Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

amvo.exe; Win32/nsanti; help[1].exe malware...Please help!


  • This topic is locked This topic is locked

#1
braninho

braninho

    New Member

  • Member
  • Pip
  • 8 posts
Hi there!

I am sorry to bother but approximately 2 weeks ago I copied through USB some files from my friend.
From that time I have a serious problems with the malware (virus, trojan) called amvo.exe, Win32/nsanti and help[1].exe.

I don't know but probably all this things have something to do with each other.

I tried almost everything I could find online about how to get rid of this malware but I didn't succeed.

When I erase amvo.exe, amvo.dll it doesn't help. When I restart my PC and try to open my USB disk on drive F:
NoAdware programm shows that amvo.exe was added to my startup programs again.

Is there anybody that can help me with this. I am getting really desperate.

Thank you very much in advance for your early reply.


Here I'm posting my log from HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:29:07 PM, on 1/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SE...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SE...S01?FORM=TOOLBR
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SE...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\Internet TV\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\Internet TV\FlashGet\getflash.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_link.htm
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c9b12eaa7cb44a169b54f3e4d6eec6e5
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c9b12eaa7cb44a169b54f3e4d6eec6e5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123fd.bay12...es/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase8300.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecu...asyInstallX.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{299F4FC9-2A6C-4D40-AEA5-382035FD868F}: NameServer = 217.118.96.203
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 9528 bytes
  • 0

Advertisements


#2
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
I see that you are running 2 antivirus which is less help rather than more.
Please uninstall Trend Micro Internet Security suite.
=================================
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\amvo.exe
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\amva


  • Return to OTMoveIt2, right click on the "Paste List Of Files/Patterns To Search For and More" window and choose Paste.
  • Click the red Moveit! button.
  • OTMoveit2 will create a log of moved files in the C:\_OTMoveIt\MovedFiles folder. The log's name will appear as the date and time it was created, with the format mmddyyyy_hhmmss.log. Open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
=======================
After OTMoveit 2 Please download FixWareout from here:
http://downloads.sub.../Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.
Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
Once the desktop loads please post the text that will open (report.txt) and a new Hijackthis log
  • 0

#3
braninho

braninho

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi!
Thank you for your fast reply.
I did everything what you said. OTMoveit.exe did not find one of those files. Here is the report:

C:\WINDOWS\system32\amvo.exe moved successfully.
File/Folder HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\amva not found.

Created on 01/12/2008 17:47:37





Here is the report from Fixwareout.exe:

TEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.146 85.255.112.196" <Value cleared.

Successfully flushed the DNS Resolver Cache.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"="lsass.exe"
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe"
"AT-Watch"=""
"avast!"="C:\\PROGRA~1\\Avast4\\ashDisp.exe"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"amva"="C:\\WINDOWS\\system32\\amvo.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~






And new HJT report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:58:51 PM, on 1/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\Notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SE...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SE...S01?FORM=TOOLBR
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SE...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\Internet TV\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\Internet TV\FlashGet\getflash.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_link.htm
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c9b12eaa7cb44a169b54f3e4d6eec6e5
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c9b12eaa7cb44a169b54f3e4d6eec6e5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123fd.bay12...es/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase8300.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecu...asyInstallX.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{299F4FC9-2A6C-4D40-AEA5-382035FD868F}: NameServer = 217.118.96.203
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 9015 bytes


Thank you again. Please let me know what should I do next. After fixing this, when I will connect my USB disk, camera and other USB media again I used before and also during that time I had problem with this malware, will the virus come back or it will be safe?

Thank you. Can't wait for your reply.
  • 0

#4
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Are you saying that your Flash Drive is infected?

Please re-open Hijackthis and click on "Do a system scan only"
Then place a check mark next to these entries below:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


Now click on Fix Checked and then close Hijackthis.
====================================
After that Please download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
  • 0

#5
braninho

braninho

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi again!

Thank you again for helping me.
About the USB drive...I was just asking if that virus is able to copy to USB storage medias? Because I'm using my 120 GB USB Hard Disk, small USB flash drive, copying some pictures from camera through usb etc. I was just wondering if that virus could copy into these drives or if I don't have to worry about it?
I don't know much about this virus so I'm rather asking.




Anyway, here is the ComboFix.txt report:

ComboFix 08-01-13.1 - Branislav Mesaros 2008-01-13 16:50:12.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.206 [GMT 1:00]
Running from: C:\Documents and Settings\Branislav Mesaros\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\Documents and Settings\All Users\Start Menu\UUSEE~1.LNK
C:\Documents and Settings\Branislav Mesaros\Application Data\DriveCleaner 2006 Free
C:\Documents and Settings\Branislav Mesaros\Application Data\DriveCleaner 2006 Free\Logs\update.log
C:\Documents and Settings\Branislav Mesaros\Local Settings\Application Data\baidu
C:\WINDOWS\system32\amvo1.dll
D:\80avp08.com
D:\Autorun.inf
D:\semo2x.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_WERFGH


((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.

2008-01-13 16:48 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-12 13:02 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-01-12 13:02 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-12 13:02 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-12 13:02 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-12 13:02 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-12 13:02 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-12 13:01 . 2008-01-12 13:02 <DIR> d-------- C:\Program Files\Avast4
2008-01-12 13:01 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-01-12 01:28 . 2008-01-12 01:28 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-12 01:28 . 2008-01-12 01:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-11 23:24 . 2008-01-11 23:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-01-11 21:47 . 2006-05-11 06:48 <DIR> d-------- C:\Documents and Settings\Administrator.BRANO\Application Data\Intuit
2008-01-10 00:53 . 2008-01-10 00:53 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-10 00:52 . 2008-01-11 19:12 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\AVG7
2008-01-10 00:51 . 2008-01-11 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-10 00:47 . 2008-01-11 23:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-10 00:16 . 2008-01-10 00:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Genie-Soft
2008-01-10 00:15 . 2008-01-10 00:15 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Genie-Soft
2008-01-10 00:11 . 2007-02-06 16:03 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-01-10 00:11 . 2007-02-02 03:00 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-01-10 00:11 . 2007-02-02 03:00 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-01-10 00:10 . 2008-01-10 00:11 <DIR> d-------- C:\Program Files\Genie Backup Manager Pro 8.0
2008-01-10 00:10 . 2006-11-02 01:50 128,104 --a------ C:\WINDOWS\system32\drivers\WimFltr.sys
2008-01-09 20:27 . 2008-01-11 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-09 20:13 . 2008-01-09 20:13 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-01-09 17:36 . 2008-01-09 17:36 819,200 --a------ C:\WINDOWS\is-RT58A.exe
2008-01-09 17:36 . 2008-01-09 17:36 10,620 --a------ C:\WINDOWS\is-RT58A.msg
2008-01-09 17:36 . 2008-01-09 17:36 1,917 --a------ C:\WINDOWS\is-RT58A.lst
2008-01-09 14:42 . 2008-01-09 14:42 104,392 --a------ C:\tio8x6.cmd
2008-01-09 11:23 . 2008-01-09 11:23 1,355 --a------ C:\WINDOWS\imsins.BAK
2008-01-09 02:15 . 2008-01-10 17:06 <DIR> d-------- C:\Program Files\Uniblue
2008-01-09 02:15 . 2008-01-10 17:06 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Uniblue
2008-01-09 02:15 . 2008-01-09 02:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-01-08 13:28 . 2008-01-08 13:29 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Regrun
2008-01-08 13:28 . 2008-01-08 13:29 <DIR> d-------- C:\backreg
2008-01-08 13:27 . 2008-01-08 13:27 25,773 --a------ C:\WINDOWS\system32\drivers\regguard.sys
2008-01-08 13:27 . C:\WINDOWS\(2) C:\ComboFix\winstart.bat
2008-01-08 13:25 . 2008-01-08 13:54 <DIR> d-------- C:\Program Files\RegRunSuite
2008-01-07 15:04 . 2008-01-07 15:04 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\TrojanHunter
2008-01-07 10:59 . 2008-01-07 13:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-01-07 10:41 . 2008-01-07 13:03 <DIR> d-------- C:\Program Files\Security Task Manager
2008-01-07 10:41 . 2008-01-11 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-01-07 10:16 . 2008-01-11 17:54 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\PrevxCSI
2008-01-07 10:16 . 2008-01-07 10:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-07 10:10 . 2008-01-11 18:12 165 --a------ C:\WINDOWS\startUp manager.INI
2008-01-06 00:47 . 2008-01-06 00:47 <DIR> d-------- C:\Program Files\Ligos
2008-01-06 00:47 . 2000-06-23 10:36 745,984 --a------ C:\WINDOWS\system32\ir50_32.dll
2008-01-06 00:47 . 2000-06-23 14:05 136,704 --a------ C:\WINDOWS\system32\iacenc.dll
2008-01-06 00:47 . 2000-06-22 13:09 56,320 --------- C:\WINDOWS\system32\iyvu9_32.dll
2008-01-05 23:52 . 2008-01-05 23:52 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Media Player Classic
2008-01-05 18:05 . 2005-03-30 05:05 3,031,040 --a------ C:\WINDOWS\system32\NCTVideoTransform.dll
2008-01-05 18:05 . 2003-10-30 16:14 679,936 --a------ C:\WINDOWS\system32\NCTMPEGFile.dll
2008-01-05 18:05 . 2005-02-23 02:32 589,824 --a------ C:\WINDOWS\system32\NCTVideoView.dll
2008-01-05 18:05 . 2003-08-07 04:01 237,568 --a------ C:\WINDOWS\system32\lame_enc.dll
2008-01-05 18:05 . 2004-01-09 03:54 188,416 --a------ C:\WINDOWS\system32\actsplash.ocx
2008-01-05 16:13 . 2008-01-05 16:13 14 --a------ C:\WINDOWS\system32\SystemInfo32.sys
2008-01-05 16:12 . 2008-01-05 16:13 <DIR> d-------- C:\Program Files\DVD X Player 4.1 Professional
2008-01-05 16:12 . 2008-01-05 16:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD X Studios
2008-01-05 00:19 . 2008-01-05 00:19 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Systweak
2008-01-05 00:16 . 2008-01-11 01:48 <DIR> d-------- C:\Program Files\Advanced System Optimizer
2008-01-04 21:09 . 2008-01-06 11:17 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-04 21:09 . 2008-01-04 21:09 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-04 15:44 . 2008-01-04 15:44 <DIR> d-------- C:\Program Files\MP3 programs
2008-01-03 20:10 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-01-03 18:20 . 2008-01-13 16:44 <DIR> d-------- C:\Program Files\PeerGuardian2
2008-01-03 17:17 . 2008-01-06 20:07 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Azureus
2008-01-03 17:17 . 2008-01-03 17:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-01-03 17:10 . 2008-01-03 17:10 <DIR> d-------- C:\Program Files\Azureus
2008-01-03 16:27 . 2008-01-03 16:27 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\FreeCap
2008-01-03 15:36 . 2008-01-12 11:58 <DIR> d-------- C:\Program Files\Hide IP Platinum 3.5
2008-01-03 13:09 . 2008-01-12 17:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-03 13:09 . 2008-01-03 13:10 2,150 --a------ C:\WINDOWS\system32\tmmute.ini
2007-12-31 22:21 . 2007-12-31 22:21 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\InstallShield
2007-12-29 01:39 . 2007-12-29 01:41 <DIR> d-------- C:\Program Files\HyperCam
2007-12-28 14:12 . 2007-12-28 14:42 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\U3
2007-12-26 11:16 . 2007-12-26 11:17 67 --a------ C:\WINDOWS\#1 DVD Ripper.INI
2007-12-25 14:01 . 2007-12-26 11:09 5 --a------ C:\WINDOWS\system32\SySDVD.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-13 15:43 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\uTorrent
2008-01-13 10:58 --------- d-----w C:\Program Files\Mp3 converter
2008-01-12 19:01 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\Skype
2008-01-11 19:08 --------- d-----w C:\Program Files\DVD CD burner
2008-01-11 18:04 --------- d-----w C:\Program Files\NoAdware5.0
2008-01-10 17:18 --------- d-----w C:\Program Files\DVD convert & burn
2008-01-09 21:29 --------- d-----w C:\Program Files\uTorrent
2008-01-07 17:57 --------- d-----w C:\Program Files\DC++
2008-01-07 14:51 --------- d-----w C:\Program Files\Common Files\Real
2008-01-03 17:51 --------- d-----w C:\Program Files\Google
2008-01-03 13:36 --------- d-----w C:\Program Files\Microangelo
2008-01-02 19:12 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\dvdcss
2007-12-15 19:33 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\SopCast
2007-12-12 10:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-11 00:51 --------- d-----w C:\Program Files\Vodei
2007-12-04 16:13 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\ICQ
2007-12-04 10:28 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-20 15:33 --------- d-----w C:\Program Files\Skype
2007-11-20 15:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-11-20 15:32 --------- d-----w C:\Program Files\Common Files\Skype
2007-11-14 17:42 --------- d-----w C:\Program Files\Nero
2007-11-14 17:42 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\Ahead
2007-11-14 17:40 --------- d-----w C:\Program Files\Nero 6
2007-11-14 17:40 --------- d-----w C:\Program Files\Common Files\Ahead
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-05-03 01:17 174 ----a-w C:\Documents and Settings\Branislav Mesaros\Application Data\wklnhst.dat
2007-01-21 18:37 87,608 ----a-w C:\Documents and Settings\Branislav Mesaros\Application Data\ezpinst.exe
2007-01-21 18:37 47,360 ----a-w C:\Documents and Settings\Branislav Mesaros\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 22:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 22:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"AT-Watch"="" []
"avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
Vongo Tray.lnk - C:\Program Files\Vongo\Tray.exe [2006-03-14 17:51:44]

C:\Documents and Settings\Administrator.BRANO\Start Menu\Programs\Startup\
Vongo Tray.lnk - C:\Program Files\Vongo\Tray.exe [2006-03-14 17:51:44]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="lsass.exe"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Branislav Mesaros^Start Menu^Programs^StartUp^Vongo Tray.lnk]
backup=C:\WINDOWS\pss\Vongo Tray.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDial]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLSP Scheduler]
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
--a------ 2006-02-22 16:03 40960 C:\Program Files\HPQ\Default Settings\cpqset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--a------ 2006-06-02 22:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1154847324\EE\AOLHostManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-02-19 09:41 49152 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
--a------ 2006-02-15 03:49 454656 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2006-03-23 13:13 77824 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2006-03-23 13:17 118784 C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2006-03-23 13:17 94208 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-08-12 00:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-08-12 00:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
--a------ 2006-03-07 21:38 131072 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-08-06 07:57 98304 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard]
--------- 2005-10-11 18:23 1187840 C:\Windows\SMINST\RecGuard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
--------- 2006-02-09 17:52 643072 C:\Windows\CREATOR\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-11 06:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2006-03-04 06:46 761948 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2004-12-20 19:41 33792 C:\Program Files\Winamp\winampa.exe

S0 Partizan;Partizan;C:\WINDOWS\system32\drivers\Partizan.sys []
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 15:05]
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys []
S3 RegGuard;RegGuard;C:\WINDOWS\system32\Drivers\regguard.sys [2008-01-08 13:27]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\d.com
\Shell\explore\Command - F:\d.com
\Shell\open\Command - F:\d.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10ddb2e8-2551-11db-91b3-00038a000015}]
\Shell\AutoRun\command - F:\80avp08.com
\Shell\explore\Command - F:\80avp08.com
\Shell\open\Command - F:\80avp08.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10ddb2ea-2551-11db-91b3-00038a000015}]
\Shell\AutoRun\command - F:\d.com
\Shell\explore\Command - F:\d.com
\Shell\open\Command - F:\d.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4572ca8c-7bfc-11db-927c-0014a5b64560}]
\Shell\AutoRun\command - F:\usdeiect.com
\Shell\explore\Command - F:\usdeiect.com
\Shell\open\Command - F:\usdeiect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{50cbc1d2-8ac6-11db-92b2-0014a5b64560}]
\Shell\AutoRun\command - F:\80avp08.com
\Shell\explore\Command - F:\80avp08.com
\Shell\open\Command - F:\80avp08.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{515b49f2-5f84-11dc-9542-0016d43313d2}]
\Shell\AutoRun\command - F:\usdeiect.com
\Shell\explore\Command - F:\usdeiect.com
\Shell\open\Command - F:\usdeiect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a0754fed-5004-11dc-9516-0016d43313d2}]
\Shell\AutoRun\command - F:\u.bat
\Shell\explore\Command - F:\u.bat
\Shell\open\Command - F:\u.bat

.
Contents of the 'Scheduled Tasks' folder
"2008-01-13 15:49:42 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-10 16:06:44 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-01-10 16:06:43 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-01-11 22:48:48 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-13 16:57:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-13 17:00:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-13 16:00:06
.
2008-01-09 10:25:10 --- E O F ---







and new HJT report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:05:05 PM, on 1/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SE...S01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SE...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\Internet TV\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\Internet TV\FlashGet\getflash.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_link.htm
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c9b12eaa7cb44a169b54f3e4d6eec6e5
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c9b12eaa7cb44a169b54f3e4d6eec6e5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123fd.bay12...es/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase8300.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecu...asyInstallX.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{299F4FC9-2A6C-4D40-AEA5-382035FD868F}: NameServer = 217.118.96.203
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 8387 bytes






Thank you very much again for doing this. Please let me know if I have to do something else to fix this virus problem or if it's clear.
  • 0

#6
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Yes your drive F: is infected keep it plugged in for the duration of the fix please.
It is not likely that the other drives are infected but to be sure plug in all devices you are concerned about.
=======================================================================
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\tio8x6.cmd
C:\WINDOWS\imsins.BAK
F:\d.com
F:\80avp08.com
F:\d.com
F:\usdeiect.com
F:\u.bat

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"=""


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
=====================
Also Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Post that log in your next reply.

Edited by kahdah, 13 January 2008 - 12:18 PM.

  • 0

#7
braninho

braninho

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hello!

I did everything you told me to do.
While running DrWeb-cureit.exe I chose "Yes to all" to cure/move.
I was just wondering what was I supposed to with all those files that were moved to report DrWeb.csv at the end. Because when I was exiting the program it asked me if I don't want to do anything with those files in report? It wasn't mentioned in your instructions so I just exited without doing anything.

I am posting the reports you asked me to do:



ComboFix log:

ComboFix 08-01-13.1 - Branislav Mesaros 2008-01-13 23:11:12.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.252 [GMT 1:00]
Running from: C:\Documents and Settings\Branislav Mesaros\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Branislav Mesaros\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\tio8x6.cmd
C:\WINDOWS\imsins.BAK
F:\80avp08.com
F:\d.com
F:\u.bat
F:\usdeiect.com
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\tio8x6.cmd
C:\WINDOWS\imsins.BAK
F:\80avp08.com
F:\Autorun.inf
F:\d.com
F:\semo2x.exe
F:\u.bat
F:\usdeiect.com

.
((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.

2008-01-13 16:48 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-12 13:02 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-01-12 13:02 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-12 13:02 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-12 13:02 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-12 13:02 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-12 13:02 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-12 13:01 . 2008-01-12 13:02 <DIR> d-------- C:\Program Files\Avast4
2008-01-12 13:01 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-01-12 01:28 . 2008-01-12 01:28 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-12 01:28 . 2008-01-12 01:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-11 23:24 . 2008-01-11 23:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-01-11 21:47 . 2006-05-11 06:48 <DIR> d-------- C:\Documents and Settings\Administrator.BRANO\Application Data\Intuit
2008-01-10 00:53 . 2008-01-10 00:53 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-10 00:52 . 2008-01-11 19:12 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\AVG7
2008-01-10 00:51 . 2008-01-11 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-10 00:47 . 2008-01-11 23:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-10 00:16 . 2008-01-10 00:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Genie-Soft
2008-01-10 00:15 . 2008-01-10 00:15 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Genie-Soft
2008-01-10 00:11 . 2007-02-06 16:03 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-01-10 00:11 . 2007-02-02 03:00 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-01-10 00:11 . 2007-02-02 03:00 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-01-10 00:10 . 2008-01-10 00:11 <DIR> d-------- C:\Program Files\Genie Backup Manager Pro 8.0
2008-01-10 00:10 . 2006-11-02 01:50 128,104 --a------ C:\WINDOWS\system32\drivers\WimFltr.sys
2008-01-09 20:27 . 2008-01-11 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-09 20:13 . 2008-01-09 20:13 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-01-09 17:36 . 2008-01-09 17:36 819,200 --a------ C:\WINDOWS\is-RT58A.exe
2008-01-09 17:36 . 2008-01-09 17:36 10,620 --a------ C:\WINDOWS\is-RT58A.msg
2008-01-09 17:36 . 2008-01-09 17:36 1,917 --a------ C:\WINDOWS\is-RT58A.lst
2008-01-09 02:15 . 2008-01-10 17:06 <DIR> d-------- C:\Program Files\Uniblue
2008-01-09 02:15 . 2008-01-10 17:06 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Uniblue
2008-01-09 02:15 . 2008-01-09 02:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-01-08 13:28 . 2008-01-08 13:29 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Regrun
2008-01-08 13:28 . 2008-01-08 13:29 <DIR> d-------- C:\backreg
2008-01-08 13:27 . 2008-01-08 13:27 25,773 --a------ C:\WINDOWS\system32\drivers\regguard.sys
2008-01-08 13:27 . C:\WINDOWS\(2) C:\ComboFix\winstart.bat
2008-01-08 13:25 . 2008-01-08 13:54 <DIR> d-------- C:\Program Files\RegRunSuite
2008-01-07 15:04 . 2008-01-07 15:04 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\TrojanHunter
2008-01-07 10:59 . 2008-01-07 13:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-01-07 10:41 . 2008-01-07 13:03 <DIR> d-------- C:\Program Files\Security Task Manager
2008-01-07 10:41 . 2008-01-11 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-01-07 10:16 . 2008-01-11 17:54 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\PrevxCSI
2008-01-07 10:16 . 2008-01-07 10:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-07 10:10 . 2008-01-11 18:12 165 --a------ C:\WINDOWS\startUp manager.INI
2008-01-06 00:47 . 2008-01-06 00:47 <DIR> d-------- C:\Program Files\Ligos
2008-01-06 00:47 . 2000-06-23 10:36 745,984 --a------ C:\WINDOWS\system32\ir50_32.dll
2008-01-06 00:47 . 2000-06-23 14:05 136,704 --a------ C:\WINDOWS\system32\iacenc.dll
2008-01-06 00:47 . 2000-06-22 13:09 56,320 --------- C:\WINDOWS\system32\iyvu9_32.dll
2008-01-05 23:52 . 2008-01-05 23:52 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Media Player Classic
2008-01-05 18:05 . 2005-03-30 05:05 3,031,040 --a------ C:\WINDOWS\system32\NCTVideoTransform.dll
2008-01-05 18:05 . 2003-10-30 16:14 679,936 --a------ C:\WINDOWS\system32\NCTMPEGFile.dll
2008-01-05 18:05 . 2005-02-23 02:32 589,824 --a------ C:\WINDOWS\system32\NCTVideoView.dll
2008-01-05 18:05 . 2003-08-07 04:01 237,568 --a------ C:\WINDOWS\system32\lame_enc.dll
2008-01-05 18:05 . 2004-01-09 03:54 188,416 --a------ C:\WINDOWS\system32\actsplash.ocx
2008-01-05 16:13 . 2008-01-05 16:13 14 --a------ C:\WINDOWS\system32\SystemInfo32.sys
2008-01-05 16:12 . 2008-01-05 16:13 <DIR> d-------- C:\Program Files\DVD X Player 4.1 Professional
2008-01-05 16:12 . 2008-01-05 16:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD X Studios
2008-01-05 00:19 . 2008-01-05 00:19 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Systweak
2008-01-05 00:16 . 2008-01-11 01:48 <DIR> d-------- C:\Program Files\Advanced System Optimizer
2008-01-04 21:09 . 2008-01-06 11:17 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-04 21:09 . 2008-01-04 21:09 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-04 15:44 . 2008-01-04 15:44 <DIR> d-------- C:\Program Files\MP3 programs
2008-01-03 20:10 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-01-03 18:20 . 2008-01-13 21:18 <DIR> d-------- C:\Program Files\PeerGuardian2
2008-01-03 17:17 . 2008-01-06 20:07 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Azureus
2008-01-03 17:17 . 2008-01-03 17:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-01-03 17:10 . 2008-01-03 17:10 <DIR> d-------- C:\Program Files\Azureus
2008-01-03 16:27 . 2008-01-03 16:27 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\FreeCap
2008-01-03 15:36 . 2008-01-12 11:58 <DIR> d-------- C:\Program Files\Hide IP Platinum 3.5
2008-01-03 13:09 . 2008-01-12 17:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-03 13:09 . 2008-01-03 13:10 2,150 --a------ C:\WINDOWS\system32\tmmute.ini
2007-12-31 22:21 . 2007-12-31 22:21 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\InstallShield
2007-12-29 01:39 . 2007-12-29 01:41 <DIR> d-------- C:\Program Files\HyperCam
2007-12-28 14:12 . 2007-12-28 14:42 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\U3
2007-12-26 11:16 . 2007-12-26 11:17 67 --a------ C:\WINDOWS\#1 DVD Ripper.INI
2007-12-25 14:01 . 2007-12-26 11:09 5 --a------ C:\WINDOWS\system32\SySDVD.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-13 20:18 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\uTorrent
2008-01-13 10:58 --------- d-----w C:\Program Files\Mp3 converter
2008-01-12 19:01 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\Skype
2008-01-11 19:08 --------- d-----w C:\Program Files\DVD CD burner
2008-01-11 18:04 --------- d-----w C:\Program Files\NoAdware5.0
2008-01-10 17:18 --------- d-----w C:\Program Files\DVD convert & burn
2008-01-09 21:29 --------- d-----w C:\Program Files\uTorrent
2008-01-07 17:57 --------- d-----w C:\Program Files\DC++
2008-01-07 14:51 --------- d-----w C:\Program Files\Common Files\Real
2008-01-03 17:51 --------- d-----w C:\Program Files\Google
2008-01-03 13:36 --------- d-----w C:\Program Files\Microangelo
2008-01-02 19:12 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\dvdcss
2007-12-24 12:49 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2007-12-15 19:33 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\SopCast
2007-12-12 10:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-11 00:51 --------- d-----w C:\Program Files\Vodei
2007-12-04 16:13 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\ICQ
2007-12-04 10:28 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-12-04 01:33 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2007-11-29 22:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-20 15:33 --------- d-----w C:\Program Files\Skype
2007-11-20 15:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-11-20 15:32 --------- d-----w C:\Program Files\Common Files\Skype
2007-11-14 17:42 --------- d-----w C:\Program Files\Nero
2007-11-14 17:42 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\Ahead
2007-11-14 17:40 --------- d-----w C:\Program Files\Nero 6
2007-11-14 17:40 --------- d-----w C:\Program Files\Common Files\Ahead
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 16:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 16:40 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-21 18:24 159,744 ----a-w C:\WINDOWS\system32\UCLiveCore.dll
2007-10-21 17:33 241,664 ----a-w C:\WINDOWS\system32\UCLiveSocket.dll
2007-05-03 01:17 174 ----a-w C:\Documents and Settings\Branislav Mesaros\Application Data\wklnhst.dat
2007-01-21 18:37 87,608 ----a-w C:\Documents and Settings\Branislav Mesaros\Application Data\ezpinst.exe
2007-01-21 18:37 47,360 ----a-w C:\Documents and Settings\Branislav Mesaros\Application Data\pcouffin.sys
2005-09-24 16:49 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.

((((((((((((((((((((((((((((( snapshot@2008-01-13_16.59.49.99 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-13 15:49:58 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-13 22:11:07 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-13 15:49:58 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-13 22:11:07 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-13 15:49:58 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-13 22:11:07 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-13 15:49:58 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-13 22:11:07 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-13 15:49:59 12,247,040 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-13 22:11:08 12,247,040 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-13 15:49:59 204,800 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-13 22:11:08 204,800 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 22:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 22:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"AT-Watch"="" []
"avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
Vongo Tray.lnk - C:\Program Files\Vongo\Tray.exe [2006-03-14 17:51:44]

C:\Documents and Settings\Administrator.BRANO\Start Menu\Programs\Startup\
Vongo Tray.lnk - C:\Program Files\Vongo\Tray.exe [2006-03-14 17:51:44]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Branislav Mesaros^Start Menu^Programs^StartUp^Vongo Tray.lnk]
backup=C:\WINDOWS\pss\Vongo Tray.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDial]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLSP Scheduler]
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
--a------ 2006-02-22 16:03 40960 C:\Program Files\HPQ\Default Settings\cpqset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--a------ 2006-06-02 22:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1154847324\EE\AOLHostManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-02-19 09:41 49152 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
--a------ 2006-02-15 03:49 454656 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2006-03-23 13:13 77824 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2006-03-23 13:17 118784 C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2006-03-23 13:17 94208 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-08-12 00:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-08-12 00:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
--a------ 2006-03-07 21:38 131072 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-08-06 07:57 98304 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard]
--------- 2005-10-11 18:23 1187840 C:\Windows\SMINST\RecGuard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
--------- 2006-02-09 17:52 643072 C:\Windows\CREATOR\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-11 06:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2006-03-04 06:46 761948 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2004-12-20 19:41 33792 C:\Program Files\Winamp\winampa.exe

S0 Partizan;Partizan;C:\WINDOWS\system32\drivers\Partizan.sys []
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 15:05]
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys []
S3 RegGuard;RegGuard;C:\WINDOWS\system32\Drivers\regguard.sys [2008-01-08 13:27]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\d.com
\Shell\explore\Command - F:\d.com
\Shell\open\Command - F:\d.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10ddb2e8-2551-11db-91b3-00038a000015}]
\Shell\AutoRun\command - F:\80avp08.com
\Shell\explore\Command - F:\80avp08.com
\Shell\open\Command - F:\80avp08.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4572ca8c-7bfc-11db-927c-0014a5b64560}]
\Shell\AutoRun\command - F:\usdeiect.com
\Shell\explore\Command - F:\usdeiect.com
\Shell\open\Command - F:\usdeiect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{50cbc1d2-8ac6-11db-92b2-0014a5b64560}]
\Shell\AutoRun\command - F:\80avp08.com
\Shell\explore\Command - F:\80avp08.com
\Shell\open\Command - F:\80avp08.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{515b49f2-5f84-11dc-9542-0016d43313d2}]
\Shell\AutoRun\command - F:\usdeiect.com
\Shell\explore\Command - F:\usdeiect.com
\Shell\open\Command - F:\usdeiect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a0754fed-5004-11dc-9516-0016d43313d2}]
\Shell\AutoRun\command - F:\u.bat
\Shell\explore\Command - F:\u.bat
\Shell\open\Command - F:\u.bat

.
Contents of the 'Scheduled Tasks' folder
"2008-01-13 21:49:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-10 16:06:44 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-01-10 16:06:43 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-01-11 22:48:48 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-13 23:15:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-13 23:15:49
ComboFix-quarantined-files.txt 2008-01-13 22:15:34
ComboFix2.txt 2008-01-13 16:00:10
.
2008-01-09 10:25:10 --- E O F ---









New HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:29:28 PM, on 1/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SE...S01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SE...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.98.238.8:3128
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\Internet TV\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\Internet TV\FlashGet\getflash.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_link.htm
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c9b12eaa7cb44a169b54f3e4d6eec6e5
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c9b12eaa7cb44a169b54f3e4d6eec6e5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123fd.bay12...es/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase8300.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecu...asyInstallX.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{299F4FC9-2A6C-4D40-AEA5-382035FD868F}: NameServer = 217.118.96.203
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 8536 bytes










And DrWeb-cureit.exe log:

aolconnfix.exe;C:\;Trojan.PWS.Gamania.origin;Incurable.Moved.;
amvo0.dll;C:\!KillBox;Trojan.PWS.Wsgame.2387;Deleted.;
amvo0.dll( 1);C:\!KillBox;Trojan.PWS.Wsgame.2387;Deleted.;
00921562.FIL;C:\$VAULT$.AVG;Trojan.Nsanti.Packed;Deleted.;
01045296.FIL;C:\$VAULT$.AVG;Trojan.Nsanti.Packed;Deleted.;
01601312.FIL;C:\$VAULT$.AVG;Trojan.Nsanti.Packed;Deleted.;
01624796.FIL;C:\$VAULT$.AVG;Trojan.Nsanti.Packed;Deleted.;
02660796.FIL;C:\$VAULT$.AVG;Trojan.Nsanti.Packed;Deleted.;
03619437.FIL;C:\$VAULT$.AVG;Trojan.Nsanti.Packed;Deleted.;
27988968.FIL;C:\$VAULT$.AVG;Trojan.Nsanti.Packed;Deleted.;
amvo.exe.q_80497C9_q;C:\Documents and Settings\All Users\Application Data\SecTaskMan;Trojan.MulDrop.6474;Deleted.;
amvo.exe.q_80497C9_q.old;C:\Documents and Settings\All Users\Application Data\SecTaskMan;Trojan.MulDrop.6474;Deleted.;
NetTools.dll;C:\Program Files\Internet TV\PPLive;Adware.Winad.origin;;
inetchk.exe;C:\Program Files\music_now;Trojan.Click.2093;Deleted.;
NoAdware5.exe;C:\Program Files\NoAdware5.0;Trojan.Fakealert.403;Deleted.;
nutils.dll;C:\Program Files\NoAdware5.0;Trojan.NtRootKit.103;Deleted.;
PPCInstall.dll;C:\Program Files\Online Services\PeoplePC;Probably STPAGE.Trojan;;
neotvsession.dll;C:\Program Files\PPMate;Probably DLOADER.Trojan;;
ppmate.dll;C:\Program Files\PPMate;Adware.Dudu.origin;;
tio8x6.cmd.vir;C:\QooBox\Quarantine\C;Trojan.MulDrop.6474;Deleted.;
amvo1.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Modification of Win32.Besso - decompression error;Moved.;
80avp08.com.vir;C:\QooBox\Quarantine\D;Trojan.PWS.Wsgame.2387;Deleted.;
semo2x.exe.vir;C:\QooBox\Quarantine\D;Trojan.MulDrop.6474;Deleted.;
80avp08.com.vir;C:\QooBox\Quarantine\F;Trojan.PWS.Wsgame.2387;Deleted.;
d.com.vir;C:\QooBox\Quarantine\F;Trojan.MulDrop.6474;Deleted.;
semo2x.exe.vir;C:\QooBox\Quarantine\F;Trojan.MulDrop.6474;Deleted.;
u.bat.vir;C:\QooBox\Quarantine\F;Trojan.PWS.Banker.14153;Deleted.;
usdeiect.com.vir;C:\QooBox\Quarantine\F;Trojan.PWS.Wsgame.2387;Deleted.;
Brandit.exe;C:\SWSETUP\Brandit\Disk1;Probably STPAGE.Trojan;;
A0000013.com;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2;Trojan.MulDrop.6474;Deleted.;
A0000030.dll;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2;Trojan.PWS.Wsgame.2387;Deleted.;
A0001031.dll;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2;Trojan.Packed.140;Deleted.;
A0002032.dll;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2;Trojan.Packed.140;Deleted.;
A0002052.dll;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2;Trojan.Packed.140;Deleted.;
A0002059.com;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP3;Trojan.MulDrop.6474;Deleted.;
A0002315.dll;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP3;Trojan.PWS.Wsgame.2387;Deleted.;
A0002316.exe;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP3;Trojan.MulDrop.6474;Deleted.;
A0002317.dll;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP3;Trojan.Packed.140;Deleted.;
A0002319.com;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP3;Trojan.MulDrop.6474;Deleted.;
A0003366.dll;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP4;Modification of Win32.Besso - decompression error;Moved.;
A0003387.bat;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP4;Probably BATCH.Virus;;
A0003457.cmd;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.MulDrop.6474;Deleted.;
A0003470.bat;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Probably BATCH.Virus;;
A0003506.exe;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Gamania.origin;Incurable.Moved.;
A0003507.dll;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Wsgame.2387;Deleted.;
A0003508.old;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.MulDrop.6474;Deleted.;
A0003509.exe;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.Click.2093;Deleted.;
A0003510.exe;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.Fakealert.403;Deleted.;
A0003511.dll;C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.NtRootKit.103;Deleted.;
amvo.exe;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Modification of Win32.Besso - decompression error;Moved.;
u.bat;D:\;Trojan.PWS.Banker.14153;Deleted.;
uxdeiect.com;D:\;Trojan.PWS.Wsgame.2387;Deleted.;
usdeiect.com;D:\;Trojan.PWS.Wsgame.2387;Deleted.;
xfoolavp.com;D:\;Trojan.PWS.Wsgame.2387;Deleted.;
tio8x6.cmd;D:\;Trojan.MulDrop.6474;Deleted.;
A0000015.com;D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2;Trojan.MulDrop.6474;Deleted.;
A0002061.com;D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP3;Trojan.MulDrop.6474;Deleted.;
A0002321.com;D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP3;Trojan.MulDrop.6474;Deleted.;
A0003364.com;D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP4;Trojan.PWS.Wsgame.2387;Deleted.;
A0003365.exe;D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP4;Trojan.MulDrop.6474;Deleted.;
A0003513.bat;D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Banker.14153;Deleted.;
A0003514.com;D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Wsgame.2387;Deleted.;
A0003515.com;D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Wsgame.2387;Deleted.;
A0003516.com;D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Wsgame.2387;Deleted.;
A0003517.cmd;D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.MulDrop.6474;Deleted.;
tio8x6.cmd;F:\;Trojan.MulDrop.6474;Deleted.;
uxdeiect.com;F:\;Trojan.PWS.Wsgame.2387;Deleted.;
xfoolavp.com;F:\;Trojan.PWS.Wsgame.2387;Deleted.;
A0072456.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP407;Win32.HLLW.Autoruner.1055;Deleted.;
A0072462.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP407;Trojan.PWS.Wsgame.2387;Deleted.;
A0072463.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP407;Win32.HLLW.Autoruner.1053;Deleted.;
A0072470.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP408;Trojan.PWS.Wsgame.2387;Deleted.;
A0072471.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP408;Win32.HLLW.Autoruner.1053;Deleted.;
A0072516.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP408;Trojan.PWS.Wsgame.2387;Deleted.;
A0072517.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP408;Win32.HLLW.Autoruner.1053;Deleted.;
A0073078.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP410;Trojan.PWS.Wsgame.2387;Deleted.;
A0073079.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP410;Win32.HLLW.Autoruner.1053;Deleted.;
A0073088.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP410;Trojan.PWS.Wsgame.2387;Deleted.;
A0073089.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP410;Win32.HLLW.Autoruner.1053;Deleted.;
A0073091.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP410;Trojan.PWS.Wsgame.2387;Deleted.;
A0073092.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP410;Win32.HLLW.Autoruner.1053;Deleted.;
A0073186.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP411;Win32.HLLW.Autoruner.1053;Deleted.;
A0073187.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP411;Trojan.PWS.Wsgame.2387;Deleted.;
A0073188.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP411;Win32.HLLW.Autoruner.1054;Deleted.;
A0073189.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP411;Trojan.PWS.Wsgame.2387;Deleted.;
A0073190.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP411;Win32.HLLW.Autoruner.1054;Deleted.;
A0073249.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP412;Trojan.PWS.Wsgame.2387;Deleted.;
A0073250.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP412;Win32.HLLW.Autoruner.1054;Deleted.;
A0073317.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP412;Trojan.PWS.Wsgame.2387;Deleted.;
A0073318.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP412;Win32.HLLW.Autoruner.1054;Deleted.;
A0073402.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP413;Win32.HLLW.Autoruner.1054;Deleted.;
A0073403.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP413;Modification of Win32.Besso - decompression error;Moved.;
A0073404.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP413;Win32.HLLW.Autoruner.1068;Deleted.;
A0073474.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP414;Modification of Win32.Besso - decompression error;Moved.;
A0073475.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP414;Win32.HLLW.Autoruner.1068;Deleted.;
A0073486.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP414;Trojan.PWS.Wsgame.2387;Deleted.;
A0073487.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP414;Win32.HLLW.Autoruner.1068;Deleted.;
A0073490.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP414;Trojan.PWS.Wsgame.2387;Deleted.;
A0073491.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP414;Win32.HLLW.Autoruner.1068;Deleted.;
A0075884.inf;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP416;Win32.HLLW.Autoruner.1068;Deleted.;
A0076083.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP416;Trojan.MulDrop.6474;Deleted.;
A0076090.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP416;Trojan.MulDrop.6474;Deleted.;
A0076093.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP416;Trojan.MulDrop.6474;Deleted.;
A0076132.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP417;Trojan.MulDrop.6474;Deleted.;
A0076139.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP417;Trojan.MulDrop.6474;Deleted.;
A0076148.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP417;Trojan.MulDrop.6474;Deleted.;
A0076175.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP417;Trojan.MulDrop.6474;Deleted.;
A0076264.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP417;Trojan.MulDrop.6474;Deleted.;
A0076428.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP417;Trojan.MulDrop.6474;Deleted.;
A0076442.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP417;Trojan.MulDrop.6474;Deleted.;
A0076814.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP418;Trojan.MulDrop.6474;Deleted.;
A0078535.bat;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP421;Trojan.PWS.Banker.14153;Deleted.;
A0078648.bat;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP424;Trojan.PWS.Banker.14153;Deleted.;
A0078662.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP425;Trojan.MulDrop.6474;Deleted.;
A0078672.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP426;Trojan.MulDrop.6474;Deleted.;
A0078810.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP427;Trojan.MulDrop.6474;Deleted.;
A0078820.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP428;Trojan.MulDrop.6474;Deleted.;
A0079635.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP430;Trojan.MulDrop.6474;Deleted.;
A0079642.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP431;Trojan.MulDrop.6474;Deleted.;
A0079697.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP432;Trojan.MulDrop.6474;Deleted.;
A0079717.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP432;Trojan.MulDrop.6474;Deleted.;
A0079733.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP433;Trojan.MulDrop.6474;Deleted.;
A0079739.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP434;Trojan.MulDrop.6474;Deleted.;
A0079745.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP435;Trojan.MulDrop.6474;Deleted.;
A0079758.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP436;Trojan.MulDrop.6474;Deleted.;
A0079780.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP436;Trojan.MulDrop.6474;Deleted.;
A0079789.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP437;Trojan.MulDrop.6474;Deleted.;
A0079795.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP438;Trojan.MulDrop.6474;Deleted.;
A0079816.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP439;Trojan.MulDrop.6474;Deleted.;
A0079843.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP443;Trojan.MulDrop.6474;Deleted.;
A0079849.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP444;Trojan.MulDrop.6474;Deleted.;
A0079914.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP446;Trojan.MulDrop.6474;Deleted.;
A0080188.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP449;Trojan.MulDrop.6474;Deleted.;
A0080198.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP450;Trojan.MulDrop.6474;Deleted.;
A0080606.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP450;Trojan.MulDrop.6474;Deleted.;
A0080613.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP451;Trojan.MulDrop.6474;Deleted.;
A0080666.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP452;Trojan.MulDrop.6474;Deleted.;
A0003455.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Wsgame.2387;Deleted.;
A0003456.exe;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.MulDrop.6474;Deleted.;
A0003458.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.MulDrop.6474;Deleted.;
A0003459.bat;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Banker.14153;Deleted.;
A0003460.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Wsgame.2387;Deleted.;
A0003518.cmd;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.MulDrop.6474;Deleted.;
A0003519.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Wsgame.2387;Deleted.;
A0003520.com;F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5;Trojan.PWS.Wsgame.2387;Deleted.;






Please let me know what to do next. Thank you again. Braninho
  • 0

#8
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please do an online scan with Kaspersky WebScanner
(This scanner is for use with internet explorer only)
Click on "Accept"

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

  • 0

#9
braninho

braninho

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi!

I am posting the Kaspersky online scanner report and new HJT report:




Kaspersky:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, January 14, 2008 3:08:23 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 14/01/2008
Kaspersky Anti-Virus database records: 510442
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 190348
Number of viruses found: 18
Number of infected objects: 66
Number of suspicious objects: 0
Duration of the scan process: 02:45:54

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\SecTaskMan\amvo0.dll.q_804D600_q Infected: Worm.Win32.AutoRun.bpn skipped
C:\Documents and Settings\All Users\Application Data\SecTaskMan\amvo0.dll.q_804D600_q.old Infected: Worm.Win32.AutoRun.bmz skipped
C:\Documents and Settings\All Users\Application Data\SecTaskMan\amvo1.dll.q_804D600_q Infected: Worm.Win32.AutoRun.bpn skipped
C:\Documents and Settings\Branislav Mesaros\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Branislav Mesaros\DoctorWeb\Quarantine\A0003366.dll Infected: Trojan-PSW.Win32.OnLineGames.nwl skipped
C:\Documents and Settings\Branislav Mesaros\DoctorWeb\Quarantine\A0073403.com Infected: Trojan-PSW.Win32.OnLineGames.mrq skipped
C:\Documents and Settings\Branislav Mesaros\DoctorWeb\Quarantine\A0073474.com Infected: Trojan-PSW.Win32.OnLineGames.mrq skipped
C:\Documents and Settings\Branislav Mesaros\DoctorWeb\Quarantine\amvo.exe Infected: Worm.Win32.AutoRun.brz skipped
C:\Documents and Settings\Branislav Mesaros\DoctorWeb\Quarantine\amvo1.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.nwl skipped
C:\Documents and Settings\Branislav Mesaros\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Branislav Mesaros\History\History.IE5\MSHist012008011420080115\index.dat Object is locked skipped
C:\Documents and Settings\Branislav Mesaros\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Branislav Mesaros\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Branislav Mesaros\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Branislav Mesaros\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Branislav Mesaros\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Branislav Mesaros\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Branislav Mesaros\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Vongo\Data\vongo.dat Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2\A0000031.com Infected: Trojan-PSW.Win32.OnLineGames.nst skipped
C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2\A0001032.com Infected: Trojan-PSW.Win32.OnLineGames.nst skipped
C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2\A0002033.com Infected: Trojan-PSW.Win32.OnLineGames.nst skipped
C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP3\A0002215.exe Infected: Trojan-PSW.Win32.OnLineGames.nst skipped
C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP3\A0002325.exe Infected: Trojan-PSW.Win32.OnLineGames.nst skipped
C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5\A0003512.exe Infected: Worm.Win32.AutoRun.brz skipped
C:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP5\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\Windows_OneCare_Evt.evt Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\temp\Perflib_Perfdata_668.dat Object is locked skipped
C:\WINDOWS\temp\sqlite_mGtQlkabbyk2ios Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2\A0000033.com Infected: Trojan-PSW.Win32.OnLineGames.nst skipped
D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2\A0001034.com Infected: Trojan-PSW.Win32.OnLineGames.nst skipped
D:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP2\A0002035.com Infected: Trojan-PSW.Win32.OnLineGames.nst skipped
F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP421\A0078536.inf Infected: Worm.Win32.AutoRun.bnq skipped
F:\System Volume Information\_restore{6D05FAB2-7A62-4A96-A638-2F0B6A273527}\RP424\A0078649.inf Infected: Worm.Win32.AutoRun.bnq skipped
F:\Install site\Screensavers\sssailing.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
F:\Install site\Screensavers\sssailing.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
F:\Install site\Screensavers\sssailing.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.z skipped
F:\Install site\Screensavers\sssailing.exe/WISE0022.BIN Infected: Trojan-Dropper.Win32.Agent.pd skipped
F:\Install site\Screensavers\sssailing.exe WiseSFX: infected - 4 skipped
F:\Install site\Screensavers\castlesceness.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
F:\Install site\Screensavers\castlesceness.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
F:\Install site\Screensavers\castlesceness.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.z skipped
F:\Install site\Screensavers\castlesceness.exe/WISE0022.BIN Infected: Trojan-Dropper.Win32.Agent.pd skipped
F:\Install site\Screensavers\castlesceness.exe WiseSFX: infected - 4 skipped
F:\Install site\Screensavers\perfectlandingss.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
F:\Install site\Screensavers\perfectlandingss.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
F:\Install site\Screensavers\perfectlandingss.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.z skipped
F:\Install site\Screensavers\perfectlandingss.exe/WISE0022.BIN Infected: Trojan-Dropper.Win32.Agent.pd skipped
F:\Install site\Screensavers\perfectlandingss.exe WiseSFX: infected - 4 skipped
F:\Install site\Screensavers\picassoclockinst.exe/VVSNInst.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
F:\Install site\Screensavers\picassoclockinst.exe CreateInstall: infected - 1 skipped
F:\Install site\Screensavers\summerfallswa.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
F:\Install site\Screensavers\summerfallswa.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
F:\Install site\Screensavers\summerfallswa.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.z skipped
F:\Install site\Screensavers\summerfallswa.exe/WISE0022.BIN Infected: Trojan-Dropper.Win32.Agent.pd skipped
F:\Install site\Screensavers\summerfallswa.exe WiseSFX: infected - 4 skipped
F:\Install site\Screensavers\alleniverson.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.MyWay.ac skipped
F:\Install site\Screensavers\alleniverson.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.EZula.av skipped
F:\Install site\Screensavers\alleniverson.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.180Solutions skipped
F:\Install site\Screensavers\alleniverson.exe WiseSFX: infected - 3 skipped
F:\Install site\Internet TV's\VGOLiveSetup.exe/data0026 Infected: not-a-virus:AdWare.Win32.BHO.ed skipped
F:\Install site\Internet TV's\VGOLiveSetup.exe NSIS: infected - 1 skipped
F:\_Picture\Other\FC Juventus Torino\juventus01th.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
F:\_Picture\Other\FC Juventus Torino\juventus01th.exe/WISE0017.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
F:\_Picture\Other\FC Juventus Torino\juventus01th.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
F:\_Picture\Other\FC Juventus Torino\juventus01th.exe WiseSFX: infected - 3 skipped
F:\_Picture\Other\FC Juventus Torino\juventus01th.exe WiseSFXDropper: infected - 3 skipped
F:\_Picture\Other\FC Juventus Torino\juvessv02.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
F:\_Picture\Other\FC Juventus Torino\juvessv02.exe/WISE0017.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
F:\_Picture\Other\FC Juventus Torino\juvessv02.exe WiseSFX: infected - 2 skipped
F:\_Picture\Other\FC Juventus Torino\juvessv02.exe WiseSFXDropper: infected - 2 skipped
F:\Other\The Simpsons\Other\simpsons350thss.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
F:\Other\The Simpsons\Other\simpsons350thss.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
F:\Other\The Simpsons\Other\simpsons350thss.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.z skipped
F:\Other\The Simpsons\Other\simpsons350thss.exe/WISE0022.BIN Infected: Trojan-Dropper.Win32.Agent.pd skipped
F:\Other\The Simpsons\Other\simpsons350thss.exe WiseSFX: infected - 4 skipped
F:\Other\The Simpsons\Other\simpsonsscrxp.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
F:\Other\The Simpsons\Other\simpsonsscrxp.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
F:\Other\The Simpsons\Other\simpsonsscrxp.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.z skipped
F:\Other\The Simpsons\Other\simpsonsscrxp.exe/WISE0022.BIN Infected: Trojan-Dropper.Win32.Agent.pd skipped
F:\Other\The Simpsons\Other\simpsonsscrxp.exe WiseSFX: infected - 4 skipped

Scan process completed.









And new HJT report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:09:34 PM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\Notepad.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SE...S01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SE...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.98.238.8:3128
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\Internet TV\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\Internet TV\FlashGet\getflash.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_link.htm
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c9b12eaa7cb44a169b54f3e4d6eec6e5
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c9b12eaa7cb44a169b54f3e4d6eec6e5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123fd.bay12...es/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase8300.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecu...asyInstallX.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{299F4FC9-2A6C-4D40-AEA5-382035FD868F}: NameServer = 217.118.96.203
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 8541 bytes






Thank you. Please let me know what to do next. Braninho
  • 0

#10
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\All Users\Application Data\SecTaskMan\amvo0.dll.q_804D600_q
    C:\Documents and Settings\All Users\Application Data\SecTaskMan\amvo0.dll.q_804D600_q.old
    F:\Install site\Screensavers\sssailing.exe
    F:\Install site\Screensavers\castlesceness.exe
    F:\Install site\Screensavers\perfectlandingss.exe
    F:\Install site\Screensavers\picassoclockinst.exe
    F:\Install site\Screensavers\summerfallswa.exe
    F:\Install site\Internet TV's\VGOLiveSetup.exe
    F:\_Picture\Other\FC Juventus Torino\juventus01th.exe
    F:\_Picture\Other\FC Juventus Torino\juvessv02.exe
    F:\Other\The Simpsons\Other\simpsons350thss.exe
    F:\Other\The Simpsons\Other\simpsonsscrxp.exe
    C:\WINDOWS\system32\tmmute.ini
    C:\WINDOWS\system32\SystemInfo32.sys


  • Return to OTMoveIt2, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • OTMoveit2 will create a log of moved files in the C:\_OTMoveIt\MovedFiles folder. The log's name will appear as the date and time it was created, with the format mmddyyyy_hhmmss.log. Open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
=======================================
After that please update your Java:
Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Ugrading Java:After that
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
==========================================
Please post back with a new Hijackthis log and the Otmoveit 2 log.
  • 0

Advertisements


#11
braninho

braninho

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hello!

I am posting the OTMoveIt.exe log and new HJT log.



OTMoveIt.exe:

C:\Documents and Settings\All Users\Application Data\SecTaskMan\amvo0.dll.q_804D600_q moved successfully.
C:\Documents and Settings\All Users\Application Data\SecTaskMan\amvo0.dll.q_804D600_q.old moved successfully.
F:\Install site\Screensavers\sssailing.exe moved successfully.
F:\Install site\Screensavers\castlesceness.exe moved successfully.
F:\Install site\Screensavers\perfectlandingss.exe moved successfully.
F:\Install site\Screensavers\picassoclockinst.exe moved successfully.
F:\Install site\Screensavers\summerfallswa.exe moved successfully.
F:\Install site\Internet TV's\VGOLiveSetup.exe moved successfully.
F:\_Picture\Other\FC Juventus Torino\juventus01th.exe moved successfully.
F:\_Picture\Other\FC Juventus Torino\juvessv02.exe moved successfully.
F:\Other\The Simpsons\Other\simpsons350thss.exe moved successfully.
F:\Other\The Simpsons\Other\simpsonsscrxp.exe moved successfully.
C:\WINDOWS\system32\tmmute.ini moved successfully.
C:\WINDOWS\system32\SystemInfo32.sys moved successfully.

Created on 01/15/2008 11:58:22








HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:14:45 PM, on 1/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SE...S01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SE...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.98.238.8:3128
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\Internet TV\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\Internet TV\FlashGet\getflash.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_link.htm
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c9b12eaa7cb44a169b54f3e4d6eec6e5
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c9b12eaa7cb44a169b54f3e4d6eec6e5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123fd.bay12...es/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase8300.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecu...asyInstallX.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{299F4FC9-2A6C-4D40-AEA5-382035FD868F}: NameServer = 217.118.96.203
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 8723 bytes




Please let me know what to do next. Thank you again. Braninho
  • 0

#12
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
    Posted Image

Please then delete all other tools if any that I had you download.
Empty your recycle bin.
===================
After that Your log is clean. :)

To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here

If you have any further problems please feel free to contact G2Go.:)
  • 0

#13
braninho

braninho

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi!

Thank you very much for everything. I really appreciate that.

First thing at the morning I'm gonna donate some money here. You really helped me.

I just want to know some advice for future...how can I find out which USB flash drive is infected and in the case I will put it into my laptop how can I stay

protected from getting that amvo virus again or how to check my other USB devices (camera, 500 MB USB flash drive, printer) if they didn't get infected too?

Thank you again. Braninho
  • 0

#14
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
The only drive I saw as infected was the F:\ drive.
What you can do is update your antivirus plug in the usb device and right click and hit scan on each device.
The best way to stay clean is to keep your antivirus up to date and stay current on all of the Windows updates.

A camera is not going to be infected only drive that contain files.


To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here
  • 0

#15
braninho

braninho

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi!

Thank you very much again for everything.

I hope you have received my donation (from branom.........). I really appreciate what you did for me. Bye, Braninho
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP