HijackThis log,
SUPERAntiSpyware Scan Log
uninstall_list and
Activescan results
what should i do next can some one please help?
------------------------------------------------------------------------------------------------------------------
HijakThis log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:22:24 PM, on 2/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\dXNlciAx\command.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\tsitra72.exe 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A284662E902BC
9ED7286138F75F2F0C8D6E84A1EF604776CA6C1637FE13FD97CB77
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfar...p1.0.0.15-3.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1202104112593
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: awvvw - C:\WINDOWS\system32\awvvw.dll (file missing)
O20 - Winlogon Notify: crypt32set - C:\WINDOWS\Media\fuwarxyus.dll
O20 - Winlogon Notify: jkkjgda - jkkjgda.dll (file missing)
O20 - Winlogon Notify: khfdedb - khfdedb.dll (file missing)
O21 - SSODL: fNeLX - {88E34F55-2249-E5FF-C9E3-BDBA8E07AA7C} - C:\WINDOWS\system32\xqs.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\dXNlciAx\command.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\bnpqyoqi.exe (file missing)
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:exe.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
--
End of file - 4046 bytes
-------------------------------------------------------------------------------------------------------------
uninstall_list
Adobe Flash Player 9 ActiveX
Apple Mobile Device Support
Apple Software Update
AVG Anti-Spyware 7.5
BCM V.92 56K Modem
BHO
Broadcom 440x 10/100 Integrated Controller
Command
Dell ResourceCD
Enhanced Ads by Think-Adz removal
HijackThis 2.0.2
Intel® Extreme Graphics Driver
Internet Speed Monitor
iTunes
Microsoft Office Professional Edition 2003
Network Monitor
OIN
Outerinfo
Panda ActiveScan
QuickTime
Roxio DLA
Roxio Express Labeler
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB923689)
Sonic Update Manager
SoundMAX
SUPERAntiSpyware Free Edition
SystemDoctor 1.1.173.0
TargetSaver
Think-Adz Search Assistant removal
Update for Windows XP (KB898461)
WinAntiSpyware 2006 Free 3.2.118.1
Windows Installer 3.1 (KB893803)
-------------------------------------------------------------------------------------------------------------
Activescan results
Incident Status Location
Adware:Adware/SearchAid Not disinfected C:\Program Files\Network Monitor\netmon.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\dXNlciAx\command.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\dXNlciAx\asappsrv.dll
Adware:adware/commad Not disinfected c:\windows\system32\atmtd.dll
Adware:adware/sqwire Not disinfected c:\windows\system32\tsuninst.exe
Potentially unwanted tool:application/winfixer2005 Not disinfected c:\windows\downloaded program files\UWA7P_0001_N91M0809NetInstaller.exe
Potentially unwanted tool:application/regclean32 Not disinfected C:\Documents and Settings\Owner\Desktop\Click to Find and Fix Errors.url
Adware:adware/keenvalue Not disinfected c:\program files\BHO
Potentially unwanted tool:application/winantispyware2006 Not disinfected hkey_local_machine\system\currentcontrolset\services\uwasfsd
Virus:Trj/Sinowal.RB Disinfected C:\30.tmp
Adware:Adware/Yazzle Not disinfected C:\38.tmp
Adware:Adware/Adband Not disinfected C:\3A.tmp
Virus:Trj/Downloader.QDR Disinfected C:\3E.tmp
Adware:Adware/Yazzle Not disinfected C:\D4.tmp
Virus:Trj/Downloader.RQM Disinfected C:\D6.tmp
Virus:Trj/Downloader.OBC Disinfected C:\D9.tmp
Virus:Generic Trojan Disinfected C:\Documents and Settings\All Users\Application Data\jmvkzqlc.dll
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\LocalService\Cookies\system@enhance[2].txt
Potentially unwanted tool:Application/Win-Touch Not disinfected C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\whlwov.exe
Virus:Trj/Agent.GJJ Disinfected C:\Documents and Settings\Owner\Application Data\WinTouch\WinTouch.exe
Potentially unwanted tool:Application/Win-Touch Not disinfected C:\Documents and Settings\Owner\Application Data\WinTouch\WTUninstaller.exe
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\!update.exe
Virus:Generic Trojan Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\e22d6yJ7.exe
Virus:Generic Trojan Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\EHyuMPWj.exe
Virus:Trj/Clicker.MP Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\hegfcdxb.exe
Virus:Trj/Downloader.PJT Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\hqyysbxi.exe
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\ipwlbooh.dll
Adware:Adware/Amera Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\ismtpa1.exe[ISMPack6.exe]
Virus:Trj/Downloader.QLY Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\ismupd8.exe[ISMPack5.exe]
Virus:Trj/Clicker.MP Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\iwuotusw.exe
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\ixytwbgm.dll
Virus:Generic Malware Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\NI.UWAS6_0001_N91M1508\setup.exe
Virus:Trj/Clicker.MP Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\psbuafic.exe
Virus:Trj/Downloader.PJT Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\qgvmwxns.exe
Virus:Generic Trojan Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\RhnM2Cwy.exe
Virus:Trj/Downloader.PCQ Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\rkmohnko.exe
Virus:Trj/Clicker.MP Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\rpvjxecq.exe
Virus:Trj/Exitwin.D Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\rsysinit.exe
Virus:Trj/Downloader.PUT Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\snapsnet.exe
Virus:Trj/Agent.GAP Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\sysskpi.exe
Adware:Adware/Zenosearch Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\thinksnet.exe
Adware:Adware/Sqwire Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\tsinstall_4_0_4_0_b4.exe
Adware:Adware/Sqwire Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\tsupdate_4_0_4_1_b3.exe
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\ugqpskds.dll
Virus:Trj/Agent.GYL Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\UpdateInsider\Installeur.exe
Virus:Trj/Agent.GYL Disinfected C:\Documents and Settings\Owner\Local Settings\Temp\UpdateInsider.zip[Installeur.exe]
Possible Virus. Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\UpdateWords\installeur.exe
Possible Virus. Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\UpdateWords.zip[installeur.exe]
Potentially unwanted tool:Application/ErrorSafe Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\USDR6_9999_N18M1603\installer.exe
Adware:Adware/BaiduBar Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\XgcDl3x2.exe
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\xnxgyhmq.dll
Adware:Adware/Yazzle Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\yazzlesnet.exe
Potentially unwanted tool:Application/SystemDoctor2006 Not disinfected C:\Documents and Settings\Owner\My Documents\SystemDoctorNewReleaseInstall.exe
Virus:Generic Trojan Disinfected C:\Documents and Settings\Owner\~tmp1174.exe
Adware:Adware/Yazzle Not disinfected C:\E5.tmp
Virus:Trj/Downloader.RQM Disinfected C:\E7.tmp
Virus:Trj/Downloader.OBC Disinfected C:\EA.tmp
Virus:Trj/Agent.GDJ Disinfected C:\Program Files\BHO\plugin.dll
Virus:Trj/Agent.GDJ Disinfected C:\Program Files\BHO\uninstall.exe
Virus:Generic Trojan Disinfected C:\Program Files\chctkdad\elgbatsf.dll
Potentially unwanted tool:Application/DriveCleaner Not disinfected C:\Program Files\Common Files\WinAntiSpyware 2006 Free\uwasdc.exe
Potentially unwanted tool:Application/DriveCleaner Not disinfected C:\Program Files\Common Files\WinAntiSpyware 2006 Free\uwasers.exe
Adware:Adware/Yazzle Not disinfected C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
Adware:Adware/Yazzle Not disinfected C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
Adware:Adware/Yazzle Not disinfected C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
Adware:Adware/Yazzle Not disinfected C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
Adware:Adware/Yazzle Not disinfected C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
Adware:Adware/Yazzle Not disinfected C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
Adware:Adware/Sqwire Not disinfected C:\Program Files\Common Files\zoku\zokua.exe
Adware:Adware/Sqwire Not disinfected C:\Program Files\Common Files\zoku\zokud\zokuc.dll
Adware:Adware/Sqwire Not disinfected C:\Program Files\Common Files\zoku\zokul.exe
Adware:Adware/Sqwire Not disinfected C:\Program Files\Common Files\zoku\zokum.exe
Adware:Adware/Sqwire Not disinfected C:\Program Files\Common Files\zoku\zokup.exe
Adware:Adware/PurityScan Not disinfected C:\Program Files\Common Files\?ecurity\services.exe
Adware:Adware/InternetSpeedMonitor Not disinfected C:\Program Files\ISM\archupd.exe
Virus:Trj/Downloader.MDW Disinfected C:\Program Files\ISM\BndDrive.dll
Virus:Generic Malware Disinfected C:\Program Files\ISM\BndDrive6.dll
Potentially unwanted tool:Application/DownAndRun Not disinfected C:\Program Files\ISM\bndloader.exe
Adware:Adware/Adband Not disinfected C:\Program Files\ISM\ism.exe
Virus:Trj/Downloader.QLX Not disinfected C:\Program Files\ISM\syncupd.exe[ISMModule4.exe]
Virus:Trj/Downloader.MDW Not disinfected C:\Program Files\ISM\synupd.exe[ISMModule6.exe]
Virus:Generic Malware Not disinfected C:\Program Files\ISM\synupd.exe[BndDrive6.dll]
Virus:Trj/Downloader.REF Disinfected C:\Program Files\ISM2\cringupd.exe
Virus:Trj/Downloader.QLY Disinfected C:\Program Files\ISM2\ISMPack5.exe
Adware:Adware/Amera Not disinfected C:\Program Files\ISM2\ISMPack6.exe
Virus:Trj/Downloader.MDW Disinfected C:\Program Files\ISM2\ISMPack8.exe
Virus:Generic Trojan Disinfected C:\Program Files\Mnpakzgu\btjwtfvn.dll
Adware:Adware/Zenosearch Not disinfected C:\Program Files\Outerinfo\FF\components\FF.dll
Adware:Adware/InternetSpeedMonitor Not disinfected C:\Program Files\QdrModule\QdrModule9.exe
Adware:Adware/InternetSpeedMonitor Not disinfected C:\Program Files\QdrPack\QdrPack11.exe
Adware:Adware/InternetSpeedMonitor Not disinfected C:\Program Files\QdrPack\trffyupd.exe[QdrPack11.exe]
Possible Virus. Not disinfected C:\Program Files\SecCenter\scprot4.exe
Virus:Trj/Downloader.MDW Disinfected C:\Program Files\Temporary\wininstall.exe
Virus:Generic Trojan Disinfected C:\Program Files\Web Buying\v1.8.0\webbuying.exe
Virus:Trj/Downloader.QLZ Disinfected C:\Program Files\WinAble\winable.exe
Virus:Generic Malware Disinfected C:\Program Files\WinAntiSpyware 2006 Free\AsAgents.dll
Spyware:Application/ErrorProtector Not disinfected C:\Program Files\WinAntiSpyware 2006 Free\InstHelp.exe
Virus:Generic Malware Disinfected C:\Program Files\WinAntiSpyware 2006 Free\uwas6chk.dll
Potentially unwanted tool:Application/DriveCleaner Not disinfected C:\Program Files\WinAntiSpyware 2006 Free\uwas6cw.exe
Potentially unwanted tool:Application/WinAntivirus Not disinfected C:\Program Files\WinAntiSpyware 2006 Free\uwasffNT.exe
Virus:Trj/Downloader.MDW Disinfected C:\Program Files\WinAntiSpyware 2006 Free\was6.exe
Virus:Trj/Agent.GAP Disinfected C:\sysskpi.exe
Virus:Generic Malware Disinfected C:\WINDOWS\b103.exe
Virus:Generic Trojan Disinfected C:\WINDOWS\b104.exe
Virus:Trj/Downloader.MDW Disinfected C:\WINDOWS\b122.exe
Virus:Trj/Downloader.MDW Disinfected C:\WINDOWS\b122.exe.bin[b122.exe]
Adware:Adware/Yazzle Not disinfected C:\WINDOWS\b128.exe
Virus:Trj/Downloader.PLQ Disinfected C:\WINDOWS\b138.exe
Virus:Trj/Downloader.MDW Disinfected C:\WINDOWS\b143.exe
Virus:Trj/Downloader.MDW Disinfected C:\WINDOWS\b147.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\dXNlciAx\xrh5w2EU.vbs
Possible Virus. Not disinfected C:\WINDOWS\Media\fuwarxyus.dll
Adware:Adware/Yazzle Not disinfected C:\WINDOWS\retadpu72.exe.tmp
Virus:Trj/BHO.O Disinfected C:\WINDOWS\system32\02cSTWdY.dll
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\abeeriqd.dll
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\acxwwhls.exe
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\aduwpuqm.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\ahhdbrsk.dll
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\aphtptwp.exe
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\apovjnwj.exe
Adware:Adware/DollarRevenue Not disinfected C:\WINDOWS\system32\atmtd.dll._
Adware:Adware/BHO Not disinfected C:\WINDOWS\system32\AU48iI55.dll
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\axuhiuhf.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\befbufne.dll
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\bewwqgbr.dll
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\bhmljnhk.dll
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\bpmdovvu.exe
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\bqiseqqk.exe
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\brcwwutc.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\brfbvcum.dll
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\btnlfuhw.exe
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\cgdrxpjn.exe
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\chhxjihf.exe
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\WINDOWS\system32\config\systemprofile\Cookies\system@doubleclick[1].txt
Spyware:Cookie/FastClick Not disinfected C:\WINDOWS\system32\config\systemprofile\Cookies\system@fastclick[2].txt
Spyware:Cookie/Overture Not disinfected C:\WINDOWS\system32\config\systemprofile\Cookies\system@overture[1].txt
Spyware:Cookie/Zedo Not disinfected C:\WINDOWS\system32\config\systemprofile\Cookies\system@zedo[1].txt
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\crdctscn.exe
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\crfvcmqr.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\dbuxurmt.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\ddmjvohc.dll
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\devxqcqh.exe
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\dhxjomxv.exe
Virus:W32/ZlFake.A Disinfected C:\WINDOWS\system32\DLA\DLACTRLW.EXE
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\dlhrsumc.exe
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\dlvuward.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\dmncmler.dll
Virus:Trj/Downloader.OZB Disinfected C:\WINDOWS\system32\dniutnss.exe
Edited by kuraikinzoku, 04 February 2008 - 03:52 AM.