hey kahdah,
i followed your instructions and please find the logs below. things are runnnig better now, my version of avg must havebecome broken or something becausewhen i tried to run it it crashed.installed the newverison and it worked,althoughwheni tried toscna second time it crashed the machine with a fatal error.
New Hjt logLogfile of HijackThis v1.99.1
Scan saved at 1:27:28 PM, on 5/02/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\services.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Hijackthis\HijackThis.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO20 - AppInit_DLLs:
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
AVG LOG---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:47:41 AM 5/02/2007
+ Scan result:
C:\Program Files\BraveSentry -> Adware.Bravesentry : Cleaned with backup (quarantined).
C:\Program Files\BraveSentry\BraveSentry.lic -> Adware.Bravesentry : Cleaned with backup (quarantined).
C:\Program Files\BraveSentry\Uninstall.exe -> Adware.Bravesentry : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP382\A0109321.dll -> Adware.Companion : Cleaned with backup (quarantined).
E:\Program Files\Picasa\pinstall.dll -> Adware.LookMe : Cleaned with backup (quarantined).
E:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109286.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109287.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109288.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109289.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109285.exe -> Adware.SpySheriff : Cleaned with backup (quarantined).
E:\WINDOWS\system32\cpqiq.dll -> Adware.WurldMedia : Cleaned with backup (quarantined).
E:\WINDOWS\system32\winbpupd.exe -> Adware.WurldMedia : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP336\A0083800.dll -> Downloader.Nurech.m : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP382\A0109322.exe -> Downloader.Nurech.m : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP382\A0109323.exe -> Downloader.Nurech.m : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109237.exe -> Downloader.Obfuscated.bh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109239.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109241.exe -> Downloader.Small.agq : Cleaned with backup (quarantined).
C:\WINDOWS\uwr3wqje.exe -> Downloader.Tiny.fl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0108240.sys -> Dropper.Agent.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109263.sys -> Dropper.Agent.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109246.dll -> Logger.BZub.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110339.exe -> Logger.BZub.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110340.exe -> Logger.BZub.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110343.exe -> Logger.BZub.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110367.exe -> Logger.BZub.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110368.exe -> Logger.BZub.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110371.exe -> Logger.BZub.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP365\A0096048.dll -> Logger.BZub.gq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP366\A0096053.exe -> Logger.BZub.gr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP366\A0096065.exe -> Logger.BZub.gr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP367\A0096072.exe -> Logger.BZub.gr : Cleaned with backup (quarantined).
C:\WINDOWS\english.exe -> Logger.BZub.gr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109248.dll -> Logger.BZub.hg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109247.dll -> Logger.BZub.ht : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109238.exe -> Proxy.Cimuz.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110338.exe -> Proxy.Cimuz.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110342.exe -> Proxy.Cimuz.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110344.exe -> Proxy.Cimuz.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110348.exe -> Proxy.Cimuz.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110366.exe -> Proxy.Cimuz.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110370.exe -> Proxy.Cimuz.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110372.exe -> Proxy.Cimuz.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110376.exe -> Proxy.Cimuz.bw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\rsvp32_2.dll -> Proxy.Cimuz.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109224.dll -> Proxy.Small : Cleaned with backup (quarantined).
E:\Documents and Settings\Adam\Cookies\adam@com[1].txt -> TrackingCookie.Com : Cleaned.
E:\Documents and Settings\Adam\Cookies\
[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109302.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP382\A0109328.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP382\A0110328.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110336.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110362.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110365.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110383.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110391.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110418.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wsys.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
[472] C:\WINDOWS\System32\wsys.dll -> Trojan.Agent.ady : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0108227.exe -> Trojan.Agent.oh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109257.exe -> Trojan.Agent.oh : Cleaned with backup (quarantined).
[1588] VM_13140000 -> Trojan.Agent.zq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110341.exe -> Trojan.Delf.yz : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110369.exe -> Trojan.Delf.yz : Cleaned with backup (quarantined).
C:\fsuls.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined).
C:\gtroncwt.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined).
C:\lvnu.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined).
C:\lypq.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined).
C:\mtiytn.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined).
C:\yvatjug.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll -> Trojan.Sinowal.bh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109250.exe -> Trojan.Sinowal.bh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP366\A0096054.dll -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP366\A0096066.dll -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP378\A0102108.dll -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0108231.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0108234.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0108235.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0108236.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0108237.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109258.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109259.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110345.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110346.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP383\A0110347.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110373.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110374.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP384\A0110375.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B68FB5FC-E2C8-4448-B972-7D1F2E384EB9}\RP381\A0109251.exe -> Trojan.Zapchast.cm : Cleaned with backup (quarantined).
::Report end
avenger logLogfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\mjesqpxu
*******************
Script file located at: \??\C:\WINDOWS\vouvsmua.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Driver PE386 unloaded successfully.
Program C:\Rustbfix\2run.bat successfully set up to run once on reboot.
Completed script processing.
*******************
Finished! Terminate.
rustbix************************* Rustock.b-fix -- By ejvindh *************************
Mon 05/02/2007 9:34:05.04
No Rustock.b-rootkits found
******************************* End of Logfile ********************************
panda sanIncident Status Location
Virus:trj/torpig.a Disinfected Operating system
Potentially unwanted tool:application/winantivirus2006 Not disinfected c:\documents and settings\all users\application data\WinAntiVirus Pro 2006
Adware:adware/sahagent Not disinfected Windows Registry
Virus:trj/qhost.gen Disinfected Operating system
Adware:Adware/BraveSentry Not disinfected C:\Documents and Settings\aa\Application Data\Install.dat
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Administrator\Desktop\SDFix.exe[SDFix\apps\Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\SDFix\apps\Process.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\hgfcay.dll
Potentially unwanted tool:Application/Restart Not disinfected C:\WINDOWS\system32\Tools\Restart.exe
Spyware:Cookie/Xiti Not disinfected E:\Documents and Settings\Adam\Cookies\adam@xiti[1].txt
Potentially unwanted tool:Application/FunWeb Not disinfected E:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.6.inf