Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:31:53 PM, on 4/29/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
D:\WINDOW\System32\smss.exe
D:\WINDOW\system32\winlogon.exe
D:\WINDOW\system32\services.exe
D:\WINDOW\system32\lsass.exe
D:\WINDOW\system32\svchost.exe
D:\WINDOW\System32\svchost.exe
D:\Program Files\Lavasoft\aawservice.exe
D:\WINDOW\Explorer.EXE
D:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
D:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\WINDOW\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
D:\WINDOW\System32\taskmgr.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zeropaid.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: {95ad647a-11c7-dc7a-5634-8a1cc33042c8} - {8c24033c-c1a8-4365-a7cd-7c11a746da59} - D:\WINDOW\System32\wvjvqicp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOW\System32\msdxm.ocx
O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
O4 - HKLM\..\Run: [MCUpdateExe] D:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] D:\PROGRA~1\McAfee.com\Agent\McAgent.exe
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [000000af] rundll32.exe "D:\WINDOW\System32\dwbginmb.dll",b
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] D:\Program Files\Mozilla Firefox\plugins\NPSWF32_FlashUtil.exe -p
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOW\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOW\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1201735493873
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: fccaXNHw - D:\WINDOW\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
--
End of file - 4289 bytes
If you all need this - - Malware byte's antimalware log.
Malwarebytes' Anti-Malware 1.11
Database version: 694
Scan type: Full Scan (D:\|)
Objects scanned: 153172
Time elapsed: 11 hour(s), 30 minute(s), 35 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 19
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\Software\AntiSpywareMaster (Rogue.AntiSpywareMaster) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM23c3d46e (Trojan.Agent) -> Delete on reboot.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
D:\Documents and Settings\All Users.WINDOW\Start Menu\Programs\AntiSpywareMaster (Rogue.AntiSpywareMaster) -> Quarantined and deleted successfully.
Files Infected:
D:\Documents and Settings\Terry\Local Settings\Temp\djevrsgd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\Documents and Settings\Terry\Local Settings\Temp\hwafhyfh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\Documents and Settings\Terry\Local Settings\Temp\lxqubyua.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\Documents and Settings\Terry\Local Settings\Temp\outerinfo.ico (Malware.Trace) -> Quarantined and deleted successfully.
D:\Documents and Settings\Terry\Local Settings\Temp\wkdxgssi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\LZF979F8\CAK5AV4P (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP77\A0002687.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP77\A0002692.dll (Adware.ZenoSearch) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP77\A0002693.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP77\A0002714.exe (Adware.Purityscan) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP78\A0003742.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP78\A0003743.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP81\A0003839.exe (Rogue.AntiSpyMaster) -> Quarantined and deleted successfully.
D:\WINDOW\system32\jsllcbqr.VIR (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\Documents and Settings\All Users.WINDOW\Start Menu\Programs\AntiSpywareMaster\AntiSpywareMaster.lnk (Rogue.AntiSpywareMaster) -> Quarantined and deleted successfully.
D:\Documents and Settings\All Users.WINDOW\Start Menu\Programs\AntiSpywareMaster\Uninstall AntiSpywareMaster.lnk (Rogue.AntiSpywareMaster) -> Quarantined and deleted successfully.
D:\WINDOW\system32\xtwcyduh.dll (Trojan.Agent) -> Delete on reboot.
D:\Documents and Settings\Terry\Desktop\AntiSpywareMaster.lnk (Rogue.AntiSpywareMaster) -> Quarantined and deleted successfully.
D:\Documents and Settings\Terry\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiSpywareMaster.lnk (Rogue.AntiSpywareMaster) -> Quarantined and deleted successfully.
And a kaspersky online scan log- -
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 29, 2008 9:17:13 PM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/04/2008
Kaspersky Anti-Virus database records: 731399
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
D:\
E:\
F:\
Scan Statistics
Total number of scanned objects 95046
Number of viruses found 6
Number of infected objects 12
Number of suspicious objects 0
Duration of the scan process 07:51:06
Infected Object Name Virus Name Last Action
D:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\Terry\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-4-29-2008( 13-0-21 ).LOG Object is locked skipped
D:\Documents and Settings\Terry\Cookies\index.dat Object is locked skipped
D:\Documents and Settings\Terry\Desktop\Download_mbam-setup.exe Infected: not-a-virus:Downloader.Win32.WinFixer.fs skipped
D:\Documents and Settings\Terry\Desktop\Download_spyzookasetup1.exe Infected: not-a-virus:Downloader.Win32.WinFixer.fs skipped
D:\Documents and Settings\Terry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\Terry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\Terry\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Documents and Settings\Terry\Local Settings\History\History.IE5\MSHist012008042920080430\index.dat Object is locked skipped
D:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Documents and Settings\Terry\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\Terry\NTUSER.DAT.LOG Object is locked skipped
D:\Documents and Settings\Terry Castleman\Application Data\Kontiki\GameSpot\thumbnails\Thumbs.db Object is locked skipped
D:\Program Files\Old Hard Drive\Previous Installation\mirc\backup\mirc32.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.571 skipped
D:\Program Files\Old Hard Drive\Previous Installation\mirc\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
D:\Program Files\Old Hard Drive\Previous Installation\mirc\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
D:\Program Files\Old Hard Drive\Previous Installation\mirc\mirc616.exe mIRC: infected - 1 skipped
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP77\A0002717.dll Infected: Packed.Win32.Monder.gen skipped
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP78\A0002733.dll Infected: Packed.Win32.Monder.gen skipped
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP78\A0003733.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrg skipped
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP78\A0003745.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrh skipped
D:\System Volume Information\_restore{9BCA5F72-8F82-4DC1-B032-FF39491B9174}\RP82\change.log Object is locked skipped
D:\WINDOW\Debug\oakley.log Object is locked skipped
D:\WINDOW\Debug\PASSWD.LOG Object is locked skipped
D:\WINDOW\SchedLgU.Txt Object is locked skipped
D:\WINDOW\SoftwareDistribution\ReportingEvents.log Object is locked skipped
D:\WINDOW\system32\config\AppEvent.Evt Object is locked skipped
D:\WINDOW\system32\config\default Object is locked skipped
D:\WINDOW\system32\config\default.LOG Object is locked skipped
D:\WINDOW\system32\config\SAM Object is locked skipped
D:\WINDOW\system32\config\SAM.LOG Object is locked skipped
D:\WINDOW\system32\config\SecEvent.Evt Object is locked skipped
D:\WINDOW\system32\config\SECURITY Object is locked skipped
D:\WINDOW\system32\config\SECURITY.LOG Object is locked skipped
D:\WINDOW\system32\config\software Object is locked skipped
D:\WINDOW\system32\config\software.LOG Object is locked skipped
D:\WINDOW\system32\config\SysEvent.Evt Object is locked skipped
D:\WINDOW\system32\config\system Object is locked skipped
D:\WINDOW\system32\config\system.LOG Object is locked skipped
D:\WINDOW\system32\h323log.txt Object is locked skipped
D:\WINDOW\system32\QUACMDVQ.VIR Infected: Packed.Win32.Monder.gen skipped
D:\WINDOW\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
D:\WINDOW\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
D:\WINDOW\system32\wvjvqicp.dll Infected: Packed.Win32.Monder.gen skipped
D:\WINDOW\WindowsUpdate.log Object is locked skipped
D:\WINDOWS\$NtUninstallKB826942$\ndis.sys Object is locked skipped
D:\WINDOWS\$NtUninstallKB826942$\ndisuio.sys Object is locked skipped
D:\WINDOWS\$NtUninstallKB826942$\netshell.dll Object is locked skipped
D:\WINDOWS\$NtUninstallKB826942$\wzcdlg.dll Object is locked skipped
D:\WINDOWS\$NtUninstallKB826942$\wzcsapi.dll Object is locked skipped
D:\WINDOWS\$NtUninstallKB826942$\wzcsvc.dll Object is locked skipped
Scan process completed.
Thank you all so much!!