Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Please take a look @ my Hjack log with your expert eyes


  • Please log in to reply

#1
jc6212

jc6212

    New Member

  • Member
  • Pip
  • 3 posts
** btw, a lot of infections have been tossed around like hot potatoes from each programs' quarantined folders ** qoobox, combofixs surviving folder, for example holds the most now- **


** My Hjack log is @ the bottom, please let me know if there's anything I should remove,
1 in paticular, can i remove: F3 - REG:win.ini: load=C:\WINDOWS\system32\tusrq.exe <--- i get popups on startup that theres a related file missing

chain of events::

Combofix

Adaware

VundoRemover

Avira virus scan and removal-

AVG scan and removal-

SCAN LOG:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 8:34:35 PM 1/9/2008

+ Scan result:



C:\QooBox\Quarantine\C\WINDOWS\b148.exe.vir -> Downloader.Agent.hbd : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ardCo18\ardCo182328.exe -> Downloader.VB.ccs : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\CursorXP\CursorXP.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\DAEMON Tools\daemon.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_02\bin\jusched.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Messenger\msmsgs.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Microsoft IntelliPoint\point32.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\twc\medicsp2\bin\sprtcmd.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\ezSP_Px .exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00067522.EX^ -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00067623.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\VundoFix Backups\ezSP_Px.exe.bad -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1281OinUninstaller.exe.vir -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\YMBOLS~1\rυndll.exe.vir -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M2210NetInstaller.exe.vir -> Not-A-Virus.Downloader.Win32.WinFixer.au : Cleaned with backup (quarantined).
:mozilla.136:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.137:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.138:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.122:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.123:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.202:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.203:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.204:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.205:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.206:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.207:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.208:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.209:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.52:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.65:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.66:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.67:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.68:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.28:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.49:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.75:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\buschdiver\Cookies\[email protected]tnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\buschdiver\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.242:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.243:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.244:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.245:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.246:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.247:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.240:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\buschdiver\Cookies\[email protected][1].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.69:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\buschdiver\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.70:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.71:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.72:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.73:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.74:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.141:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.117:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.7:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.190:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.156:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.157:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.158:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.159:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.160:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.161:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.162:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.264:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.265:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.103:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.104:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.90:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.91:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.92:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.97:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.99:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.210:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.211:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.212:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.213:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.214:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.215:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.217:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.130:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.121:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.241:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.81:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.82:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.83:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.84:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.85:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.249:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.250:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.251:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.252:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.253:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.30:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.129:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.179:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.102:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.93:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.94:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.95:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.100:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.96:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.98:C:\Documents and Settings\buschdiver\Application Data\Mozilla\Firefox\Profiles\jmeqwm9u.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt -> TrackingCookie.Zedo : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\wapiicomsv.exe.vir -> Trojan.Small : Cleaned with backup (quarantined).


::Report end



********************************************************************************
***




SUPERAntiSpyware Scan Log
Generated 01/09/2008 at 09:29 PM

Application Version : 3.6.1000

Core Rules Database Version : 3377
Trace Rules Database Version: 1371

Scan type : Quick Scan
Total Scan Time : 00:36:38

Memory items scanned : 346
Memory threats detected : 0
Registry items scanned : 608
Registry threats detected : 0
File items scanned : 12450
File threats detected : 17

Adware.Tracking Cookie
C:\Documents and Settings\buschdiver\Cookies\[email protected][1].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][1].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][1].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][1].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][2].txt
C:\Documents and Settings\buschdiver\Cookies\[email protected][1].txt

Adware.Vundo Variant
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\TUVUVTR.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\XXYVUVT.DLL.VIR

Trojan.Downloader-Gen/DDC
C:\VUNDOFIX BACKUPS\BDTYSPUF.EXE.BAD
C:\VUNDOFIX BACKUPS\BKNQVEPO.EXE.BAD





**************************************************************





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:55:50 AM, on 1/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\ezSP_Px .exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\1-Click Answers\answers.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\1-Click Answers\agtserv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
F3 - REG:win.ini: load=C:\WINDOWS\system32\tusrq.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
O2 - BHO: (no name) - {718355E0-853A-4A13-BB2E-F6CC2F2F2348} - \
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {829C6FE6-9D11-405B-B1F5-75BEEF1C46D4} - C:\WINDOWS\system32\tusrq.dll (file missing)
O2 - BHO: {359eb164-2793-20aa-de94-1da7a1e4c55e} - {e55c4e1a-7ad1-49ed-aa02-3972461be953} - C:\WINDOWS\system32\loflcsgl.dll (file missing)
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px .exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files\BlazeVideo\BlazeDVD4 Professional\MediaDetector.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE http://www.symantec....0000d4.00000264
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office2K\Office\OSA9.EXE
O8 - Extra context menu item: Answers... - file:C:\Program Files\1-Click Answers\Html\atiemenu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr...ads/tgctlcm.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...195/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 6343 bytes



* Any help would be greatly appreciated * Thanks
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP