Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Alcan worm [RESOLVED]


  • This topic is locked This topic is locked

#1
stoorren

stoorren

    New Member

  • Member
  • Pip
  • 8 posts
Hi there,

My system seemed to be infected with the W32.Alcra.F Virus
I found a topic: http://www.geekstogo...showtopic=98929 ,
Witch I completely followed.
So I have used the Brute Force uninstaller, with the Alcra PLUS Remover script.
And I have let Hijackthis scanned my system.
So, here is my log.
Please tell me what to do to totally clean up my system from this annoying virus.

In advance thanks



Logfile of HijackThis v1.99.1
Scan saved at 15:41:48, on 27-3-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\limewire\limewire.exe
C:\Program Files\shareaza\shareaza.exe
C:\WINDOWS\explorer.exe
C:\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: svchost.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Onderzoekscentrum - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postb...l/sesam/CAX.cab
O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus....ek_sys_ctrl.cab
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/o...utodetectNT.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/d...SISTransfer.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1137948915761
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123787647612
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - file://C:\WINDOWS\Web\TSWeb\msrdp.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprint...IPSUploader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{286F3DFB-DCAF-4723-BCB7-D7E0DB863E8C}: NameServer = 62.45.45.45,62.45.46.46
O17 - HKLM\System\CCS\Services\Tcpip\..\{D46C24FD-5523-487C-B323-CD6288C633AB}: NameServer = 62.45.46.46,62.45.45.45
O17 - HKLM\System\CS1\Services\Tcpip\..\{286F3DFB-DCAF-4723-BCB7-D7E0DB863E8C}: NameServer = 62.45.45.45,62.45.46.46
O17 - HKLM\System\CS2\Services\Tcpip\..\{286F3DFB-DCAF-4723-BCB7-D7E0DB863E8C}: NameServer = 62.45.45.45,62.45.46.46
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
  • 0

Advertisements


#2
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Hi and welcome to GeeksToGo! My name is Sam and I will be helping you. :whistling:

I apologize for the delay getting to your log, the helpers here are very busy.
If you still need help, please post a fresh Hijackthis log, in this thread, so I can help you with your Malware Problems.

If you have resolved this issue please let us know.
  • 0

#3
stoorren

stoorren

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi Sam, the delay is no problem, I aam glad you try to help me anyway!

So, I still have the virus, Limewire and Shareaza automaticaly starts everytime i shut them down, they start again. And also a few things like task manager, and regedit are ´´ allready opened by an other program´´.
I found out, when my computer is rebooted at save mode, these functions are available.

I'm sorry for my bad english, that's because I am a Dutch guy.

Here is my new Hijackthis log:


Logfile of HijackThis v1.99.1
Scan saved at 17:38:42, on 31-3-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\limewire\limewire.exe
C:\Program Files\shareaza\shareaza.exe
C:\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: svchost.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Onderzoekscentrum - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postb...l/sesam/CAX.cab
O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus....ek_sys_ctrl.cab
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/o...utodetectNT.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/d...SISTransfer.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1137948915761
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123787647612
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - file://C:\WINDOWS\Web\TSWeb\msrdp.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprint...IPSUploader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{286F3DFB-DCAF-4723-BCB7-D7E0DB863E8C}: NameServer = 62.45.45.45,62.45.46.46
O17 - HKLM\System\CCS\Services\Tcpip\..\{D46C24FD-5523-487C-B323-CD6288C633AB}: NameServer = 62.45.46.46,62.45.45.45
O17 - HKLM\System\CS1\Services\Tcpip\..\{286F3DFB-DCAF-4723-BCB7-D7E0DB863E8C}: NameServer = 62.45.45.45,62.45.46.46
O17 - HKLM\System\CS2\Services\Tcpip\..\{286F3DFB-DCAF-4723-BCB7-D7E0DB863E8C}: NameServer = 62.45.45.45,62.45.46.46
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#4
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
I think your english is excellent! :whistling:

Download KillBox and unzip it to your desktop.

Open Killbox and select the Delete on reboot option.
Copy and paste the following file to the field labeled "Full path of file to delete"

C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\svchost.exe

Press the Delete button (the button that looks like a red circle with a white X in it).
A first dialog box will ask if you want to delete the file on reboot, press the YES button.
A second dialog box will ask you if you want to REBOOT now. Press the YES button.

Your computer will reboot.



Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report along with a new hijackthis log.

  • 0

#5
stoorren

stoorren

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Ok, I did all the things you told me,
Here's the Active Scan report of panda, with :whistling: thousands of treaths found, witch are files, I have never downloaded by myself, and witch I can't see in the download folder.. Looks a bit strange to me.

Anyway, here's the report of Panda active scan, followed by the new Hijackthis scan.

I added the panda active scan as a attachment, because, it is to big to post here.


Hijackthis log:


Logfile of HijackThis v1.99.1
Scan saved at 19:41:14, on 31-3-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\hijack this\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Onderzoekscentrum - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postb...l/sesam/CAX.cab
O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus....ek_sys_ctrl.cab
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/o...utodetectNT.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/d...SISTransfer.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1137948915761
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123787647612
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - file://C:\WINDOWS\Web\TSWeb\msrdp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprint...IPSUploader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{286F3DFB-DCAF-4723-BCB7-D7E0DB863E8C}: NameServer = 62.45.45.45,62.45.46.46
O17 - HKLM\System\CCS\Services\Tcpip\..\{D46C24FD-5523-487C-B323-CD6288C633AB}: NameServer = 62.45.46.46,62.45.45.45
O17 - HKLM\System\CS1\Services\Tcpip\..\{286F3DFB-DCAF-4723-BCB7-D7E0DB863E8C}: NameServer = 62.45.45.45,62.45.46.46
O17 - HKLM\System\CS2\Services\Tcpip\..\{286F3DFB-DCAF-4723-BCB7-D7E0DB863E8C}: NameServer = 62.45.45.45,62.45.46.46
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#6
stoorren

stoorren

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Ok, I don't see the attatchment, so I am going to split the active scan log into pieces, so I can post it here.
  • 0

#7
stoorren

stoorren

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Incident Status Location

Virus:W32/Gaobot.MJA.worm Disinfected C:\!KillBox\svchost.exe
Virus:W32/Gaobot.MJA.worm Disinfected C:\RECYCLER\NPROTECT\00003770.EXE
Virus:W32/Gaobot.MJA.worm Disinfected C:\WINDOWS\pss\svchost.exeCommon Startup
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\(2002) Attack.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\(anarchist ebook) How to fire your boss, a workers....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\(COMEDY) Roy Chubby Brown Live (55m 53s).exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\(ebook self help) Leil Lowndes Conversation....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\(New)VA Now Dance 2005 [2CDs] [2004] [Covers]....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\(PS1) Holly & Benji Captain Tsubasa J.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\(PS2) Red Faction 2 FULL DVD NTSC {By roflmfao}.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\(reseed) The A Team season 5 3297560 TPB.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\007 DVD Copy v5.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\02 25 05 Howard Stern Show (24kbps BOS).exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\02 28 05 Howard Stern Show (56k NYC).exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\0S Non-Proxy Atomic Sync v2.06.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\11 El perro de Flandes 11 El campo de tulipanes de....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\111Free History Eraser 2.8.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\131 3160 IMG.JPG.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\1944 Battle Of The Bulge.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\1992 Eternal Prisoner.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\1Click DVD Copy 4.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\1Click Spy Clean v1.4.9.36.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\1st Evidence Remover 2.1.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\21 Jump Street 1x10 Next Generation avi 3277352....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\232Analyzer 4.1.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\2Flyer Screensaver Builder Pro v7.5.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\3 doors down landing in london xvid [2006] [] [www....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\32bit Fax v9.87.01.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\3581 Gif picturs (mrdalice;)) rar.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\3D Aquatic Screen Saver.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\3D World Studio 5.31.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\4U AVI MPEG Converter v3.3.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\4U AVI MPEG Converter v3.62.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\5 Internet Security Tools AIO.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\7th Heaven 9x02 torrent avi.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\A Dozen Furies Rip The Stars Down (EP) 2004 h8me.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\A Man Apart DVDRip Xvid.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\A Perfect Murder Unbroken 2004 h8me.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\A Snakes Life v2.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AbandonWare – Imperialism II.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\ABC Backup Pro v4.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Absolute Sound Recorder v3.32.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Absolute Sound Recorder v3.33.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Absolute Video Converter v2.5.24.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Absolute Video to Audio Converter v2.6.7.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Absolute Video to Audio Converter.v2.6.8.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AccuRev v3.8 Enterprise.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Ace FTP v3.01Pro.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Ace Utilities 2.20.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Ace Video Workshop 1.4.11.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AceFTP Pro v3.70.3.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\ACID Music Studio 6.0 Build 51.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Acme CAD Converter v6 51 WinALL Incl Keygen....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Acoustica Mixcraft 2.50.45.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Acronis Bootable Cd Aio.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Acronis True Image v9.1 - Server - Workstation - Enterp.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Act Of War High Treason CLONEDVD MONCUL.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\ActionXP v4.69.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Active Desktop Calendar v5.95.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Active Desktop Calendar v5.99a.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Active KeyBoard v3.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Activestate Komodo v2.5.1.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Adaware 6 Pro Build 181 Traduccion serial Plugins....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Adobe Audition 1.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Adobe Creative Suite 2.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\ADOBE CREATIVE SUITE PREMIUM EDITION V2 0 TDA DISC....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Adobe Photoshop 9 CS2 [AIO].exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Adobe Photoshop CS in 10 Simple Steps or Less.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Adobe Photoshop CS2 9.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Adobe Photoshop Elements 4 Retail CD.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AdSenseLog v2.7.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\ADSLKeepalive Version v3.1 FULL.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced Business Card Maker 3.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced Host Monitor v5.92.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced Log Analyser v1.5.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced MP3 Converter v2.43.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced MP3 Converter v2.62.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced RAR Repair 1.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced RAR Repair v1.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced Replace Tools 3.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced System Optimizer v2.10.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced Uninstaller 7 5 (with crack) rar.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Advanced Web Ranking v4.53.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Adware Deluxe v1.0.8.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Adware Nuker v1.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Afroman Good Times.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Age Of Empires III - RELOADED iSO.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Age of Empires III iso.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Age of Empires III.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Agendus Palm Desktop v3.32.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Ahead Nero v6 6 0 0 Reloaded Enterprise Edition....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AHQ DBZ 148 165.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AI RoboForm 6.6.7.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AIDA32 System Info.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AimOne Screen Recorder 1.31.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AIO - Anti-Virus Software.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AIO ~ Macromedia.Products.v2.XiSO.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Air Crash Investigations S03E07 Egypt Air 990 avi.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Alarm Plus Plus v7.03.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Alcohol 120% v1.9.5.3105 Retail+Patch.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Alcohol 120% v1.9.5.3823.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\alejandra Urdian Wallpapers 3352727 TPB.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\alf s01e01 a l f dvdrip xvid crntv avi 3320630 TPB.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Alias Maya 7 Unlimited.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Alias StudioTools 13.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Alien Lockdown 2004 DVDRip XviD FiNaLe 3311770 TPB.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\All In One - Xilisoft Products.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\All in One Slysoft.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\All In One Vcom 2006.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\All My Fonts Pro v2.0.0.1.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\All My Movies 3.9.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\All-In-One RapidShare Hacks.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Alldata v8 0 Audi CD TBE 3254469 TPB.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Allman Brothers Band.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Allok Video Splitter v1.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Allt med eminem 3309986 TPB.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Along Came Polly DVDrip XviD.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Alpeak CD Anywhere v1.8.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AlphaXP Lite 1.1.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Amadis DVD Ripper Pro v1.0.3.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Amadis DVD Ripper Professional v1.0.3.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Amateur Allure Tabetha s Monster Facial.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Amateur XXX [bleep] video complete Hot teen college....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Amazing Photo Editor v5.3.1.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Amazon DVD Shrinker v2.1.1.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\American Pie Band Camp.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\andromeda 4x21 the dissonant interval xvid fov avi.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Angel Heart DvD rip fr [Mc TeAm].exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Another Woman (Woody Allen) Pal DVD5 Multilanguaje....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Anti-Keylogger Elite v.2.1.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Anti-Virus AIO.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Antispyware Applications AIO.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Any Capture Screen v3.12.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AnyDVD 5.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AnyDVD 5.9.4.1.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AnyDVD v5.9.4.1.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Anytrac 2005 v1.0.43.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AoA DVD COPY 2.5.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Aone Photo Screensaver Maker 5.0.8.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Aone Photo Screensaver Maker v4.9.6.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Aone Photo Screensaver Maker v5.0.8.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Aone Ultra Video Splitter v3.6.2.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\aoword8p bin.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Apollo Audio and Data Burner v1.2.6.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Apple QuickTime Pro 7.0.4.80.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\AptPassport v2.1.00.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Aqua Bubble 2.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Aquamarine 2006 CAM PRiDEVCD.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Aquazone Desktop Garden 1.0.1.4.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Aquila Software Examine32 v4.30.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Arabian Nights.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Arc DVD Copy v1.2.2.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Area 51.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Arial Audio Converter v2.3.22.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Arlington Road SoloDVD.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Armin van Buuren A State of Trance 185 24 02 2005.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Art Farmer, Benny Golson Jazztet Blues March....exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Ashampoo Anti-Spyware 1.10.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Ashampoo AntiSpyWare v1.10.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Ashampoo AudioCD MP3 Studio3.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Ashampoo UnInstaller Platinum v2.0.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Asmw PC-Optimizer Pro 7.6.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Aston Villa Arsenal 2nd Half XviD MaXxed.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Astonishing X Men v3.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Atari Lynx ROMS (V2 01) 3240698 TPB.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\ATI OverClock ATI Tool With Driver 3365721 TPB.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Atlantis 1.4.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire downloads\_\Atom & His Package Live DVD.exe
Virus:W32/Gaobot.MJA.worm Disinfected F:\Limewire download
  • 0

#8
stoorren

stoorren

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
This seems not to work either.

I uploaded the log file to my personal home page, so the log of Panda active scan can be seen/downloaded
here: http://home.kabelfoo... Activescan.txt
  • 0

#9
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Everything in those folders is infected.

Delete these folders and everything in them:

F:\Shareaza downloads
F:\Limewire downloads



Right click on your recycle bin and delete all Norton protected files.


Your hijackthis log looks pretty good to me.
Let me know what problems you are still having.
  • 0

#10
stoorren

stoorren

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
I deleted those 2 maps, and cleaned my norton protected files.
Then I rescanned with Panda active scan, with the following results:

Incident Status Location

Potentially unwanted tool:Application/Pskill.K Not disinfected G:\downloads\bin\pskill.exe

Since I used the killbox, my Shareaza, and Limewire didn't start automatik, so thats back to normal.

So, I Deleted the pskill.exe file, and I think my problems are gone :whistling:

Thank you very much!
  • 0

#11
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
You're welcome! :blink:

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point left over from what we have just cleaned.

    You can find instructions on how to enable and reenable system restore here:

    Managing Windows Millenium System Restore

    or

    Windows XP System Restore Guide

    Renable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

:whistling: :help:
  • 0

#12
stoorren

stoorren

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Oke, my problem is solved.
I use Norton systemworks 2006, so I have anti-virus software, and an firewall, also my router has a build-in firewall.
For my spyware I use Hitman pro 2, So I think my pc is ''save'' now :whistling:

Thanx a lot again, and I think this topic can be closed?
  • 0

#13
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :whistling:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP