Hi. I have been infected with some spyware and whenever I open Internet Explorer and Firefox I am getting pop ups asking me to install AntispywareMaster. I scanned with Spyboot and it found Virtumonde.dll so it removed it but still getting the popups.
What is the file lqhvjsqg.dll? Every time I try to remove it from start up, it puts its self back on system startup.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:55, on 2008-05-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Xobni\XobniService.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
C:\WINDOWS\P1370Mon.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Iconic Tray\it.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\WINDOWS\FSScrCtl.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Safari\Safari.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.savewealth.com/support/ie6/complete/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Spybot- Search & Destroy
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
O2 - BHO: (no name) - {28FA97BF-F731-481E-9718-EF33BBAE29A8} - (no file)
O2 - BHO: (no name) - {2EB1FA82-7202-4085-8E69-F3F9AB1AD59D} - (no file)
O2 - BHO: (no name) - {3E020B46-47AA-4862-875A-CF52B802D04E} - (no file)
O2 - BHO: (no name) - {44168FA6-2616-4FE4-95B4-FB6875DAB7D7} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {85CF4327-68DE-1974-B32E-766E84A9706C} - C:\WINDOWS\wcidBHO.dll
O2 - BHO: (no name) - {8AD701AE-B646-48B8-BCF7-ADD4EBD177AD} - (no file)
O2 - BHO: Encarta Web Companion Helper Object - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: (no name) - {C23635D6-DB5C-43C6-9A42-A4C42E20177A} - (no file)
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: Vazu Mobile Toolbar - {D772C84A-0605-4025-8103-40305D6C47B7} - C:\Program Files\Vazu\VazuMobileBar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [KBD] "C:\HP\KBD\KBD.EXE"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "HDAudPropShortcut.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [SoundMan] "SOUNDMAN.EXE"
O4 - HKLM\..\Run: [AVFX Engine] "C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe"
O4 - HKLM\..\Run: [P1370Mon.exe] "C:\WINDOWS\P1370Mon.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [BM7f087710] Rundll32.exe "C:\WINDOWS\system32\lqhvjsqg.dll",s
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [Iconic Tray] "C:\Program Files\Iconic Tray\it.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WeatherEye] "C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe"
O4 - HKUS\S-1-5-21-1177238915-57989841-682003330-1003\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" (User '?')
O4 - HKUS\S-1-5-21-1177238915-57989841-682003330-1003\..\Run: [Iconic Tray] "C:\Program Files\Iconic Tray\it.exe" (User '?')
O4 - HKUS\S-1-5-21-1177238915-57989841-682003330-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1177238915-57989841-682003330-1003\..\Run: [WeatherEye] "C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" (User '?')
O4 - S-1-5-21-1177238915-57989841-682003330-1003 Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe (User '?')
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: + Offline &Explorer: Download the link - file://C:\Program Files\Offline Explorer\Add_UrlO.htm
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - file://C:\Program Files\Offline Explorer\Add_AllO.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Copy to &Lightning Note - C:\Program Files\WordPerfect Lightning\Programs\WPLightningCopyToNote.hta
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI69DF~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Vazu: Send &this image to my phone - C:\Program Files\Vazu\sendtext.htm
O8 - Extra context menu item: Vazu: Send &this text to my phone - C:\Program Files\Vazu\sendtext.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {144FDEB7-A23D-4D39-A00E-AA44195535B6} - C:\WINDOWS\wcidButton.exe
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI69DF~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI69DF~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI69DF~1\Office12\REFIEBAR.DLL
O9 - Extra button: Vazu Mobile - {9F618E2B-154A-493e-8F8F-453252B8EDAF} - C:\Program Files\Vazu\VazuMobileBar.dll
O9 - Extra 'Tools' menuitem: Vazu Mobile Toolbar - {9F618E2B-154A-493e-8F8F-453252B8EDAF} - C:\Program Files\Vazu\VazuMobileBar.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: ConferenceRoom Java Client - http://irc.albasoul.com:8081/java/cr.cab
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/0.9.0929.18/WinSSWebAgent.CAB
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124203214057
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136393781437
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - http://sscnet.uwo.ca/msrdp.cab
O16 - DPF: {82F2D6B2-6C58-4404-A930-9DB0FD90D4B1} (Driver_Detective_v43_Non_Member.DD_v43) - http://www.drivershq.com/cab/prod/Driver_Detective_v43_Non_Member.CAB
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CCC46940-DED0-476C-A27E-115B10DAE0B4} -
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1CE9FA8B-8802-416C-9B27-6B070FB9B379}: NameServer = 192.168.0.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office 2007\Office12\GrooveSystemServices.dll
O18 - Filter: text/xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: text/xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NSCService - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Auto Power-on & Shut-down Service (PCAutoPowerOnService) - Unknown owner - C:\Program Files\Auto Power-on\PCAutoPowerOnService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe
--
End of file - 14282 bytes
KASPERSKY 6.0 ANTIVIRUS LOG
Protection
----------
Total scanned: 8466
Detected: 3
Untreated: 0
Start time: 2008-05-20 08:52
Duration: 01:04:03
Detected
--------
Status Object
------ ------
detected: riskware Invader Running process: C:\WINDOWS\Explorer.EXE
detected: riskware Invader Running process: C:\WINDOWS\system32\winlogon.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.sfm File: c:\windows\system32\kapxstye.dll
Events
------
Time Event
---- -----
2008-05-19 20:39 Protection of your computer started.
2008-05-19 20:39 Update completed successfully
2008-05-19 20:39 Threat signatures are up-to-date
2008-05-19 20:40 Running process C:\WINDOWS\Explorer.EXE: detected modification of riskware 'Invader'.
2008-05-19 20:40 Process C:\WINDOWS\Explorer.EXE (PID: 416): attempt to embed itself into another process was blocked.
2008-05-19 20:40 Running process C:\WINDOWS\Explorer.EXE: detected modification of riskware 'Invader'.
2008-05-19 20:40 Process C:\WINDOWS\Explorer.EXE (PID: 416): attempt to embed itself into another process was blocked.
2008-05-19 20:42 Running process C:\WINDOWS\system32\winlogon.exe: detected modification of riskware 'Invader'.
2008-05-19 20:42 Process C:\WINDOWS\system32\winlogon.exe (PID: 1100): attempt to embed itself into another process was blocked.
2008-05-19 20:42 Protection of your computer is not running. You are advised to resume protection.
2008-05-19 22:17 System is running in safe mode. Some protection components are disabled.
2008-05-19 22:17 Update can not be started because of error: task cannot be started in the safe mode
2008-05-19 22:47 Update can not be started because of error: task cannot be started in the safe mode
2008-05-19 22:58 System is running in safe mode. Some protection components are disabled.
2008-05-19 22:58 Update can not be started because of error: task cannot be started in the safe mode
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: detected adware 'not-a-virus:AdWare.Win32.Virtumonde.sfm'.
2008-05-19 23:01 Security threats have been detected. You are advised to neutralize them immediately.
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: detected adware 'not-a-virus:AdWare.Win32.Virtumonde.sfm'.
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: is still infected, postponed.
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: detected adware 'not-a-virus:AdWare.Win32.Virtumonde.sfm'.
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: is still infected, postponed.
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: is still infected, postponed.
2008-05-19 23:02 File c:\windows\system32\kapxstye.dll: detected adware 'not-a-virus:AdWare.Win32.Virtumonde.sfm'.
2008-05-19 23:03 File c:\windows\system32\kapxstye.dll: deleted.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RegistryFix.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RegistryFix.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip/removalfile.bat: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde3.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde3.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip/fcccdCrs.dll: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll2.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll2.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll3.zip/fcccdCrs.dll_old: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll3.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll4.zip/ssqRHwWQ.dll: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll4.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll5.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll5.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll6.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll6.zip/sbRecovery.ini: is password protected.
2008-05-19 23:38 File C:\Documents and Settings\HP\Local Settings\Temp\{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}~setup\P2V.cab/VMware_Agent.msi//Data1.cab/reconfigurationDataStore.dat.83E54AD8_8A25_42BE_9B7F_B00EC13C3883/reconfigurationDataStore.xml: is password protected.
2008-05-19 23:38 File C:\Documents and Settings\HP\Local Settings\Temp\{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}~setup\P2V.cab/reconfigurationDataStore.dat.83E54AD8_8A25_42BE_9B7F_B00EC13C3883/reconfigurationDataStore.xml: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Ayers & Reder, 1998.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Higham, 1998.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Jaschinski & Wentura, 2002.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Loftus, 1975.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Loftus, Donders, Hoffman & Schooler, 1989.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Schooler, Gerhard, & Loftus, 1986.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Tousignant, Hall, & Loftus, 1986.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Zaragoza & Mitchell, 1996.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\Psych_280_1st_term_experiment_datafile.zip/Psych_280_1st_term_experiment_datafile.sav: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\group-project-files\Group_Project_data_file.zip/Group Project data file.sav: is password protected.
2008-05-20 08:52 Protection of your computer started.
2008-05-20 08:52 Some protection components are disabled. You are advised to enable them.
2008-05-20 08:53 Update error: DNS name resolving error.
2008-05-20 09:23 Update error: DNS name resolving error.
2008-05-20 09:53 Update completed successfully
Reports
-------
Component Status Start Finish Size
--------- ------ ----- ------ ----
Proactive Defense running 2008-05-20 08:52 53.9 KB
File Anti-Virus running 2008-05-20 08:52 1.6 MB
Update DNS name resolving error 2008-05-20 08:52 2008-05-20 08:53 50.3 KB
Web Anti-Virus running 2008-05-20 08:52 88.8 KB
Update DNS name resolving error 2008-05-20 09:22 2008-05-20 09:23 50.3 KB
Update completed 2008-05-20 09:52 2008-05-20 09:53 27.0 KB
Quarantine
----------
Status Object Size Added
------ ------ ---- -----
Backup
------
Status Object Size
------ ------ ----
Infected: adware not-a-virus:AdWare.Win32.Virtumonde.sfm c:\windows\system32\kapxstye.dll 123 KB
What is the file lqhvjsqg.dll? Every time I try to remove it from start up, it puts its self back on system startup.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:55, on 2008-05-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Xobni\XobniService.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
C:\WINDOWS\P1370Mon.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Iconic Tray\it.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\WINDOWS\FSScrCtl.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Safari\Safari.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.savewealth.com/support/ie6/complete/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Spybot- Search & Destroy
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
O2 - BHO: (no name) - {28FA97BF-F731-481E-9718-EF33BBAE29A8} - (no file)
O2 - BHO: (no name) - {2EB1FA82-7202-4085-8E69-F3F9AB1AD59D} - (no file)
O2 - BHO: (no name) - {3E020B46-47AA-4862-875A-CF52B802D04E} - (no file)
O2 - BHO: (no name) - {44168FA6-2616-4FE4-95B4-FB6875DAB7D7} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {85CF4327-68DE-1974-B32E-766E84A9706C} - C:\WINDOWS\wcidBHO.dll
O2 - BHO: (no name) - {8AD701AE-B646-48B8-BCF7-ADD4EBD177AD} - (no file)
O2 - BHO: Encarta Web Companion Helper Object - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: (no name) - {C23635D6-DB5C-43C6-9A42-A4C42E20177A} - (no file)
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: Vazu Mobile Toolbar - {D772C84A-0605-4025-8103-40305D6C47B7} - C:\Program Files\Vazu\VazuMobileBar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [KBD] "C:\HP\KBD\KBD.EXE"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "HDAudPropShortcut.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [SoundMan] "SOUNDMAN.EXE"
O4 - HKLM\..\Run: [AVFX Engine] "C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe"
O4 - HKLM\..\Run: [P1370Mon.exe] "C:\WINDOWS\P1370Mon.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [BM7f087710] Rundll32.exe "C:\WINDOWS\system32\lqhvjsqg.dll",s
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [Iconic Tray] "C:\Program Files\Iconic Tray\it.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WeatherEye] "C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe"
O4 - HKUS\S-1-5-21-1177238915-57989841-682003330-1003\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" (User '?')
O4 - HKUS\S-1-5-21-1177238915-57989841-682003330-1003\..\Run: [Iconic Tray] "C:\Program Files\Iconic Tray\it.exe" (User '?')
O4 - HKUS\S-1-5-21-1177238915-57989841-682003330-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1177238915-57989841-682003330-1003\..\Run: [WeatherEye] "C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" (User '?')
O4 - S-1-5-21-1177238915-57989841-682003330-1003 Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe (User '?')
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: + Offline &Explorer: Download the link - file://C:\Program Files\Offline Explorer\Add_UrlO.htm
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - file://C:\Program Files\Offline Explorer\Add_AllO.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Copy to &Lightning Note - C:\Program Files\WordPerfect Lightning\Programs\WPLightningCopyToNote.hta
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI69DF~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Vazu: Send &this image to my phone - C:\Program Files\Vazu\sendtext.htm
O8 - Extra context menu item: Vazu: Send &this text to my phone - C:\Program Files\Vazu\sendtext.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {144FDEB7-A23D-4D39-A00E-AA44195535B6} - C:\WINDOWS\wcidButton.exe
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI69DF~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI69DF~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI69DF~1\Office12\REFIEBAR.DLL
O9 - Extra button: Vazu Mobile - {9F618E2B-154A-493e-8F8F-453252B8EDAF} - C:\Program Files\Vazu\VazuMobileBar.dll
O9 - Extra 'Tools' menuitem: Vazu Mobile Toolbar - {9F618E2B-154A-493e-8F8F-453252B8EDAF} - C:\Program Files\Vazu\VazuMobileBar.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: ConferenceRoom Java Client - http://irc.albasoul.com:8081/java/cr.cab
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/0.9.0929.18/WinSSWebAgent.CAB
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124203214057
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136393781437
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - http://sscnet.uwo.ca/msrdp.cab
O16 - DPF: {82F2D6B2-6C58-4404-A930-9DB0FD90D4B1} (Driver_Detective_v43_Non_Member.DD_v43) - http://www.drivershq.com/cab/prod/Driver_Detective_v43_Non_Member.CAB
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CCC46940-DED0-476C-A27E-115B10DAE0B4} -
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1CE9FA8B-8802-416C-9B27-6B070FB9B379}: NameServer = 192.168.0.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office 2007\Office12\GrooveSystemServices.dll
O18 - Filter: text/xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: text/xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NSCService - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Auto Power-on & Shut-down Service (PCAutoPowerOnService) - Unknown owner - C:\Program Files\Auto Power-on\PCAutoPowerOnService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe
--
End of file - 14282 bytes
KASPERSKY 6.0 ANTIVIRUS LOG
Protection
----------
Total scanned: 8466
Detected: 3
Untreated: 0
Start time: 2008-05-20 08:52
Duration: 01:04:03
Detected
--------
Status Object
------ ------
detected: riskware Invader Running process: C:\WINDOWS\Explorer.EXE
detected: riskware Invader Running process: C:\WINDOWS\system32\winlogon.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.sfm File: c:\windows\system32\kapxstye.dll
Events
------
Time Event
---- -----
2008-05-19 20:39 Protection of your computer started.
2008-05-19 20:39 Update completed successfully
2008-05-19 20:39 Threat signatures are up-to-date
2008-05-19 20:40 Running process C:\WINDOWS\Explorer.EXE: detected modification of riskware 'Invader'.
2008-05-19 20:40 Process C:\WINDOWS\Explorer.EXE (PID: 416): attempt to embed itself into another process was blocked.
2008-05-19 20:40 Running process C:\WINDOWS\Explorer.EXE: detected modification of riskware 'Invader'.
2008-05-19 20:40 Process C:\WINDOWS\Explorer.EXE (PID: 416): attempt to embed itself into another process was blocked.
2008-05-19 20:42 Running process C:\WINDOWS\system32\winlogon.exe: detected modification of riskware 'Invader'.
2008-05-19 20:42 Process C:\WINDOWS\system32\winlogon.exe (PID: 1100): attempt to embed itself into another process was blocked.
2008-05-19 20:42 Protection of your computer is not running. You are advised to resume protection.
2008-05-19 22:17 System is running in safe mode. Some protection components are disabled.
2008-05-19 22:17 Update can not be started because of error: task cannot be started in the safe mode
2008-05-19 22:47 Update can not be started because of error: task cannot be started in the safe mode
2008-05-19 22:58 System is running in safe mode. Some protection components are disabled.
2008-05-19 22:58 Update can not be started because of error: task cannot be started in the safe mode
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: detected adware 'not-a-virus:AdWare.Win32.Virtumonde.sfm'.
2008-05-19 23:01 Security threats have been detected. You are advised to neutralize them immediately.
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: detected adware 'not-a-virus:AdWare.Win32.Virtumonde.sfm'.
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: is still infected, postponed.
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: detected adware 'not-a-virus:AdWare.Win32.Virtumonde.sfm'.
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: is still infected, postponed.
2008-05-19 23:01 File c:\windows\system32\kapxstye.dll: is still infected, postponed.
2008-05-19 23:02 File c:\windows\system32\kapxstye.dll: detected adware 'not-a-virus:AdWare.Win32.Virtumonde.sfm'.
2008-05-19 23:03 File c:\windows\system32\kapxstye.dll: deleted.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RegistryFix.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RegistryFix.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip/removalfile.bat: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde3.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde3.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip/fcccdCrs.dll: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll2.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll2.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll3.zip/fcccdCrs.dll_old: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll3.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll4.zip/ssqRHwWQ.dll: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll4.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll5.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll5.zip/sbRecovery.ini: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll6.zip/sbRecovery.reg: is password protected.
2008-05-19 23:16 File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll6.zip/sbRecovery.ini: is password protected.
2008-05-19 23:38 File C:\Documents and Settings\HP\Local Settings\Temp\{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}~setup\P2V.cab/VMware_Agent.msi//Data1.cab/reconfigurationDataStore.dat.83E54AD8_8A25_42BE_9B7F_B00EC13C3883/reconfigurationDataStore.xml: is password protected.
2008-05-19 23:38 File C:\Documents and Settings\HP\Local Settings\Temp\{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}~setup\P2V.cab/reconfigurationDataStore.dat.83E54AD8_8A25_42BE_9B7F_B00EC13C3883/reconfigurationDataStore.xml: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Ayers & Reder, 1998.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Higham, 1998.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Jaschinski & Wentura, 2002.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Loftus, 1975.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Loftus, Donders, Hoffman & Schooler, 1989.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Schooler, Gerhard, & Loftus, 1986.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Tousignant, Hall, & Loftus, 1986.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\articles_for_1st_term_experiment.zip/Zaragoza & Mitchell, 1996.pdf: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\1st-term-experiment\Psych_280_1st_term_experiment_datafile.zip/Psych_280_1st_term_experiment_datafile.sav: is password protected.
2008-05-19 23:57 File C:\download\psychology.uwo.ca\undergraduate\psych280E\group-project-files\Group_Project_data_file.zip/Group Project data file.sav: is password protected.
2008-05-20 08:52 Protection of your computer started.
2008-05-20 08:52 Some protection components are disabled. You are advised to enable them.
2008-05-20 08:53 Update error: DNS name resolving error.
2008-05-20 09:23 Update error: DNS name resolving error.
2008-05-20 09:53 Update completed successfully
Reports
-------
Component Status Start Finish Size
--------- ------ ----- ------ ----
Proactive Defense running 2008-05-20 08:52 53.9 KB
File Anti-Virus running 2008-05-20 08:52 1.6 MB
Update DNS name resolving error 2008-05-20 08:52 2008-05-20 08:53 50.3 KB
Web Anti-Virus running 2008-05-20 08:52 88.8 KB
Update DNS name resolving error 2008-05-20 09:22 2008-05-20 09:23 50.3 KB
Update completed 2008-05-20 09:52 2008-05-20 09:53 27.0 KB
Quarantine
----------
Status Object Size Added
------ ------ ---- -----
Backup
------
Status Object Size
------ ------ ----
Infected: adware not-a-virus:AdWare.Win32.Virtumonde.sfm c:\windows\system32\kapxstye.dll 123 KB