trojan.win32.obfuscated.gx has infected my work computer. please help, Read before.... unfortunately did not work. I can only access my pc i |
![]() ![]() |
trojan.win32.obfuscated.gx has infected my work computer. please help, Read before.... unfortunately did not work. I can only access my pc i |
Dec 16 2007, 10:13 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 11 OS: XP |
Here is my HiJack This log:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:46:04 PM, on 12/16/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Safe mode with network support Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C: \Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: IE plugin - {17A1DBB5-DAD8-4E78-BF7E-9BE4B965408B} - C:\WINDOWS\pmspl. dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c: \program files\google\googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System 32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C: \Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops. cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages. exe O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" - atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10 \bin\jusched.exe" O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" / hide /waitservice O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages. exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0 \Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1 \MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C 608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~ 1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C: \WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa 003c157a} - C:\WINDOWS\web\related.htm O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {CAFECAFE-0013-0001-0025-ABCDEFABCDEF} (JInitiator 1.3.1.25) - http:// hxphlbusvxxxap1/webhtml/opera_jinit_1012_25.exe O16 - DPF: {DAAC8ECF-DB09-4821-8126-E2C9499A20BA} (RegTerminalSrv Object) - http ://hxphlbusvxxxap1/installregterm.exe O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/ download/files/abasetup161.cab O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cnatla4svradx01. local,inns.hiw.com,hiw.com O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cnatla4svradx01. local,inns.hiw.com,hiw.com O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = cnatla4svradx01. local,inns.hiw.com,hiw.com O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cnatla4svradx01. local,inns.hiw.com,hiw.com O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C: \Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O24 - Desktop Component 0: (no name) - http://asp7.centra.com/SiteRoots/main/ AgendaStorageRoot/Cobranding/0000014189d000000102fc8e37ab9de6/En/US/Images/Banner .gif -- End of file - 6960 bytes **************************************** Uninstall list from HiJack This: Abacast Client Access IBM Access IBM Cleanup Utility Access IBM Message Center Access IBM Tools Adobe Acrobat 4.0, 5.0 Adobe Flash Player 9 ActiveX Adobe Shockwave Player AIM 6 AOL Instant Messenger Boomer Radio Tuner CentraOne DirectX 9 Hotfix - KB839643 DivX Content Uploader DivX Web Player ESET NOD32 Antivirus Google Toolbar for Internet Explorer Google Updater HijackThis 2.0.2 IBM Access Support IBM Access Support - Local Content Pack IBM Printer Software Uninstall IBM Update Connector Intel® Extreme Graphics 2 Driver Intel® PRO Network Adapters and Drivers Intel® PROSet J2SE Runtime Environment 5.0 Update 10 Java 2 Runtime Environment Standard Edition v1.3.1_11 LiveUpdate 2.5 (Symantec Corporation) McAfee VirusScan Enterprise Micros Fidelio Opera Print Utility Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 2.0 Microsoft Data Access Components KB870669 Microsoft Office Standard Edition 2003 MSN Music Assistant Norton Security Scan Opera Register Terminal Oracle JInitiator 1.3.1.25 Oracle JInitiator 1.3.1.25 Oracle JInitiator 1.3.1.9 Outlook Express Q823353 Panda ActiveScan PC-Doctor for Windows Picasa 2 QuickTime SoundMAX Spyware Doctor 5.1 Support.com Software ThinkCentre Wallpaper Update for Windows XP (KB931836) Viewpoint Media Player Windows Installer 3.1 (KB893803) Windows Live Toolbar Windows Live Toolbar Windows Media Format Runtime Windows Media Player 10 Windows Media Player Hotfix [See Q828026 for more information] Windows XP Hotfix - KB823182 Windows XP Hotfix - KB824105 Windows XP Hotfix - KB825119 Windows XP Hotfix - KB826939 Windows XP Hotfix - KB828035 Windows XP Hotfix - KB828741 Windows XP Hotfix - KB833407 Windows XP Hotfix - KB833987 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB835732 Windows XP Hotfix - KB837001 Windows XP Hotfix - KB839645 Windows XP Hotfix - KB840315 Windows XP Hotfix - KB840374 Windows XP Hotfix - KB840987 Windows XP Hotfix - KB841356 Windows XP Hotfix - KB841533 Windows XP Hotfix - KB841873 Windows XP Hotfix - KB842773 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB873376 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB889293 Windows XP Hotfix (SP2) [See Q331060 for more information] WinRAR archiver Xvid 1.1.3 final uninstall ******************************************************** Need all the help I can get. Have been in contact with friends who work at Micro Center and the Googleplex to no avail. Thank you in advance. |
|
|
Dec 22 2007, 06:38 AM
Post
#2
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Hello and welcome
sorry for the delay
Lets make sure we got it all Please download Deckard's System Scanner (DSS) and save it to your Desktop.
|
|
|
Dec 22 2007, 02:37 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 11 OS: XP |
that prog didnt work when i downloaded it the same night i got the virus. i had since deleted it but just got it again and tried. the FixIEDef.bat file was not in there. there wasFixIEDef.php, which i figured was that file since it was around the same file size so i change the extension (it did not say that changing the extension may make the file unusable). I clicked on it, the command screen popped up for a split second and went away. Again the program did not work, but I'm thinking it didn't this time because i am running in safe mode, the only way i can even run my pc. any other suggestions?
|
|
|
Dec 22 2007, 10:02 PM
Post
#4
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
run DSS please and post back the logs from it please
|
|
|
Dec 23 2007, 07:29 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 11 OS: XP |
Here it is:
Deckard's System Scanner v20071014.68 Run by Administrator on 2007-12-23 20:27:13 Computer is in Safe Mode with Networking. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Failed to create restore point; computer is in safe mode. -- Last 1 Restore Point(s) -- 1: 2007-12-16 03:41:50 UTC - RP988 - Installed ESET NOD32 Antivirus Backed up registry hives. Performed disk cleanup. Total Physical Memory: 503 MiB (512 MiB recommended). -- HijackThis (run as Administrator.exe) --------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:28:59 PM, on 12/23/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Safe mode with network support Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Administrator\My Documents\ALONZo\dss.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\Administrator.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: IE plugin - {17A1DBB5-DAD8-4E78-BF7E-9BE4B965408B} - C:\WINDOWS\pmspl.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {CAFECAFE-0013-0001-0025-ABCDEFABCDEF} (JInitiator 1.3.1.25) - http://hxphlbusvxxxap1/webhtml/opera_jinit_1012_25.exe O16 - DPF: {DAAC8ECF-DB09-4821-8126-E2C9499A20BA} (RegTerminalSrv Object) - http://hxphlbusvxxxap1/installregterm.exe O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup161.cab O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cnatla4svradx01.local,inns.hiw.com,hiw.com O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cnatla4svradx01.local,inns.hiw.com,hiw.com O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = cnatla4svradx01.local,inns.hiw.com,hiw.com O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cnatla4svradx01.local,inns.hiw.com,hiw.com O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O24 - Desktop Component 0: (no name) - http://asp7.centra.com/SiteRoots/main/Agen...ages/Banner.gif -- End of file - 6612 bytes -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R1 NaiAvTdi1 - c:\windows\system32\drivers\mvstdi5x.sys <Not Verified; Network Associates, Inc.; VirusScan> S1 eeCtrl (Symantec Eraser Control driver) - c:\program files\common files\symantec shared\eengine\eectrl.sys (file missing) S2 PMEM - c:\windows\system32\drivers\pmemnt.sys <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System> S3 EntDrv51 - c:\windows\system32\drivers\entdrv51.sys <Not Verified; Network Associates, Inc; Virus Scan Enterprise, Entercept> S3 NaiAvFilter1 - c:\windows\system32\drivers\naiavf5x.sys <Not Verified; Network Associates, Inc.; VirusScan (Enterprise, ASaP & Retail.)> -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- S2 McAfeeFramework (McAfee Framework Service) - "c:\program files\network associates\common framework\frameworkservice.exe" /servicestart <Not Verified; McAfee, Inc.; McAfee Common Framework> S2 McTaskManager (Network Associates Task Manager) - "c:\program files\network associates\virusscan\vstskmgr.exe" <Not Verified; Network Associates, Inc.; VirusScan Enterprise> S2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager> -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Scheduled Tasks ------------------------------------------------------------- 2007-12-17 11:05:19 270 --a------ C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job 2007-12-15 18:24:20 424 --a------ C:\WINDOWS\Tasks\Norton Security Scan.job 2004-12-15 13:18:54 380 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job -- Files created between 2007-11-23 and 2007-12-23 ----------------------------- 2007-12-16 22:45:48 0 d-------- C:\Program Files\Trend Micro 2007-12-16 21:02:35 552 --a------ C:\WINDOWS\System32\d3d8caps.dat 2007-12-16 20:38:03 0 d-------- C:\WINDOWS\System32\ActiveScan 2007-12-15 22:41:52 0 d-------- C:\Documents and Settings\All Users\Application Data\ESET 2007-12-15 21:42:11 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2007-12-15 20:41:30 0 d--h----- C:\WINDOWS\PIF 2007-12-15 20:11:35 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2007-12-15 19:04:32 0 --a------ C:\Documents and Settings\Administrator\regsvr32 2007-12-15 18:28:23 0 d-------- C:\Program Files\Picasa2 2007-12-15 18:24:17 0 d-------- C:\Program Files\Norton Security Scan 2007-12-15 18:20:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Google Updater 2007-12-15 17:51:53 0 d-------- C:\Program Files\Microsoft Windows OneCare Live 2007-12-15 17:46:49 0 d-------- C:\VundoFix Backups 2007-12-15 17:21:04 223232 --a------ C:\WINDOWS\pmspl.dll <Not Verified; Kodack; > 2007-12-08 20:13:54 0 d-------- C:\Program Files\Windows Live Toolbar -- Find3M Report --------------------------------------------------------------- 2007-12-20 13:53:46 0 d-------- C:\Program Files\Google 2007-12-16 21:55:52 0 d-------- C:\Program Files\Common Files\Symantec Shared 2007-12-16 21:18:09 0 d-------- C:\Program Files\OperaRegTerm 2007-12-15 21:10:39 0 d-------- C:\Program Files\Common Files 2007-12-15 18:02:02 0 d--h----- C:\Documents and Settings\Administrator\Application Data\Move Networks 2007-11-22 23:25:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\IBM 2007-11-06 21:53:38 0 d-------- C:\Program Files\AIM6 2007-11-06 21:53:27 0 d-------- C:\Program Files\Viewpoint -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{17A1DBB5-DAD8-4E78-BF7E-9BE4B965408B}] 12/15/2007 05:21 PM 223232 --a------ C:\WINDOWS\pmspl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BluetoothAuthenticationAgent"="irprops.cpl" [11/22/2002 04:45 PM C:\WINDOWS\system32\irprops.cpl] "IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [06/06/2004 10:45 AM] "HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [06/06/2004 10:41 AM] "tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [10/16/2002 03:59 AM] "UC_Start"="C:\IBMTools\Updater\ucstartup.exe" [03/17/2003 05:27 PM] "ibmmessages"="C:\Program Files\IBM\Messages By IBM\ibmmessages.exe" [09/30/2003 11:05 AM] "PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [03/11/2003 04:24 PM] "McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [12/07/2005 02:55 AM] "ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [09/22/2004 07:00 PM] "Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [10/07/2003 08:48 AM] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [09/01/2006 03:57 PM] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [11/09/2006 03:07 PM] "egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [11/14/2007 03:05 PM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ibmmessages"="C:\Program Files\IBM\Messages By IBM\ibmmessages.exe" [09/30/2003 11:05 AM] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/28/2007 03:44 AM] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [08/20/2002 05:08 PM] "Aim6"="" [] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [12/15/2007 6:20:50 PM] -- End of Deckard's System Scanner: finished at 2007-12-23 20:29:26 ------------ |
|
|
Dec 23 2007, 07:31 PM
Post
#6
|
|
|
Member ![]() ![]() Posts: 11 OS: XP |
Here is the file "extra.txt":
Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 1.0 Architecture: X86; Language: English CPU 0: Intel® Pentium® 4 CPU 3.00GHz CPU 1: Intel® Pentium® 4 CPU 3.00GHz Percentage of Memory in Use: 56% Physical Memory (total/avail): 502.98 MiB / 219.37 MiB Pagefile Memory (total/avail): 1227.71 MiB / 976.13 MiB Virtual Memory (total/avail): 2047.88 MiB / 1937.68 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 37.27 GiB total, 29.88 GiB free. D: is CDROM (No Media) O: is Network (NTFS) P: is Network (NTFS) R: is Network (NTFS) Z: is Network (NTFS) \\.\PHYSICALDRIVE0 - HDS728040PLAT20 - 37.27 GiB - 1 partition \PARTITION0 (bootable) - Installable File System - 37.27 GiB - C: -- Security Center ------------------------------------------------------------- AUOptions is disabled. -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Administrator\Application Data CLASSPATH=.;C:\Program Files\JavaSoft\JRE\1.3.1_11\lib\ext\QTJava.zip CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=HXPHLBUDTXXX002 ComSpec=C:\WINDOWS\system32\cmd.exe HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Administrator LOGONSERVER=\\HXPHLBUDTXXX002 NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\QuickTime\QTSystem\ PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 1, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0401 ProgramFiles=C:\Program Files PROMPT=$P$G QTJAVA=C:\Program Files\JavaSoft\JRE\1.3.1_11\lib\ext\QTJava.zip SAFEBOOT_OPTION=NETWORK SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp TMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp USERDOMAIN=HXPHLBUDTXXX002 USERNAME=Administrator USERPROFILE=C:\Documents and Settings\Administrator windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Administrator (admin) -- Add/Remove Programs --------------------------------------------------------- --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\SETUP.EXE" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\SETUP.EXE" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\SETUP.EXE" --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Abacast Client --> C:\PROGRA~1\Abacast\UNWISE.EXE C:\PROGRA~1\Abacast\client.LOG Access IBM --> MsiExec.exe /X{B5599ECB-DA72-43EE-8A30-2C80396FF8BB} Access IBM Cleanup Utility --> MsiExec.exe /I{CF44C7A5-5705-41E4-BE84-A9A42977AB05} Access IBM Message Center --> MsiExec.exe /X{710C0BB2-FE39-484E-BB23-C9B96835A14A} Access IBM Tools --> C:\Program Files\IBM\Access IBM\IBMUINST.EXE Adobe Acrobat 4.0, 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll" Adobe Flash Player 9 ActiveX --> C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log AIM 6 --> C:\Program Files\AIM6\uninst.exe AOL Instant Messenger --> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM= Boomer Radio Tuner --> C:\PROGRA~1\BOOMER~1\UNWISE.EXE C:\PROGRA~1\BOOMER~1\INSTALL.LOG CentraOne --> C:\PROGRA~1\CENTRA~1\bin\launcher.exe uninstall DirectX 9 Hotfix - KB839643 --> C:\WINDOWS\$NtUninstallKB839643-DirectX9$\spuninst\spuninst.exe DivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN ESET NOD32 Antivirus --> MsiExec.exe /I{BB703122-AF65-4AD9-BCA0-273E165DABEE} Google Updater --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall IBM Access Support --> wscript "C:\Program Files\Support.com\bin\uninstall.vbs" -uninstall -release1 IBM Access Support - Local Content Pack --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1E34AB5C-B893-4EE9-82F3-F195978D009D}\Setup.exe" -l0x9 IBM Printer Software Uninstall --> C:\Program Files\IBM\Install\Uninstall.exe IBM Update Connector --> MsiExec.exe /X{31C2FBAC-67CF-4093-8F36-15A146613747} Intel® Extreme Graphics 2 Driver --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572 Intel® PRO Network Adapters and Drivers --> Prounstl.exe Intel® PROSet --> MsiExec.exe /I{A790BEB1-BCCF-4EC6-807B-5708B36E8A79} J2SE Runtime Environment 5.0 Update 10 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100} Java 2 Runtime Environment Standard Edition v1.3.1_11 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{68249B71-B714-11D7-88E8-0050DA21757E}\Setup.exe" -uninst LiveUpdate 2.5 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U McAfee VirusScan Enterprise --> MsiExec.exe /I{5DF3D1BB-894E-4DCD-8275-159AC9829B43} Micros Fidelio Opera Print Utility --> C:\PROGRA~1\MI9EC0~1\Opera\PRINTC~1\UNWISE.EXE C:\PROGRA~1\MI9EC0~1\Opera\PRINTC~1\INSTALL.LOG Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9} MSN Music Assistant --> rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msninst.inf,Uninstall Norton Security Scan --> MsiExec.exe /I{3A4FFB84-D070-4DA5-AB7B-D41D87FD8D19} Opera Register Terminal --> C:\PROGRA~1\OPERAR~1\UNWISE.EXE C:\PROGRA~1\OPERAR~1\INSTALL.LOG Oracle JInitiator 1.3.1.25 --> \UNWISE.EXE C:\DOCUME~1\ADMINI~1\Desktop\ Oracle JInitiator 1.3.1.25 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CAFECAFE-0013-0001-0125-ABCDEFABCDEF}\Setup.exe" -l0x9 -uninst Oracle JInitiator 1.3.1.9 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Oracle\JInitiator 1.3.1.9\Uninst.isu" Outlook Express Q823353 --> C:\WINDOWS\oeuninst.exe C:\WINDOWS\INF\Q823353.inf Panda ActiveScan --> C:\WINDOWS\System32\ASUninst.exe Panda ActiveScan PC-Doctor for Windows --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\SETUP.EXE" Picasa 2 --> "C:\Program Files\Picasa2\Uninstall.exe" QuickTime --> MsiExec.exe /I{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8} SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\SETUP.EXE" Support.com Software --> wscript "C:\Program Files\Support.com\bin\admins.vbs" ThinkCentre Wallpaper --> MsiExec.exe /I{80380166-A872-4B78-B98A-33447A032BDF} Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u Windows Live Toolbar --> "C:\Program Files\Windows Live Toolbar\UnInstall.exe" {D5A145FC-D00C-4F1A-9119-EB4D9D659750} Windows Live Toolbar --> MsiExec.exe /X{D5A145FC-D00C-4F1A-9119-EB4D9D659750} WinRAR archiver --> C:\WINDOWS\WinSxS\Manifests\uninstall.exe Xvid 1.1.3 final uninstall --> "C:\Program Files\Xvid\unins000.exe" -- Application Event Log ------------------------------------------------------- Event Record #/Type8448 / Error Event Submitted/Written: 12/20/2007 02:02:33 PM Event ID/Source: 8193 / VSS Event Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206. Event Record #/Type8447 / Error Event Submitted/Written: 12/20/2007 02:02:33 PM Event ID/Source: 4609 / EventSystem Event Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007043C from line 44 of d:\nt_qxp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error. Event Record #/Type8442 / Warning Event Submitted/Written: 12/20/2007 01:56:43 PM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. Event Record #/Type8441 / Warning Event Submitted/Written: 12/20/2007 01:54:35 PM Event ID/Source: 1015 / MsiInstaller Event Description: Failed to connect to server. Error: 0x8007043C Event Record #/Type8440 / Warning Event Submitted/Written: 12/20/2007 01:54:21 PM Event ID/Source: 1015 / MsiInstaller Event Description: Failed to connect to server. Error: 0x8007043C -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type387 / Error Event Submitted/Written: 12/20/2007 02:03:53 PM Event ID/Source: 7026 / Service Control Manager Event Description: The following boot-start or system-start driver(s) failed to load: easdrv eeCtrl Fips Processor Event Record #/Type386 / Error Event Submitted/Written: 12/20/2007 02:03:08 PM Event ID/Source: 10005 / DCOM Event Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} Event Record #/Type385 / Warning Event Submitted/Written: 12/20/2007 02:02:35 PM Event ID/Source: 1007 / Dhcp Event Description: Your computer has automatically configured the IP address for the Network Card with network address 0011257A1880. The IP address being used is 169.254.109.242. Event Record #/Type384 / Error Event Submitted/Written: 12/20/2007 02:02:33 PM Event ID/Source: 10005 / DCOM Event Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} Event Record #/Type383 / Warning Event Submitted/Written: 12/20/2007 02:02:30 PM Event ID/Source: 1003 / Dhcp Event Description: Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 0011257A1880. The following error occurred: %%121. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. -- End of Deckard's System Scanner: finished at 2007-12-23 20:29:26 ------------ |
|
|
Dec 23 2007, 10:02 PM
Post
#7
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Please restart HJT put a check next to the following, close all open windows and click “Fix Checked”
O2 - BHO: IE plugin - {17A1DBB5-DAD8-4E78-BF7E-9BE4B965408B} - C:\WINDOWS\pmspl.dll Next Reboot into SAFE MODE Search for and delete the File highlighted in BOLD C:\WINDOWS\pmspl.dll Restart your computer, Next Please do an online scan with Kaspersky WebScanner Click on Kaspersky Online Scanner You will be promted to install an ActiveX component from Kaspersky, Click Yes.
Scan Mail Bases
Post back a fresh DSS log please |
|
|
Dec 24 2007, 05:51 PM
Post
#8
|
|
|
Member ![]() ![]() Posts: 11 OS: XP |
Here is the Kaspersky WebScanner log:
------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Monday, December 24, 2007 6:30:08 PM Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 24/12/2007 Kaspersky Anti-Virus database records: 493131 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ O:\ P:\ R:\ Z:\ Scan Statistics: Total number of scanned objects: 71786 Number of viruses found: 4 Number of infected objects: 26 Number of suspicious objects: 0 Duration of the scan process: 02:40:54 Infected Object Name / Virus Name / Last Action C:\Deckard\System Scanner\backup\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~E4B_tmp.exe Infected: Trojan-Downloader.Win32.Delf.dkk skipped C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Administrator\jinitiator13125.trace Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012007122420071225\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator\ntuser.dat Object is locked skipped C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\IBMTOOLS\APPS\RRPC\RRPC\superinstall.EXE/IGWSE2SAS2.1WM2.1.EXE/HOTVIEW.EXE Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped C:\IBMTOOLS\APPS\RRPC\RRPC\superinstall.EXE/IGWSE2SAS2.1WM2.1.EXE/VNCHOOKS.DLL Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped C:\IBMTOOLS\APPS\RRPC\RRPC\superinstall.EXE/IGWSE2SAS2.1WM2.1.EXE Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped C:\IBMTOOLS\APPS\RRPC\RRPC\superinstall.EXE ZIP: infected - 3 skipped C:\Program Files\Trend Micro\HijackThis\backups\backup-20071224-141431-889.dll Infected: Trojan-Downloader.Win32.IEDefender.c skipped C:\System Volume Information\_restore{29FD9B63-4F58-4DB0-B2C4-8709D5244F27}\RP988\A0104055.dll Infected: Trojan-Downloader.Win32.IEDefender.c skipped C:\System Volume Information\_restore{29FD9B63-4F58-4DB0-B2C4-8709D5244F27}\RP988\change.log Object is locked skipped C:\WINDOWS\CSC\00000001 Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped O:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped O:\Documents and Settings\Administrator\Desktop\IHG_MEG_E_PATCH_V40303E51.zip/IHG_MEG_E_PATCH_V40303E51.exe/WISE0016.BIN/WISE0293.BIN/WISE0024.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\IHG_MEG_E_PATCH_V40303E51.zip/IHG_MEG_E_PATCH_V40303E51.exe/WISE0016.BIN/WISE0293.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\IHG_MEG_E_PATCH_V40303E51.zip/IHG_MEG_E_PATCH_V40303E51.exe/WISE0016.BIN/WISE0303.BIN/WISE0022.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\IHG_MEG_E_PATCH_V40303E51.zip/IHG_MEG_E_PATCH_V40303E51.exe/WISE0016.BIN/WISE0303.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\IHG_MEG_E_PATCH_V40303E51.zip/IHG_MEG_E_PATCH_V40303E51.exe/WISE0016.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\IHG_MEG_E_PATCH_V40303E51.zip/IHG_MEG_E_PATCH_V40303E51.exe Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\IHG_MEG_E_PATCH_V40303E51.zip ZIP: infected - 6 skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe/WISE0016.BIN/WISE0022.BIN/WISE0024.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe/WISE0016.BIN/WISE0022.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe/WISE0016.BIN/WISE0032.BIN/WISE0022.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe/WISE0016.BIN/WISE0032.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe/WISE0016.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe/WISE0078.BIN/WISE0012.BIN/WISE0023.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe/WISE0078.BIN/WISE0012.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe/WISE0078.BIN/WISE0015.BIN/WISE0024.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe/WISE0078.BIN/WISE0015.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe/WISE0078.BIN Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip/OH_V40_P0303_E00066.exe Infected: not-a-virus:NetTool.Win32.PsKill.a skipped O:\Documents and Settings\Administrator\Desktop\OH_V40_P0303_E00066.zip ZIP: infected - 11 skipped O:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\ConsoleMain.exe.721603a.ini.inuse Object is locked skipped O:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped O:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped O:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped O:\Documents and Settings\Administrator\Local Settings\Temp\NAILogs\UpdaterUI_HXPHLBUSVXXXAP1.log Object is locked skipped O:\Documents and Settings\Administrator\Local Settings\Temp\~DF8F86.tmp Object is locked skipped O:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped O:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped O:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped O:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\AccessProtectionLog.txt Object is locked skipped O:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\BufferOverflowProtectionLog.txt Object is locked skipped O:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\OnAccessScanLog.txt Object is locked skipped O:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_HXPHLBUSVXXXAP1.log Object is locked skipped O:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_HXPHLBUSVXXXAP1.log Object is locked skipped O:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped O:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped O:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped O:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped O:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped O:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped O:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped O:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped O:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped O:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped O:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped O:\McAfee\Rogue System Sensor\key.pem Object is locked skipped O:\McAfee\Rogue System Sensor\root.pem Object is locked skipped O:\McAfee\Rogue System Sensor\RSSensor_out.log Object is locked skipped O:\McAfee\Rogue System Sensor\sensor.pem Object is locked skipped O:\Micros\sdc\pbd.LCK Object is locked skipped O:\Micros\sdc\pbdirect.dbg Object is locked skipped O:\Micros\sdc\pbgate\pbtcpste.01300 Object is locked skipped O:\oracle\oradata\opera\REDO02B.RDO Object is locked skipped O:\oracle\oradata\opera\REDO03B.RDO Object is locked skipped O:\oracle\oradata\opera\REDO04B.RDO Object is locked skipped O:\oracle\oradata\opera\REDO05B.RDO Object is locked skipped O:\oracle\oradata\opera\REDO06B.RDO Object is locked skipped O:\oracle\oradata\opera\REDO07B.RDO Object is locked skipped O:\oracle\oradata\opera\REDO08B.RDO Object is locked skipped O:\oracle\oradata\opera\REDO09B.RDO Object is locked skipped O:\oracle\oradata\opera\REDO10B.RDO Object is locked skipped O:\Program Files\APC\PowerChute Business Edition\agent\data.dat Object is locked skipped O:\Program Files\APC\PowerChute Business Edition\agent\EventLog Object is locked skipped O:\Program Files\APC\PowerChute Business Edition\server\data.dat Object is locked skipped O:\Program Files\Micros-Fidelio\OXChange\OXA\Logs\HOLIDEX.20071224.log.xml Object is locked skipped O:\WINDOWS\Debug\Netlogon.log Object is locked skipped O:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped O:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped O:\WINDOWS\system32\config\default Object is locked skipped O:\WINDOWS\system32\config\default.LOG Object is locked skipped O:\WINDOWS\system32\config\DnsEvent.Evt Object is locked skipped O:\WINDOWS\system32\config\SAM Object is locked skipped O:\WINDOWS\system32\config\SAM.LOG Object is locked skipped O:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped O:\WINDOWS\system32\config\SECURITY Object is locked skipped O:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped O:\WINDOWS\system32\config\software Object is locked skipped O:\WINDOWS\system32\config\software.LOG Object is locked skipped O:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped O:\WINDOWS\system32\config\system Object is locked skipped O:\WINDOWS\system32\config\system.LOG Object is locked skipped O:\WINDOWS\system32\dhcp\dhcp.mdb Object is locked skipped O:\WINDOWS\system32\dhcp\DhcpSrvLog-Mon.log Object is locked skipped O:\WINDOWS\system32\dhcp\j50.log Object is locked skipped O:\WINDOWS\system32\dhcp\j50tmp.log Object is locked skipped O:\WINDOWS\system32\dhcp\tmp.edb Object is locked skipped O:\WINDOWS\system32\dns\dns.log Object is locked skipped O:\WINDOWS\system32\h323log.txt Object is locked skipped O:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped O:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped O:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped O:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped O:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped O:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped O:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped O:\WINDOWS\Tasks\SchedLgU.Txt Object is locked skipped O:\WINDOWS\Temp\hsperfdata_SYSTEM\2712 Object is locked skipped Scan process completed. ******************************************* Here is the DSS log ran after the WebScanner: Deckard's System Scanner v20071014.68 Run by Administrator on 2007-12-24 18:50:18 Computer is in Safe Mode with Networking. -------------------------------------------------------------------------------- Total Physical Memory: 503 MiB (512 MiB recommended). -- HijackThis (run as Administrator.exe) --------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:50:19 PM, on 12/24/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Safe mode with network support Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\notepad.exe C:\Documents and Settings\Administrator\My Documents\ALONZo\dss.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\ADMINI~1.EXE O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {CAFECAFE-0013-0001-0025-ABCDEFABCDEF} (JInitiator 1.3.1.25) - http://hxphlbusvxxxap1/webhtml/opera_jinit_1012_25.exe O16 - DPF: {DAAC8ECF-DB09-4821-8126-E2C9499A20BA} (RegTerminalSrv Object) - http://hxphlbusvxxxap1/installregterm.exe O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup161.cab O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cnatla4svradx01.local,inns.hiw.com,hiw.com O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cnatla4svradx01.local,inns.hiw.com,hiw.com O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = cnatla4svradx01.local,inns.hiw.com,hiw.com O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cnatla4svradx01.local,inns.hiw.com,hiw.com O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O24 - Desktop Component 0: (no name) - http://asp7.centra.com/SiteRoots/main/Agen...ages/Banner.gif -- End of file - 6638 bytes -- Files created between 2007-11-24 and 2007-12-24 ----------------------------- 2007-12-24 14:50:56 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2007-12-24 14:50:55 0 d-------- C:\WINDOWS\System32\Kaspersky Lab 2007-12-24 14:50:54 0 d-------- C:\WINDOWS\LastGood 2007-12-16 22:45:48 0 d-------- C:\Program Files\Trend Micro 2007-12-16 21:02:35 552 --a------ C:\WINDOWS\System32\d3d8caps.dat 2007-12-16 20:38:03 0 d-------- C:\WINDOWS\System32\ActiveScan 2007-12-15 22:41:52 0 d-------- C:\Documents and Settings\All Users\Application Data\ESET 2007-12-15 21:42:11 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2007-12-15 20:41:30 0 d--h----- C:\WINDOWS\PIF 2007-12-15 20:11:35 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2007-12-15 19:04:32 0 --a------ C:\Documents and Settings\Administrator\regsvr32 2007-12-15 18:28:23 0 d-------- C:\Program Files\Picasa2 2007-12-15 18:24:17 0 d-------- C:\Program Files\Norton Security Scan 2007-12-15 18:20:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Google Updater 2007-12-15 17:51:53 0 d-------- C:\Program Files\Microsoft Windows OneCare Live 2007-12-15 17:46:49 0 d-------- C:\VundoFix Backups 2007-12-08 20:13:54 0 d-------- C:\Program Files\Windows Live Toolbar -- Find3M Report --------------------------------------------------------------- 2007-12-20 13:53:46 0 d-------- C:\Program Files\Google 2007-12-16 21:55:52 0 d-------- C:\Program Files\Common Files\Symantec Shared 2007-12-16 21:18:09 0 d-------- C:\Program Files\OperaRegTerm 2007-12-15 21:10:39 0 d-------- C:\Program Files\Common Files 2007-12-15 18:02:02 0 d--h----- C:\Documents and Settings\Administrator\Application Data\Move Networks 2007-11-22 23:25:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\IBM 2007-11-06 21:53:38 0 d-------- C:\Program Files\AIM6 2007-11-06 21:53:27 0 d-------- C:\Program Files\Viewpoint -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BluetoothAuthenticationAgent"="irprops.cpl" [11/22/2002 04:45 PM C:\WINDOWS\system32\irprops.cpl] "IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [06/06/2004 10:45 AM] "HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [06/06/2004 10:41 AM] "tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [10/16/2002 03:59 AM] "UC_Start"="C:\IBMTools\Updater\ucstartup.exe" [03/17/2003 05:27 PM] "ibmmessages"="C:\Program Files\IBM\Messages By IBM\ibmmessages.exe" [09/30/2003 11:05 AM] "PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [03/11/2003 04:24 PM] "McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [12/07/2005 02:55 AM] "ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [09/22/2004 07:00 PM] "Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [10/07/2003 08:48 AM] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [09/01/2006 03:57 PM] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [11/09/2006 03:07 PM] "egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [11/14/2007 03:05 PM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ibmmessages"="C:\Program Files\IBM\Messages By IBM\ibmmessages.exe" [09/30/2003 11:05 AM] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/28/2007 03:44 AM] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [08/20/2002 05:08 PM] "Aim6"="" [] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [12/15/2007 6:20:50 PM] -- End of Deckard's System Scanner: finished at 2007-12-24 18:50:39 ------------ |
|
|
Dec 25 2007, 10:58 AM
Post
#9
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Kaspersky is finding a few false possitives from the IBM program
any issues still everything is looking clean now |
|
|
Dec 25 2007, 11:32 AM
Post
#10
|
|
|
Member ![]() ![]() Posts: 11 OS: XP |
Just tried starting the pc on normal mode. It brings me to the background screen, no desktop icons or taskbar. It still only runs in safe mode, which does the job but is unacceptable to the other managers.
|
|
|
Dec 25 2007, 11:59 AM
Post
#11
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Just tried starting the pc on normal mode. It brings me to the background screen, no desktop icons or taskbar. It still only runs in safe mode, which does the job but is unacceptable to the other managers. what do you mean by other managers ? Background screen of what ? |
|
|
Dec 25 2007, 12:12 PM
Post
#12
|
|
|
Member ![]() ![]() Posts: 11 OS: XP |
The other managers at my job, they want it in normal mode.
The background screen after inputting my logon/pwd to get into windows. It shows that, the cursor, and nothing else. I kept it on to see if it was just taking EXTRA long; its been an hour and its still just showing the background and nothing else. |
|
|
Dec 25 2007, 12:32 PM
Post
#13
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
any other users on the machine ?
Do you have admin rights ? |
|
|
Dec 25 2007, 12:55 PM
Post
#14
|
|
|
Member ![]() ![]() Posts: 11 OS: XP |
its only the admin login that is used so i'd be able to switch pretty much any settings
|
|
|
Dec 25 2007, 06:53 PM
Post
#15
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Go Here and download Taskbarrepair tool
select the taskbar issue your having and let the tool repair it Let me know how that works out then we can work on getting the background squared away |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
2 / 315 | 6th January 2008 - 11:13 AM savedbygrace started - last by savedbygrace |
|||||
![]() |
16 / 1,377 | 13th February 2008 - 05:56 PM milkdad started - last by Wizard |
|||||
![]() |
16 / 1,280 | 12th September 2008 - 02:40 AM Kinnaj started - last by sarahw |
|||||
![]() |
4 / 552 | 17th April 2009 - 05:42 AM mandy95 started - last by Rorschach112 |
|||||
|
Time is now: 21st November 2009 - 05:06 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising