING-MONSTER\Local Settings\Temporary Internet Files\Content.IE5\9VNBH1CE\HiJackThis[1].exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {14CE45C5-2B48-408F-9BF0-11C34E85F9FD} - C:\WINNT\system32\hgGyywxW.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINNT\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {92264836-839F-46F0-A4FC-CF10207FB3B1} - C:\WINNT\system32\pmnkHWOE.dll (file missing)
O2 - BHO: (no name) - {FCBABDA2-801E-4F51-B6E8-0122032FB16B} - C:\WINNT\system32\yayaXPhE.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: qtvglped - {74E5E4E8-79DD-49AC-B64B-E74822D5F3CD} - C:\DOCUME~1\MIKE~1.GAM\LOCALS~1\Temp\ac8zt2\qtvglped.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINNT\system32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [DLA] C:\WINNT\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R200 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /M "Stylus Photo R200" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [R4xqMScv9w] C:\Documents and Settings\All Users.WINNT\Application Data\dyzitsfm\fsbopsxw.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1194506362750
O20 - Winlogon Notify: yayaXPhE - C:\WINNT\SYSTEM32\yayaXPhE.dll
O21 - SSODL: ServiceVolume - {3ba238aa-aa55-416f-bbae-c30056ac7730} - C:\WINNT\Resources\ServiceVolume.dll
O21 - SSODL: zip - {6a63b924-4984-448e-9258-054e502d5c9d} - C:\WINNT\Installer\{6a63b924-4984-448e-9258-054e502d5c9d}\zip.dll (file missing)
O21 - SSODL: omlbpkaw - {636EBCD6-6EB2-41BD-8DF0-6E0B18A747AA} - C:\WINNT\omlbpkaw.dll (file missing)
O21 - SSODL: pmsoarbf - {42F7DCD7-0C95-4307-85EE-F7B133D5A9B6} - C:\WINNT\pmsoarbf.dll (file missing)
O21 - SSODL: DrvAvp - {3f913173-538c-4148-8c47-2bed89337667} - C:\WINNT\Resources\DrvAvp.dll
O21 - SSODL: DriveSrv - {3617afb0-a8e4-4949-82d7-6fb575f616dd} - C:\WINNT\Resources\DriveSrv.dll
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINNT\privacy_danger\index.htm
--
End of file - 8111 bytes