Logfile of HijackThis v1.99.1
Scan saved at 05:25:12 AM, on 2006/11/30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\dxtconf.exe
C:\WINDOWS\system32\fsdconf.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ASWLSVC.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\system32\ASWL2K.exe
C:\Program Files\Asus\Asus ChkMail\ChkMail.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Mark Asus\Desktop\spyware removal geeks\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://C:\WINDOWS\system32\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [brwdiag] C:\WINDOWS\system32\brwconf.exe
O4 - HKLM\..\Run: [ijtdiag] C:\WINDOWS\system32\ijtconf.exe
O4 - HKLM\..\Run: [deidiag] C:\WINDOWS\system32\deiconf.exe
O4 - HKLM\..\Run: [dxtdiag] C:\WINDOWS\system32\dxtconf.exe
O4 - HKLM\..\Run: [fsddiag] C:\WINDOWS\system32\fsdconf.exe
O4 - HKLM\..\Run: [isrdiag] C:\WINDOWS\system32\isrconf.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: ASUS ChkMail.lnk = C:\Program Files\Asus\Asus ChkMail\ChkMail.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Picture Package Menu.lnk = ?
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3BFFDB8-6B6F-4A66-AC66-00CD95D9B13E}: NameServer = 192.168.2.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{EE7D341B-AAE4-4923-A267-7048432465AA}: NameServer = 192.168.0.200
O20 - AppInit_DLLs: e1.dll libdcabi.dll confbrw.dll brwstat.dll confaud.dll audstat.dll diagijt.dll statijt.dll diagdei.dll statdei.dll diagcre.dll statcre.dll diagdxt.dll statdxt.dll diagfsd.dll statfsd.dll diagisr.dll statisr.dll
O20 - Winlogon Notify: audmgr - audmgr32.dll (file missing)
O20 - Winlogon Notify: brwmgr - brwmgr32.dll (file missing)
O20 - Winlogon Notify: deiconf - cfgdei.dll (file missing)
O20 - Winlogon Notify: dxtconf - C:\WINDOWS\SYSTEM32\cfgdxt.dll
O20 - Winlogon Notify: fsdconf - C:\WINDOWS\SYSTEM32\cfgfsd.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ijtconf - cfgijt.dll (file missing)
O20 - Winlogon Notify: isrconf - C:\WINDOWS\SYSTEM32\cfgisr.dll
O20 - Winlogon Notify: vsutmsgi - C:\WINDOWS\system32\vsutmsgi.dll (file missing)
O23 - Service: ASWLSVC - Unknown owner - C:\WINDOWS\system32\ASWLSVC.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
Incident Status Location
Virus:W32/Spamta.LK.worm Disinfected Operating system
Virus:W32/Spamta.LB.worm Disinfected C:\WINDOWS\system32\audprf32.dll
Virus:Trj/SpamtaLoad.BP Disinfected Local Folders\Deleted Items\Mail server report.\Update-KB6562-x86.zip[Update-KB6562-x86.exe]
Virus:Trj/Spamtaload.AR Disinfected Local Folders\Deleted Items\This is not shown on TV.\picture8421..gif. exe
Virus:Trj/SpamtaLoad.AL Disinfected Local Folders\Deleted Items\Livan War real pictures.\picture703.zip[picture703.jpg .exe]
Virus:Trj/SpamtaLoad.AL Disinfected Local Folders\Deleted Items\Error\text.zip[text.dat.cmd]
Virus:Trj/SpamtaLoad.AL Disinfected Local Folders\Deleted Items\Livan War real pictures.\picture4093..gif. exe
Virus:Trj/SpamtaLoad.AL Disinfected Local Folders\Deleted Items\Mail Transaction Failed\file.zip[file.log.scr]
Virus:Trj/SpamtaLoad.AL Disinfected Local Folders\Deleted Items\Livan War real pictures.\picture218.zip[picture218.gif .exe]
Virus:Trj/SpamtaLoad.BE Disinfected Local Folders\Deleted Items\Mail delivery Error\attach4687..txt. exe
Virus:Trj/SpamtaLoad.BE Disinfected Local Folders\Deleted Items\Mail Delivery System\text.zip[text.msg.scr]
Virus:Trj/Spamtaload.AR Disinfected Local Folders\Deleted Items\test\body.zip[body.log.cmd]
Virus:Trj/Spamtaload.AI Disinfected Local Folders\Deleted Items\Mail server report.\Update-KB9562-x86.zip[Update-KB9562-x86.exe]
Virus:Trj/SpamtaLoad.BL Disinfected Local Folders\Deleted Items\test\document.zip[document.txt.cmd]
Virus:Trj/SpamtaLoad.BL Disinfected Local Folders\Deleted Items\Mail server report.\Update-KB7640-x86.zip[Update-KB7640-x86.exe]
Virus:Trj/SpamtaLoad.BH Disinfected Local Folders\Deleted Items\hello\doc.zip[doc.dat.pif]
Virus:Trj/SpamtaLoad.BH Disinfected Local Folders\Deleted Items\Mail server report.\Update-KB2236-x86.zip[Update-KB2236-x86.exe]
Virus:Trj/SpamtaLoad.BP Disinfected Local Folders\Deleted Items\picture\readme.zip[readme.elm.cmd]
Virus:Trj/SpamtaLoad.BP Disinfected Local Folders\Deleted Items\Mail server report.\Update-KB578-x86.zip[Update-KB578-x86.exe]
Virus:Trj/SpamtaLoad.N Disinfected Local Folders\Deleted Items\Mail server report.\Update-KB6281-x86.zip[Update-KB6281-x86.exe]