<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>HJT LOG - PC sends out massive random emails, locks up! in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20381034</link>
<description></description>
<language>en</language>
<pubDate>Wed, 09 Jul 2008 02:02:53 EDT</pubDate>
<lastBuildDate>Wed, 09 Jul 2008 02:02:53 EDT</lastBuildDate>

<item>
<title>Re: HJT LOG - PC sends out massive random emails, locks up!</title>
<link>http://www.dslreports.com/forum/remark,20403796</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Open <b>Acrobat</b> if you have the Full Version installed  Click <b>Help</b> and run the <b>Upgrade</b> applet found there.  If no update is offered:  Use the Preferences, Internet submenu of Acrobat and uncheck to integrate with your Browser.  Close Acrobat.<br>Whether you had the Full Version of Acrobat or not, download and install <b>Adobe Reader 8.1.1</b> and use this as the integrated PDF Reader insider your browser:  &raquo;<A HREF="http://www.adobe.com/products/acrobat/readstep2.html" >www.adobe.com/products/acrobat/r&middot;&middot;&middot;ep2.html</A><br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226;  Right click "My Computer", Properties, and then click the System Restore tab.  <b>Checkmark</b> the box at the top to stop System Restore on all drives.  Click the "<b>Apply</b>" button.  Agree to the deletion of old Restore Points.  Then <b><u>uncheck</u></b> the box at the top and again click the "<b>Apply</b>" button.  Finally, click the "<b>OK</b>" button.  This will create a new Restore Point reflecting your clean system state.<br><br>&#8226; Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br>(If we have renamed this file, please use the current name for the program in this instruction.)<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to an On-Line scanner we may have used.  <br>If you find any files or folders created during this cleanup operation remaining, please feel free to delete them.<br><br>&#8226; Configure your Antivirus software to check for updates daily, at a time in which you are sure the computer will be on.<br><br>&#8226; If I asked you to <b>Disable</b> something like TeaTimer or another malware blocker, please go ahead an re-enable them if you wish.<br><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>Best wishes.<br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20403796</guid>
<pubDate>Tue, 29 Apr 2008 06:46:30 EDT</pubDate>
</item>

<item>
<title>Re: HJT LOG - PC sends out massive random emails, locks up!</title>
<link>http://www.dslreports.com/forum/remark,20402047</link>
<description><![CDATA[<A HREF="/useremail/u/1546970"><b>fjr1966</b></A> : Spyware Doctor has been disabled whenever I am executing the instructions you have been providing me to this point. Items 1, 2 & 3 have been completed. Log from aproposfix.exe provided below. Thank you. :)<br><br>************************<br><br>Log of AproposFix v1.1 <br> <br>************ <br> <br>Running from directory:  <br>C:\Documents and Settings\FRANK\Desktop\aproposfix<br> <br>************ <br> <br> <br> <br>Registry entries found: <br> <br> <br>************ <br> <br>No service found! <br> <br>Removing hidden folder: <br>No folder found! <br> <br>Deleting files: <br> <br> <br>Backing up files: <br>Done! <br> <br>Removing registry entries: <br> <br>REGEDIT4 <br> <br> <br>Done! <br> <br>Finished! ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20402047</guid>
<pubDate>Mon, 28 Apr 2008 19:58:46 EDT</pubDate>
</item>

<item>
<title>Re: HJT LOG - PC sends out massive random emails, locks up!</title>
<link>http://www.dslreports.com/forum/remark,20390053</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : DISABLE Spyware Doctor --<br>It is a good program, but ... it may hinder the removal of some malware entries. You can re-enable it after you're clean. <br>From within Spyware Doctor, click the "<b>OnGuard</b>" button on the left side. <br><b>Uncheck</b> "Activate OnGuard". <br><br>1. Using your mouse, left click once where it says: <b>Copy to clipboard</b> to capture the entire contents of the Code box below, including blank lines:<br><textarea name="code" class="text" cols=50 rows=10>REGEDIT4&#012; &#012;&#91;HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\7il&#93; &#012;&#91;HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ttool&#93; &#012; &#012;</textarea><!--end code block--><br>Open a new <b>Notepad</b> document. (Do not use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled. <br>Right-click <b>| <i>Paste</i></b> the Code box contents from above into Notepad.  Click File, <b>Save as...</b>,  and enter (including quotation marks) as the filename: <b>"RegFix.REG"</b>.   Exit Notepad.<br><br>Double click your new file and agree to the registry merge when asked.  You can then delete this new file.<br><br>2. Using your mouse, Highlight and then Right-click <b>| <i>Copy</i></b> the entire contents of the Quote box below, including blank lines:<br> <blockquote><small>quote:</small><hr>@echo off<br>cd %~dp0<br><br>REM :!: malware removal script only for this user<br>REM :!: Please do not use.<br>REM :!: Unintended consequences are likely if you are not this user.<br>REM :!: Authored by Bill Castner, BroadBandReports Forum<br><br>@echo off<br>cd %~dp0<br><br>del /a /f /q C:\Program Files\Messenger\kygeta.html<br>del /a /f /q C:\Documents and Settings\FRANK\My Documents\Computer Tools\SYSTEM TOOLS\keyfinder.exe<br>del /a /f /q D:\Computer Tools\SYSTEM TOOLS\keyfinder.exe<br>del /a /f /q G:\SYSTEM TOOLS\keyfinder.exe<br><br>del %0<br>exit<br><br><hr></blockquote><br><br>Open a new <b>Notepad</b> document. (Do not use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled. <br>Right-click <b>| <i>Paste</i></b> the Quote box contents from above into Notepad.  Click File, <b>Save as...</b>,  and enter (including quotation marks) as the filename: <b>"Cleanit.cmd"</b>.   Exit Notepad.<br><br>Double click your new file to run the script.  It will briefly open a black box and then exit..<br><br>3. Please download <b>AproposFix</b> from here:<br><textarea name="code" class="text" cols=50 rows=10>http://swandog46.geekstogo.com/aproposfix.exe&#012;</textarea><!--end code block-->Save it to your desktop but do not run it yet.<br>Now reboot into <b>Safe Mode</b>.<br>This can be done tapping the F8 key as soon as you start your computer <br>You will be brought to a menu where you can choose to boot into safe mode. <br>Make sure you choose the option without networking support.<br><br>Once in Safe Mode, please double-click aproposfix.exe and unzip it to the desktop. <br>Open the aproposfix folder on your desktop and run <b>RunThis.bat</b>. Follow the prompts.<br>When the tool is finished, please  post the entire contents of the <b>log.txt</b> file in the aproposfix folder.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20390053</guid>
<pubDate>Sat, 26 Apr 2008 05:46:11 EDT</pubDate>
</item>

<item>
<title>Re: HJT LOG - PC sends out massive random emails, locks up!</title>
<link>http://www.dslreports.com/forum/remark,20388090</link>
<description><![CDATA[<A HREF="/useremail/u/1546970"><b>fjr1966</b></A> : Results of Combofix and the Kaspersky scan are below. I will attempt the SP3 update as soon as possible and time allowed. If I have any problems with the update, I will be sure to start a new topic thread for help. Norton AV was recently reinstalled. It would not update and showed &#147;error&#148; in the email scanning section all the time. Norton AV online help desk had me do a reinstall. However, I now see that although the Norton AV live update, even after the reinstall, said it was current, actually, when paging through the definitions, was woefully out-of-date. After we performed all of the steps prescribed on this forum, I ran a manual install, from Norton AV&#146;s website and the definitions are, in fact, now completely up-to-date. I ran Norton AV again and it found a number of viruses previously not detected. (I run Norton AV every week for a full scan and it remains resident so as to detect any real-time viral events and fix and/or quarantine them.) I am sure this was due to the fact that my best educated guess is that the Norton AV definitions were more than 6 months outdated. I am also fairly confident, with your help, we have eradicated and cured most of the ailments my PC was afflicted with, and the original problem I posted about has ceased to resurface. I await any further instructions after you view the logs from the latest scans. Thank you.<br><br><b>COMBOFIX LOG</b><br>*******************************<br><br>ComboFix 08-04-22.5 - FRANK 2008-04-25 16:10:18.2 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.1.1252.1.1033.18.285 [GMT -4:00]<br>Running from: C:\Documents and Settings\FRANK\Desktop\ComboFix.exe<br>Command switches used :: C:\Documents and Settings\FRANK\Desktop\CFscript.txt<br> * Created a new restore point<br><br>FILE ::<br>C:\WINDOWS\system32\asferrorq.dll<br>C:\windows\SYSTEM32\BLACKBOXL.DLL<br>C:\windows\SYSTEM32\cfgmgr32f.dll<br>C:\windows\SYSTEM32\CFGMGR32F.DLL<br>C:\windows\SYSTEM32\COMPATUIP.DLL<br>C:\windows\SYSTEM32\KBDPOV.DLL<br>C:\WINDOWS\system32\syfowhie.tmp<br>C:\WINDOWS\wininit.ini<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\WINDOWS\system32\asferrorq.dll<br>C:\windows\SYSTEM32\cfgmgr32f.dll<br>C:\WINDOWS\system32\syfowhie.tmp<br>C:\WINDOWS\wininit.ini<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2008-03-25 to 2008-04-25  )))))))))))))))))))))))))))))))<br>.<br><br>2008-04-25 00:25 . 2008-04-25 00:25&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-04-25 00:25 . 2008-04-25 00:25&#9;&#9;d--------&#9;C:\Documents and Settings\FRANK\Application Data\Malwarebytes<br>2008-04-25 00:25 . 2008-04-25 00:25&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-04-24 16:06 . 2008-04-25 07:13&#9;&#9;d--------&#9;C:\Program Files\Spyware Doctor<br>2008-04-24 16:06 . 2008-04-24 16:06&#9;&#9;d--------&#9;C:\Documents and Settings\FRANK\Application Data\PC Tools<br>2008-04-24 16:06 . 2007-12-10 13:53&#9;81,288&#9;--a------&#9;C:\WINDOWS\system32\drivers\iksyssec.sys<br>2008-04-24 16:06 . 2007-12-10 13:53&#9;66,952&#9;--a------&#9;C:\WINDOWS\system32\drivers\iksysflt.sys<br>2008-04-24 16:06 . 2008-02-01 11:55&#9;42,376&#9;--a------&#9;C:\WINDOWS\system32\drivers\ikfilesec.sys<br>2008-04-24 16:06 . 2007-12-10 13:53&#9;29,576&#9;--a------&#9;C:\WINDOWS\system32\drivers\kcom.sys<br>2008-04-24 14:49 . 2008-04-24 15:55&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-04-24 07:28 . 2008-04-24 07:28&#9;&#9;d--------&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-04-24 06:53 . 2008-04-24 06:53&#9;&#9;d--------&#9;C:\Program Files\SymNetDrv<br>2008-04-24 06:52 . 2005-07-29 09:56&#9;124,168&#9;--a------&#9;C:\WINDOWS\system32\SymStore.dll<br>2008-04-24 06:49 . 2008-04-24 06:50&#9;&#9;d--------&#9;C:\Program Files\Norton AntiVirus<br>2008-04-24 06:49 . 2008-04-24 06:49&#9;&#9;d--------&#9;C:\Documents and Settings\FRANK\Application Data\Symantec<br>2008-04-24 06:49 . 2002-02-26 10:40&#9;120,379&#9;--a------&#9;C:\WINDOWS\system32\SYMEVNT.386<br>2008-04-24 06:49 . 2002-02-26 10:40&#9;58,224&#9;--a------&#9;C:\WINDOWS\system32\drivers\SYMEVENT.SYS<br>2008-04-24 06:49 . 2002-02-26 10:40&#9;36,864&#9;--a------&#9;C:\WINDOWS\system32\S32EVNT1.DLL<br>2008-04-24 06:12 . 2008-04-24 06:12&#9;0&#9;--a------&#9;C:\WINDOWS\nsreg.dat<br>2008-04-24 06:08 . 2008-04-24 06:53&#9;&#9;d--------&#9;C:\Program Files\Symantec<br>2008-04-24 06:08 . 2008-04-24 06:55&#9;&#9;d--------&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-04-24 06:08 . 2008-04-24 06:50&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Symantec<br>2008-04-24 05:25 . 2002-02-26 10:40&#9;4,032&#9;--a------&#9;C:\WINDOWS\system32\SYMEVNT1.DLL<br>2008-04-24 04:45 . 2008-04-25 17:03&#9;&#9;d-a------&#9;C:\Documents and Settings\All Users\Application Data\TEMP<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-04-24 11:33&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-04-24 09:11&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-04-24 08:52&#9;12,632&#9;----a-w&#9;C:\WINDOWS\system32\lsdelete.exe<br>2008-04-23 17:15&#9;---------&#9;d-----w&#9;C:\Documents and Settings\FRANK\Application Data\uTorrent<br>2008-02-11 13:39&#9;253,952&#9;----a-w&#9;C:\WINDOWS\system32\OnlineScannerDLLA.dll<br>2008-02-11 13:39&#9;237,568&#9;----a-w&#9;C:\WINDOWS\system32\OnlineScannerDLLW.dll<br>2008-02-08 17:53&#9;110,592&#9;----a-w&#9;C:\WINDOWS\system32\OnlineScannerLang.dll<br>2008-02-05 12:48&#9;77,824&#9;----a-w&#9;C:\WINDOWS\system32\OnlineScannerUninstaller.exe<br>2007-09-28 18:40&#9;57,760&#9;----a-w&#9;C:\Documents and Settings\FRANK\Application Data\GDIPFONTCACHEV1.DAT<br>.<br><br>(((((((((((((((((((((((((((((   snapshot@2008-04-25_ 0.17.47.46   )))))))))))))))))))))))))))))))))))))))))<br>.<br>- 2008-04-25 04:10:55&#9;2,048&#9;--s-a-w&#9;C:\WINDOWS\bootstat.dat<br>+ 2008-04-25 20:13:28&#9;2,048&#9;--s-a-w&#9;C:\WINDOWS\bootstat.dat<br>- 2008-04-24 07:37:19&#9;41,708&#9;----a-w&#9;C:\WINDOWS\system32\perfc009.dat<br>+ 2008-04-25 04:13:47&#9;41,708&#9;----a-w&#9;C:\WINDOWS\system32\perfc009.dat<br>- 2008-04-24 07:37:19&#9;314,710&#9;----a-w&#9;C:\WINDOWS\system32\perfh009.dat<br>+ 2008-04-25 04:13:47&#9;314,710&#9;----a-w&#9;C:\WINDOWS\system32\perfh009.dat<br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]<br>"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-20 18:08 1511453]<br>"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2006-12-25 03:11 16384]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-30 13:50 185896]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624]<br>"nwiz"="nwiz.exe" [2004-03-24 10:04 782336 C:\WINDOWS\system32\nwiz.exe]<br>"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-03-24 10:04 46080]<br>"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-03-24 10:04 3309568]<br>"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [2001-07-09 06:50 155648]<br>"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [ ]<br>"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 12:39 98304]<br>"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 05:50 19968 C:\WINDOWS\LOGI_MWX.EXE]<br>"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-11 04:08 172032]<br>"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24 49152]<br>"SoundMan"="SOUNDMAN.EXE" [2003-05-14 01:20 55296 C:\WINDOWS\SOUNDMAN.EXE]<br>"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2007-08-15 17:59 374688]<br>"NAV Agent"="C:\PROGRA~1\NORTON~1\navapw32.exe" [2002-02-27 11:27 75384]<br>"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2008-04-24 06:53 95960]<br>"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 11:55 1103240]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]<br>Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-12-25 03:11:09 169472]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br>"VIDC.JPGL"= jpgl.dll<br>"vidc.xvid"= xvid.dll<br>"VIDC.I263"= i263_32.drv<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\7il]<br>C:\WINDOWS\system32\7il.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoProp]<br>--------- 2001-07-16 07:50 36864 C:\PROGRA~1\MICROS~2\Office\bots\fp_wmp\regprop.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]<br>--------- 2006-07-11 06:06 3144800 C:\Program Files\ICQLite\ICQLite.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ttool]<br>C:\WINDOWS\9129837.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebCamRT.exe]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher]<br>--------- 2003-12-01 12:38 892928 C:\Program Files\Logitech\iTouch\iTouch.exe<br><br>R2 IOPort;IOPort;C:\WINDOWS\System32\DRIVERS\IOPORT.SYS [1998-11-27 23:57]<br>R3 QCPro;Logitech QuickCam Pro USB(PID_D001);C:\WINDOWS\System32\DRIVERS\p35u.sys [2001-09-24 12:42]<br><br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-04-24 10:50:56 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"<br>- C:\PROGRA~1\NORTON~1\NAVW32.exeG/task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca<br>.<br>**************************************************************************<br><br>catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-04-25 17:02:32<br>Windows 5.1.2600 Service Pack 1 NTFS<br><br>detected NTDLL code modification:<br>ZwClose<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br>C:\Program Files\Norton AntiVirus\Navapsvc.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\locator.exe<br>C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>C:\Program Files\Spyware Doctor\pctsSvc.exe<br>C:\WINDOWS\system32\wdfmgr.exe<br>C:\Program Files\Canon\CAL\CALMAIN.exe<br>C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-04-25 17:14:08 - machine was rebooted<br>ComboFix-quarantined-files.txt  2008-04-25 21:14:02<br>ComboFix2.txt  2008-04-25 04:18:52<br><br>Pre-Run: 66,407,792,640 bytes free<br>Post-Run: 66,450,685,952 bytes free<br><br>155<br><br><b>KASPERSKY REPORT</b><br>*************************<br><br>-------------------------------------------------------------------------------<br> KASPERSKY ONLINE SCANNER REPORT<br> Friday, April 25, 2008 6:55:12 PM<br> Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)<br> Kaspersky Online Scanner version: 5.0.98.0<br> Kaspersky Anti-Virus database last update: 25/04/2008<br> Kaspersky Anti-Virus database records: 725571<br>-------------------------------------------------------------------------------<br><br>Scan Settings:<br>&#9;Scan using the following antivirus database: extended<br>&#9;Scan Archives: true<br>&#9;Scan Mail Bases: true<br><br>Scan Target - My Computer:<br>&#9;A:\<br>&#9;C:\<br>&#9;D:\<br>&#9;E:\<br>&#9;F:\<br>&#9;G:\<br>&#9;H:\<br><br>Scan Statistics:<br>&#9;Total number of scanned objects: 88522<br>&#9;Number of viruses found: 5<br>&#9;Number of infected objects: 34<br>&#9;Number of suspicious objects: 0<br>&#9;Duration of the scan process: 01:19:48<br><br>Infected Object Name / Virus Name / Last Action<br>C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-04-25_Log.ALUSchedulerSvc.LiveUpdate&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\FRANK\Application Data\Sun\Java\Deployment\cache\6.0\41\14123b69-28de183b&#9;Infected: Trojan-Downloader.Java.OpenStream.y&#9;skipped<br>C:\Documents and Settings\FRANK\Cookies\index.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\FRANK\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\FRANK\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\FRANK\Local Settings\History\History.IE5\index.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\FRANK\Local Settings\History\History.IE5\MSHist012008042520080426\index.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\FRANK\Local Settings\Temporary Internet Files\Content.IE5\index.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\FRANK\My Documents\Computer Tools\SYSTEM TOOLS\keyfinder.exe/data.rar/xpkey.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>C:\Documents and Settings\FRANK\My Documents\Computer Tools\SYSTEM TOOLS\keyfinder.exe/data.rar/officekey.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>C:\Documents and Settings\FRANK\My Documents\Computer Tools\SYSTEM TOOLS\keyfinder.exe/data.rar&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>C:\Documents and Settings\FRANK\My Documents\Computer Tools\SYSTEM TOOLS\keyfinder.exe&#9;RarSFX: infected - 3&#9;skipped<br>C:\Documents and Settings\FRANK\ntuser.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\FRANK\ntuser.dat.LOG&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\LocalService\Cookies\index.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\LocalService\NTUSER.DAT&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\LocalService\ntuser.dat.LOG&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\NetworkService\Cookies\index.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\NetworkService\NTUSER.DAT&#9;Object is locked&#9;skipped<br>C:\Documents and Settings\NetworkService\ntuser.dat.LOG&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\chandir.dat&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\chandir.idx&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\chn.dat&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\chn.idx&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\D0000000.FCS&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\inuse.txt&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\L0000003.FCS&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\main.log&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\prs.dat&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\prs.idx&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\prs_die.dat&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\prs_die.idx&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\prs_dnd.dat&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\prs_dnd.idx&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\prs_ext.dat&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\prs_ext.idx&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\prs_rcv.dat&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\prs_rcv.idx&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\storydb.dat&#9;Object is locked&#9;skipped<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Users\FRANK\Data\storydb.idx&#9;Object is locked&#9;skipped<br>C:\Program Files\Messenger\kygeta.html&#9;Infected: Trojan-Clicker.Win32.Small.jf&#9;skipped<br>C:\Program Files\Norton AntiVirus\Quarantine\7AAF073F.exe/data.rar/xpkey.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>C:\Program Files\Norton AntiVirus\Quarantine\7AAF073F.exe/data.rar/RAS.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>C:\Program Files\Norton AntiVirus\Quarantine\7AAF073F.exe/data.rar/RockXp_.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>C:\Program Files\Norton AntiVirus\Quarantine\7AAF073F.exe/data.rar&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>C:\Program Files\Norton AntiVirus\Quarantine\7AAF073F.exe&#9;RarSFX: infected - 4&#9;skipped<br>C:\Program Files\Norton AntiVirus\Quarantine\7AAF073F.exe&#9;Crypt.Quarantine: infected - 4&#9;skipped<br>C:\Program Files\Windows NT\hodyrugo.html&#9;Infected: Trojan-Clicker.Win32.Small.jf&#9;skipped<br>C:\QooBox\Quarantine\catchme2008-04-25_ 00911.26.zip/RKWR64.sys&#9;Infected: Rootkit.Win32.Agent.aih&#9;skipped<br>C:\QooBox\Quarantine\catchme2008-04-25_ 00911.26.zip&#9;ZIP: infected - 1&#9;skipped<br>C:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP13\A0000032.dll&#9;Infected: Trojan-Spy.Win32.Agent.bzy&#9;skipped<br>C:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\change.log&#9;Object is locked&#9;skipped<br>C:\WINDOWS\Debug\oakley.log&#9;Object is locked&#9;skipped<br>C:\WINDOWS\Debug\PASSWD.LOG&#9;Object is locked&#9;skipped<br>C:\WINDOWS\pfirewall.log&#9;Object is locked&#9;skipped<br>C:\WINDOWS\SchedLgU.Txt&#9;Object is locked&#9;skipped<br>C:\WINDOWS\SoftwareDistribution\ReportingEvents.log&#9;Object is locked&#9;skipped<br>C:\WINDOWS\Sti_Trace.log&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\AppEvent.Evt&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\default&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\default.LOG&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\SAM&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\SAM.LOG&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\SecEvent.Evt&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\SECURITY&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\SECURITY.LOG&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\software&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\software.LOG&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\SysEvent.Evt&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\system&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\config\system.LOG&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\h323log.txt&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR&#9;Object is locked&#9;skipped<br>C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA&#9;Object is locked&#9;skipped<br>C:\WINDOWS\wiadebug.log&#9;Object is locked&#9;skipped<br>C:\WINDOWS\wiaservc.log&#9;Object is locked&#9;skipped<br>C:\WINDOWS\WindowsUpdate.log&#9;Object is locked&#9;skipped<br>D:\Computer Tools\SYSTEM TOOLS\keyfinder.exe/data.rar/xpkey.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>D:\Computer Tools\SYSTEM TOOLS\keyfinder.exe/data.rar/officekey.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>D:\Computer Tools\SYSTEM TOOLS\keyfinder.exe/data.rar&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>D:\Computer Tools\SYSTEM TOOLS\keyfinder.exe&#9;RarSFX: infected - 3&#9;skipped<br>D:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\A0000150.exe/data.rar/xpkey.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>D:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\A0000150.exe/data.rar/RAS.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>D:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\A0000150.exe/data.rar/RockXp_.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>D:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\A0000150.exe/data.rar&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>D:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\A0000150.exe&#9;RarSFX: infected - 4&#9;skipped<br>D:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\change.log&#9;Object is locked&#9;skipped<br>G:\SYSTEM TOOLS\keyfinder.exe/data.rar/xpkey.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>G:\SYSTEM TOOLS\keyfinder.exe/data.rar/officekey.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>G:\SYSTEM TOOLS\keyfinder.exe/data.rar&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>G:\SYSTEM TOOLS\keyfinder.exe&#9;RarSFX: infected - 3&#9;skipped<br>G:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\A0000151.exe/data.rar/xpkey.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>G:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\A0000151.exe/data.rar/RAS.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>G:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\A0000151.exe/data.rar/RockXp_.exe&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>G:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\A0000151.exe/data.rar&#9;Infected: not-a-virus:PSWTool.Win32.RAS.a&#9;skipped<br>G:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\A0000151.exe&#9;RarSFX: infected - 4&#9;skipped<br>G:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\change.log&#9;Object is locked&#9;skipped<br>H:\System Volume Information\_restore{DDC2EB08-1B46-4CD4-8582-F7D631FA6E0E}\RP14\change.log&#9;Object is locked&#9;skipped<br><br>Scan process completed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20388090</guid>
<pubDate>Fri, 25 Apr 2008 19:20:22 EDT</pubDate>
</item>

<item>
<title>Re: HJT LOG - PC sends out massive random emails, locks up!</title>
<link>http://www.dslreports.com/forum/remark,20384048</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Service Pack 3 for XP was just released, and will be available for dowload and through Windows Update next week.  Please install this through a direct download when available.  The main Security Forum page will not when this happens.  If you have any problems installing SP3, start a new topic here.  I helped over 1200 people install SP2 through Forum assistance, and not one of them was unable to do so with assistance.  Your computer was massively infected, and a lot of this would have been avoided with SP2 installed.<br><br>What is the status of your Norton installation?  Is this a new installation?  You show a great deal of recent file updates.  Please advise if your subscription is current, and that Norton is updated and working properly.<br><br>1. Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>KILLALL::&#012; &#012;File::&#012;C:\WINDOWS\wininit.ini&#012;C:\windows\SYSTEM32\BLACKBOXL.DLL&#012;C:\windows\SYSTEM32\CFGMGR32F.DLL&#012;C:\windows\SYSTEM32\COMPATUIP.DLL&#012;C:\windows\SYSTEM32\KBDPOV.DLL&#012;C:\WINDOWS\system32\asferrorq.dll&#012;C:\WINDOWS\system32\syfowhie.tmp&#012; &#012;Registry::&#012;&#91;HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\7il&#93;&#012;&#91;HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ttool&#93;&#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>2. <b>Kaspersky Online Scanner</b><br><br><b>Go Here ---</b>  &raquo;<A HREF="http://www.kaspersky.co.uk/virusscanner" >www.kaspersky.co.uk/virusscanner</A> <br><br>Read the Requirements and limitations before you click Accept.<br>Allow the ActiveX download if necessary <br>Once the database has downloaded, click Next. <br>Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK. <br><b>Click on "My Computer"</b> and then take a long walk! Do not use the computer until the scan is finished.<br><b>When the scan has completed, click Save Report As... </b><br>Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt) <br><b>Click Save </b>- by default the file will be saved to your Desktop, but you can change this if you wish. <br><br>3. Use the Norton Live Update feature and make sure you are current on definitions.<br><br>Boot to Safe Mode and scan your computer as thoroughly as Norton permits.<br><br>Post back to the Forum the results of C:\Combofix.txt, and the Kaspersky scan results.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20384048</guid>
<pubDate>Fri, 25 Apr 2008 06:08:36 EDT</pubDate>
</item>

<item>
<title>Re: HJT LOG - PC sends out massive random emails, locks up!</title>
<link>http://www.dslreports.com/forum/remark,20383547</link>
<description><![CDATA[<A HREF="/useremail/u/1546970"><b>fjr1966</b></A> : Thank you for the reply. All steps as requested, in order, completed successfully. Logs requested below. SP2 not installed due to overwhelming difficulties with SP2 installation some time ago.<br><br><b> COMBO LOG</b> <br><br>ComboFix 08-04-22.5 - FRANK 2008-04-25  0:05:52.1 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.1.1252.1.1033.18.193 [GMT -4:00]<br>Running from: C:\Documents and Settings\FRANK\Desktop\ComboFix.exe<br> * Created a new restore point<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat<br>C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat<br>C:\Program Files\Common Files\icroso~1.net<br>C:\Program Files\Common Files\icroso~1.net\ICROSO~1.NET\ctxad-464.0000<br>C:\Program Files\Common Files\icroso~1.net\ICROSO~1.NET\ctxad-464.0001<br>C:\Program Files\Common Files\icroso~1.net\ICROSO~1.NET\ctxad-464.0002<br>C:\Program Files\Common Files\icroso~1.net\ICROSO~1.NET\ctxad-464.0003<br>C:\Program Files\Common Files\icroso~1.net\ICROSO~1.NET\ctxad-464.0004<br>C:\Program Files\Common Files\icroso~1.net\ICROSO~1.NET\ctxad-464.0005<br>C:\Program Files\Common Files\icroso~1.net\ICROSO~1.NET\ctxad-464.0006<br>C:\Program Files\Common Files\icroso~1.net\ICROSO~1.NET\ctxad-464.0007<br>C:\WINDOWS\system32\azip32.dll<br>C:\WINDOWS\system32\drivers\grande48.sys<br>C:\WINDOWS\system32\drivers\RKWR64.sys<br>C:\WINDOWS\System32\dswavec.dll<br>C:\WINDOWS\system32\dzgtactx.dll<br>C:\WINDOWS\system32\FTPx.dll<br>C:\WINDOWS\system32\MabryObj.dll<br>C:\WINDOWS\Tasks.\At1.job<br><br>----- BITS: Possible infected sites -----<br><br>hxxp://thenetworkcom.com<br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Legacy_CYHNTPNZ<br>-------\Legacy_EXAMPLE<br>-------\Legacy_EXAMPLE1<br>-------\Legacy_RKWR64<br>-------\Legacy_RUNTIME<br>-------\Service_cyhntpnz<br>-------\Service_EXAMPLE1<br>-------\Service_Rkwr64<br>-------\Service_RKWR64<br><br>(((((((((((((((((((((((((   Files Created from 2008-03-25 to 2008-04-25  )))))))))))))))))))))))))))))))<br>.<br><br>2008-04-24 16:06 . 2008-04-24 16:10&#9;&#9;d--------&#9;C:\Program Files\Spyware Doctor<br>2008-04-24 16:06 . 2008-04-24 16:06&#9;&#9;d--------&#9;C:\Documents and Settings\FRANK\Application Data\PC Tools<br>2008-04-24 16:06 . 2007-12-10 13:53&#9;81,288&#9;--a------&#9;C:\WINDOWS\system32\drivers\iksyssec.sys<br>2008-04-24 16:06 . 2007-12-10 13:53&#9;66,952&#9;--a------&#9;C:\WINDOWS\system32\drivers\iksysflt.sys<br>2008-04-24 16:06 . 2008-02-01 11:55&#9;42,376&#9;--a------&#9;C:\WINDOWS\system32\drivers\ikfilesec.sys<br>2008-04-24 16:06 . 2007-12-10 13:53&#9;29,576&#9;--a------&#9;C:\WINDOWS\system32\drivers\kcom.sys<br>2008-04-24 14:49 . 2008-04-24 15:55&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-04-24 08:07 . 2008-04-24 08:07&#9;174&#9;--a------&#9;C:\WINDOWS\wininit.ini<br>2008-04-24 07:28 . 2008-04-24 07:28&#9;&#9;d--------&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-04-24 06:53 . 2008-04-24 06:53&#9;&#9;d--------&#9;C:\Program Files\SymNetDrv<br>2008-04-24 06:52 . 2005-07-29 09:56&#9;124,168&#9;--a------&#9;C:\WINDOWS\system32\SymStore.dll<br>2008-04-24 06:49 . 2008-04-24 06:50&#9;&#9;d--------&#9;C:\Program Files\Norton AntiVirus<br>2008-04-24 06:49 . 2008-04-24 06:49&#9;&#9;d--------&#9;C:\Documents and Settings\FRANK\Application Data\Symantec<br>2008-04-24 06:49 . 2002-02-26 10:40&#9;120,379&#9;--a------&#9;C:\WINDOWS\system32\SYMEVNT.386<br>2008-04-24 06:49 . 2002-02-26 10:40&#9;58,224&#9;--a------&#9;C:\WINDOWS\system32\drivers\SYMEVENT.SYS<br>2008-04-24 06:49 . 2002-02-26 10:40&#9;36,864&#9;--a------&#9;C:\WINDOWS\system32\S32EVNT1.DLL<br>2008-04-24 06:12 . 2008-04-24 06:12&#9;0&#9;--a------&#9;C:\WINDOWS\nsreg.dat<br>2008-04-24 06:08 . 2008-04-24 06:53&#9;&#9;d--------&#9;C:\Program Files\Symantec<br>2008-04-24 06:08 . 2008-04-24 06:55&#9;&#9;d--------&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-04-24 06:08 . 2008-04-24 06:50&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Symantec<br>2008-04-24 05:25 . 2002-02-26 10:40&#9;4,032&#9;--a------&#9;C:\WINDOWS\system32\SYMEVNT1.DLL<br>2008-04-24 04:45 . 2008-04-25 00:12&#9;&#9;d-a------&#9;C:\Documents and Settings\All Users\Application Data\TEMP<br>2008-04-24 03:33 . 2002-12-11 15:16&#9;88,064&#9;--a------&#9;C:\WINDOWS\system32\asferrorq.dll<br>2008-04-24 03:28 . 2008-04-24 03:28&#9;29&#9;--a------&#9;C:\WINDOWS\system32\syfowhie.tmp<br>2008-04-24 03:27 . 2003-03-31 08:00&#9;88,064&#9;--a------&#9;C:\WINDOWS\system32\cfgmgr32f.dll<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-04-24 11:33&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-04-24 09:11&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-04-24 08:52&#9;12,632&#9;----a-w&#9;C:\WINDOWS\system32\lsdelete.exe<br>2008-04-23 17:15&#9;---------&#9;d-----w&#9;C:\Documents and Settings\FRANK\Application Data\uTorrent<br>2008-02-11 13:39&#9;253,952&#9;----a-w&#9;C:\WINDOWS\system32\OnlineScannerDLLA.dll<br>2008-02-11 13:39&#9;237,568&#9;----a-w&#9;C:\WINDOWS\system32\OnlineScannerDLLW.dll<br>2008-02-08 17:53&#9;110,592&#9;----a-w&#9;C:\WINDOWS\system32\OnlineScannerLang.dll<br>2008-02-05 12:48&#9;77,824&#9;----a-w&#9;C:\WINDOWS\system32\OnlineScannerUninstaller.exe<br>2007-09-28 18:40&#9;57,760&#9;----a-w&#9;C:\Documents and Settings\FRANK\Application Data\GDIPFONTCACHEV1.DAT<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]<br>"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-20 18:08 1511453]<br>"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2006-12-25 03:11 16384]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-30 13:50 185896]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624]<br>"nwiz"="nwiz.exe" [2004-03-24 10:04 782336 C:\WINDOWS\system32\nwiz.exe]<br>"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-03-24 10:04 46080]<br>"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-03-24 10:04 3309568]<br>"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [2001-07-09 06:50 155648]<br>"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [ ]<br>"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 12:39 98304]<br>"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 05:50 19968 C:\WINDOWS\LOGI_MWX.EXE]<br>"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-11 04:08 172032]<br>"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24 49152]<br>"SoundMan"="SOUNDMAN.EXE" [2003-05-14 01:20 55296 C:\WINDOWS\SOUNDMAN.EXE]<br>"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2007-08-15 17:59 374688]<br>"NAV Agent"="C:\PROGRA~1\NORTON~1\navapw32.exe" [2002-02-27 11:27 75384]<br>"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2008-04-24 06:53 95960]<br>"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 11:55 1103240]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br>"VIDC.JPGL"= jpgl.dll<br>"vidc.xvid"= xvid.dll<br>"VIDC.I263"= i263_32.drv<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\7il]<br>C:\WINDOWS\system32\7il.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoProp]<br>--------- 2001-07-16 07:50 36864 C:\PROGRA~1\MICROS~2\Office\bots\fp_wmp\regprop.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]<br>--------- 2006-07-11 06:06 3144800 C:\Program Files\ICQLite\ICQLite.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ttool]<br>C:\WINDOWS\9129837.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebCamRT.exe]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher]<br>--------- 2003-12-01 12:38 892928 C:\Program Files\Logitech\iTouch\iTouch.exe<br><br>R2 IOPort;IOPort;C:\WINDOWS\System32\DRIVERS\IOPORT.SYS [1998-11-27 23:57]<br>R3 QCPro;Logitech QuickCam Pro USB(PID_D001);C:\WINDOWS\System32\DRIVERS\p35u.sys [2001-09-24 12:42]<br><br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-04-24 10:50:56 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"<br>- C:\PROGRA~1\NORTON~1\NAVW32.exeG/task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca<br>.<br>**************************************************************************<br><br>catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-04-25 00:12:24<br>Windows 5.1.2600 Service Pack 1 NTFS<br><br>detected NTDLL code modification:<br>ZwClose<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br>C:\Program Files\Norton AntiVirus\Navapsvc.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\locator.exe<br>C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>C:\Program Files\Spyware Doctor\pctsSvc.exe<br>C:\WINDOWS\system32\wdfmgr.exe<br>C:\Program Files\Canon\CAL\CALMAIN.exe<br>C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-04-25  0:18:51 - machine was rebooted<br>ComboFix-quarantined-files.txt  2008-04-25 04:18:45<br><br>Pre-Run: 65,896,796,160 bytes free<br>Post-Run: 66,456,514,560 bytes free<br><br>161<br><br><b> MBAM LOG</b> <br><br>Malwarebytes' Anti-Malware 1.11<br>Database version: 679<br><br>Scan type: Quick Scan<br>Objects scanned: 35883<br>Time elapsed: 6 minute(s), 34 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 1<br>Files Infected: 2<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>C:\Program Files\whInstall (Adware.WebHancer) -> Quarantined and deleted successfully.<br><br>Files Infected:<br>C:\Program Files\whInstall\license.txt (Adware.WebHancer) -> Quarantined and deleted successfully.<br>C:\Program Files\whInstall\readme.txt (Adware.WebHancer) -> Quarantined and deleted successfully.<br><br><b> HIJACKTHIS LOG</b> <br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 12:47:10 AM, on 4/25/2008<br>Platform: Windows XP SP1 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\csrss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\alg.exe<br>C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>C:\Program Files\Norton AntiVirus\navapsvc.exe<br>C:\WINDOWS\System32\nvsvc32.exe<br>C:\WINDOWS\System32\locator.exe<br>C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>C:\Program Files\Spyware Doctor\pctsSvc.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\wdfmgr.exe<br>C:\Program Files\Canon\CAL\CALMAIN.exe<br>C:\Program Files\Spyware Doctor\pctsTray.exe<br>C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe<br>C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>C:\Program Files\Logitech\MouseWare\system\em_exec.exe<br>C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe<br>C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe<br>C:\WINDOWS\SOUNDMAN.EXE<br>C:\Program Files\TomTom HOME 2\HOMERunner.exe<br>C:\PROGRA~1\NORTON~1\navapw32.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe<br>C:\WINDOWS\explorer.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\Internet Explorer\IEXPLORE.EXE<br>C:\Program Files\HijackThis\HijackThis.exe<br>C:\WINDOWS\System32\wbem\wmiprvse.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe<br>O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe<br>O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe<br>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe<br>O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"<br>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br>O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s<br>O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe<br>O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe<br>O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"<br>O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll<br>O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - &raquo;<A HREF="http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab" >supportcenter.rr.com/sdccommon/d&middot;&middot;&middot;tlcm.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - &raquo;<A HREF="http://www.winkflash.com/photo/loaders/SAXFile.cab" >www.winkflash.com/photo/loaders/SAXFile.cab</A><br>O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - &raquo;<A HREF="http://software-dl.real.com/172a026fd0accf903e05/netzip/RdxIE601.cab" >software-dl.real.com/172a026fd0a&middot;&middot;&middot;E601.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/buxus/docs/OnlineScanner.cab" >www.eset.eu/buxus/docs/OnlineScanner.cab</A><br>O16 - DPF: {5F05A225-0F66-43DE-89E4-6FFD589C4F01} (OC web Installer) - &raquo;<A HREF="http://www.aebn.net/ws/DownloadCoach/dc5/files/objectCubeInstall.cab" >www.aebn.net/ws/DownloadCoach/dc&middot;&middot;&middot;tall.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093983166671" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;83166671</A><br>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173296885812" >update.microsoft.com/microsoftup&middot;&middot;&middot;96885812</A><br>O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - &raquo;<A HREF="http://entimg.msn.com/client/msnediag2918.cab" >entimg.msn.com/client/msnediag2918.cab</A><br>O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - &raquo;<A HREF="http://pcpitstop.com/mhLbl.cab" >pcpitstop.com/mhLbl.cab</A><br>O16 - DPF: {97BB6657-DC7F-4489-9067-51FAB9D8857E} (CWebLaunchCtl Object) - &raquo;<A HREF="http://support.gateway.com/eSupport/static/weblaunch/weblaunch2.cab" >support.gateway.com/eSupport/sta&middot;&middot;&middot;nch2.cab</A><br>O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - &raquo;<A HREF="http://www.crucial.com/controls/cpcScanner.cab" >www.crucial.com/controls/cpcScanner.cab</A><br>O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - &raquo;<A HREF="http://www.byteshop.com:8081/plugin/h263ctrl.cab" >www.byteshop.com:8081/plugin/h263ctrl.cab</A><br>O16 - DPF: {B41059F3-1704-45E3-88F2-6A297F7153FC} (XLoader Control) - &raquo;<A HREF="http://www.testout.com/portal/AllUsers/XLoader.ocx" >www.testout.com/portal/AllUsers/XLoader.ocx</A><br>O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - &raquo;<A HREF="http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?323" >h30043.www3.hp.com/hpdj/en/check&middot;&middot;&middot;.cab?323</A><br>O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - &raquo;<A HREF="http://entimg.msn.com/client/msnmusax2918.cab" >entimg.msn.com/client/msnmusax2918.cab</A><br>O16 - DPF: {FCE90474-8B60-445B-A2B5-57E289BCEA42} (SmartDownloader Control) - &raquo;<A HREF="http://www.downloadcoach.com/SmartDownloader.cab" >www.downloadcoach.com/SmartDownloader.cab</A><br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br>O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br><br>--<br>End of file - 8877 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20383547</guid>
<pubDate>Fri, 25 Apr 2008 00:54:29 EDT</pubDate>
</item>

<item>
<title>Re: HJT LOG - PC sends out massive random emails, locks up!</title>
<link>http://www.dslreports.com/forum/remark,20381838</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <b><u>First Steps</u></b><br><b>:!: The following instructions are <u>only</u> for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance. You assuredly will make a cleanup of your system more difficult.</b><br><br>Please download<b>  <i>ATF Cleaner</i></b> <br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><br><b>First Step:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows XP to show hidden files:</b><br><i>To enable the viewing of Hidden files follow these steps: </i><br>&#8226; Close all programs so that you are at your desktop. <br>&#8226; Double-click on the My Computer icon. <br>&#8226; Select the Tools menu and click Folder Options. <br>&#8226; After the new window appears select the View tab. <br>&#8226; Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226; Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226; Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226; Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226; Press the Apply button and then the OK button and exit My Computer. <br>&#8226; Now your computer is configured to show all hidden files. <br><br><b><u>Malware Removal Steps</u></b><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>F2 - REG:system.ini: UserInit=userinit.exe<br>O2 - BHO: (no name) - {7F38CA7E-C0E2-4638-BE3A-E9CD85DD1121} - c:\windows\system32\dswavec.dll<br>O2 - BHO: (no name) - {B1C8DEA1-A3AA-4549-B165-9856CFD00111} - C:\WINDOWS\System32\cfgmgr32f.dll<br>O20 - Winlogon Notify: qzvntkva - C:\WINDOWS\SYSTEM32\dswavec.dll<br>O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/FRANK/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Download and Run  -- <b>ComboFix&copy; </b> <br>Download this file <b><u>-- to your Desktop --</u></b> from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable  your Antivirus  software -- this includes any Script Blocking Feature it may have.<br><br><b>Important:  Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.</b><br>&#8226; A window will open with a warning.  Accept any disclaimers to start the fix. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>3. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>4. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The <b>MBAM</b> log;<br>&#8226; The reason Service Pack 2 is not installed;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20381838</guid>
<pubDate>Thu, 24 Apr 2008 19:12:46 EDT</pubDate>
</item>

<item>
<title>HJT LOG - PC sends out massive random emails, locks up!</title>
<link>http://www.dslreports.com/forum/remark,20381034</link>
<description><![CDATA[<A HREF="/useremail/u/1546970"><b>fjr1966</b></A> : After a routine reboot, system started sending our massive emails all on its own, email client &#150; Outlook Express &#150; can be open or not&#133;does not make any difference.<br><br>Many pops ups by Norton AV alerting me &#147;outgoing email is being scanned&#148; until system locks up. I followed these steps from Mandatory Steps #13616. (Some could not be completed, but all were attempted.)<br><br>1. Installed Spybot S&D and ran as prescribed per directions in step 1a. All steps were successful.<br><br>2. Ran Ad-aware 2007 as prescribed per directions in 1b. All steps were successful.<br><br>3. Unable to install Windows Defender, errors out and quits when attempting install.<br><br>4. AVG Anti-spyware with 14-day free trial no longer avail. Tried updated version and would not install.<br><br>5. Performed  ESET online scan&#133;removed and deleted 66 items. Log.txt file saved as required.<br><br>6. Etrust Web Scanner, unable to run. Error.<br><br>7. Trend Micro free online scan completed&#133;17 items found and removed.<br><br>8. Rebooted system, problem still remains.<br><br>9. Performed step to download and install HijackThis; performed scan and saved log.<br><br>10. Additional information: When running a Google search and clicking through to desired URL, browser redirects to other spam URL;sometimes. Homepage has NOT been hijacked or changed. It has remained constant.<br><br>I think my system is infected or hijacked and need help. I am a research author who works from home and cannot afford to do a clean install. Please help. Thank you!<br><br>---------<br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 4:17:25 PM, on 4/24/2008<br>Platform: Windows XP SP1 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\csrss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe<br>C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe<br>C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe<br>C:\WINDOWS\SOUNDMAN.EXE<br>C:\PROGRA~1\NORTON~1\navapw32.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe<br>C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>C:\Program Files\Logitech\MouseWare\system\em_exec.exe<br>C:\Program Files\Norton AntiVirus\navapsvc.exe<br>C:\WINDOWS\System32\nvsvc32.exe<br>C:\WINDOWS\System32\locator.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\wdfmgr.exe<br>C:\Program Files\Canon\CAL\CALMAIN.exe<br>C:\WINDOWS\System32\wuauclt.exe<br>C:\WINDOWS\System32\wbem\wmiprvse.exe<br>C:\Program Files\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>F2 - REG:system.ini: UserInit=userinit.exe<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll<br>O2 - BHO: (no name) - {7F38CA7E-C0E2-4638-BE3A-E9CD85DD1121} - c:\windows\system32\dswavec.dll<br>O2 - BHO: (no name) - {B1C8DEA1-A3AA-4549-B165-9856CFD00111} - C:\WINDOWS\System32\cfgmgr32f.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe<br>O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe<br>O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe<br>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe<br>O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"<br>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br>O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s<br>O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe<br>O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe<br>O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll<br>O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - &raquo;<A HREF="http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab" >supportcenter.rr.com/sdccommon/d&middot;&middot;&middot;tlcm.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - &raquo;<A HREF="http://www.winkflash.com/photo/loaders/SAXFile.cab" >www.winkflash.com/photo/loaders/SAXFile.cab</A><br>O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - &raquo;<A HREF="http://software-dl.real.com/172a026fd0accf903e05/netzip/RdxIE601.cab" >software-dl.real.com/172a026fd0a&middot;&middot;&middot;E601.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/buxus/docs/OnlineScanner.cab" >www.eset.eu/buxus/docs/OnlineScanner.cab</A><br>O16 - DPF: {5F05A225-0F66-43DE-89E4-6FFD589C4F01} (OC web Installer) - &raquo;<A HREF="http://www.aebn.net/ws/DownloadCoach/dc5/files/objectCubeInstall.cab" >www.aebn.net/ws/DownloadCoach/dc&middot;&middot;&middot;tall.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093983166671" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;83166671</A><br>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173296885812" >update.microsoft.com/microsoftup&middot;&middot;&middot;96885812</A><br>O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - &raquo;<A HREF="http://entimg.msn.com/client/msnediag2918.cab" >entimg.msn.com/client/msnediag2918.cab</A><br>O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - &raquo;<A HREF="http://pcpitstop.com/mhLbl.cab" >pcpitstop.com/mhLbl.cab</A><br>O16 - DPF: {97BB6657-DC7F-4489-9067-51FAB9D8857E} (CWebLaunchCtl Object) - &raquo;<A HREF="http://support.gateway.com/eSupport/static/weblaunch/weblaunch2.cab" >support.gateway.com/eSupport/sta&middot;&middot;&middot;nch2.cab</A><br>O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - &raquo;<A HREF="http://www.crucial.com/controls/cpcScanner.cab" >www.crucial.com/controls/cpcScanner.cab</A><br>O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - &raquo;<A HREF="http://www.byteshop.com:8081/plugin/h263ctrl.cab" >www.byteshop.com:8081/plugin/h263ctrl.cab</A><br>O16 - DPF: {B41059F3-1704-45E3-88F2-6A297F7153FC} (XLoader Control) - &raquo;<A HREF="http://www.testout.com/portal/AllUsers/XLoader.ocx" >www.testout.com/portal/AllUsers/XLoader.ocx</A><br>O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - &raquo;<A HREF="http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?323" >h30043.www3.hp.com/hpdj/en/check&middot;&middot;&middot;.cab?323</A><br>O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - &raquo;<A HREF="http://entimg.msn.com/client/msnmusax2918.cab" >entimg.msn.com/client/msnmusax2918.cab</A><br>O16 - DPF: {FCE90474-8B60-445B-A2B5-57E289BCEA42} (SmartDownloader Control) - &raquo;<A HREF="http://www.downloadcoach.com/SmartDownloader.cab" >www.downloadcoach.com/SmartDownloader.cab</A><br>O20 - Winlogon Notify: qzvntkva - C:\WINDOWS\SYSTEM32\dswavec.dll<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br>O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/FRANK/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg<br><br>--<br>End of file - 8639 bytes<br><br>-----------------------<br>ESET RESULTS:<br><br># version=4<br># OnlineScanner.ocx=1.0.0.635<br># OnlineScannerDLLA.dll=1, 0, 0, 79<br># OnlineScannerDLLW.dll=1, 0, 0, 78<br># OnlineScannerUninstaller.exe=1, 0, 0, 49<br># vers_standard_module=3052 (20080424)<br># vers_arch_module=1.064 (20080214)<br># vers_adv_heur_module=1.064 (20070717)<br># EOSSerial=6211970585b6124d85837d4130aae6fe<br># end=finished<br># remove_checked=true<br># unwanted_checked=true<br># utc_time=2008-04-24 07:55:25<br># local_time=2008-04-24 03:55:25 (-0500, Eastern Standard Time)<br># country="United States"<br># osver=5.1.2600 NT Service Pack 1<br># scanned=247904<br># found=66<br># scan_time=3860<br>C:\Documents and Settings\Administrator\My Documents\Data\all_files4.exe&#9;multiple infiltrations (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Administrator\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;install_soundfil.exe&#9;Win32/TrojanDownloader.Mendwar.A trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Administrator\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;dist1_1_00.exe&#9;Win32/TrojanDownloader.Agent.EC trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Administrator\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;ezStub.exe&#9;a variant of Win32/Adware.Ezula application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Administrator\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;apropos_client_loader.exe&#9;probably a variant of Win32/Adware.Apropos.downloader application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Administrator\My Documents\Data\Data\all_files4.exe&#9;multiple infiltrations (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Administrator\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;install_soundfil.exe&#9;Win32/TrojanDownloader.Mendwar.A trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Administrator\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;dist1_1_00.exe&#9;Win32/TrojanDownloader.Agent.EC trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Administrator\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;ezStub.exe&#9;a variant of Win32/Adware.Ezula application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Administrator\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;apropos_client_loader.exe&#9;probably a variant of Win32/Adware.Apropos.downloader application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Default User\My Documents\Data\all_files4.exe&#9;multiple infiltrations (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Default User\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;install_soundfil.exe&#9;Win32/TrojanDownloader.Mendwar.A trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Default User\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;dist1_1_00.exe&#9;Win32/TrojanDownloader.Agent.EC trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Default User\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;ezStub.exe&#9;a variant of Win32/Adware.Ezula application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Default User\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;apropos_client_loader.exe&#9;probably a variant of Win32/Adware.Apropos.downloader application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Default User\My Documents\Data\Data\all_files4.exe&#9;multiple infiltrations (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Default User\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;install_soundfil.exe&#9;Win32/TrojanDownloader.Mendwar.A trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Default User\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;dist1_1_00.exe&#9;Win32/TrojanDownloader.Agent.EC trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Default User\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;ezStub.exe&#9;a variant of Win32/Adware.Ezula application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\Default User\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;apropos_client_loader.exe&#9;probably a variant of Win32/Adware.Apropos.downloader application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\ctxad.exe&#9;multiple infiltrations (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\ctxad.exe &raquo;NSIS &raquo;NDrv.dll&#9;a variant of Win32/Adware.PurityScan application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\ctxad.exe &raquo;NSIS &raquo;NDrv.exe&#9;a variant of Win32/Adware.PurityScan application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\ctxad.exe &raquo;NSIS &raquo;PsUninstaller.exe&#9;probably a variant of Win32/Adware.PurityScan application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\gd155d.exe&#9;probably a variant of Win32/Zapchast trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\istdnld.exe&#9;Win32/TrojanDownloader.IstBar.AP1 trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\mit2D3.tmp&#9;a variant of Win32/Adware.Mirar application (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\mit2D3.tmp &raquo;CAB &raquo;NNBar_VCSetup_876075.exe&#9;a variant of Win32/Adware.Mirar application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\mit2D3.tmp.cab&#9;a variant of Win32/Adware.Mirar application (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\mit2D3.tmp.cab &raquo;CAB &raquo;NNBar_VCSetup_876075.exe&#9;a variant of Win32/Adware.Mirar application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\NNBar_VCSetup_876075.exe&#9;a variant of Win32/Adware.Mirar application (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\SuperBarInstall.exe&#9;Win32/Adware.SuperBar.A application (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\SuperBarInstall.exe &raquo;NSIS &raquo;&yacute;&#140;&#128;&#9;Win32/Adware.SuperBar.A application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\tb_setup.exe&#9;Win32/Adware.HuntBar application (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\Local Settings\Temp\ICD1.tmp\installer_MARKETING11.exe&#9;Win32/TrojanDownloader.Adload.A.gen trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\My Documents\Computer Tools\Internet Tools\agmfree.exe&#9;Win32/Adware.Aureate application (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\My Documents\Computer Tools\Internet Tools\agmfree.exe &raquo;ZIP &raquo;AJJ.EXE&#9;Win32/Adware.Aureate application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\My Documents\Computer Tools\Internet Tools\agmfree.exe &raquo;ZIP &raquo;AJJ.EXE&#9;Win32/Adware.Aureate application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\FRANK\My Documents\Computer Tools\Internet Tools\agmfree.exe &raquo;ZIP &raquo;ADVERT.DLL&#9;Win32/Adware.Aureate application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\HelpAssistant\My Documents\Data\all_files4.exe&#9;multiple infiltrations (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\HelpAssistant\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;install_soundfil.exe&#9;Win32/TrojanDownloader.Mendwar.A trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\HelpAssistant\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;dist1_1_00.exe&#9;Win32/TrojanDownloader.Agent.EC trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\HelpAssistant\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;ezStub.exe&#9;a variant of Win32/Adware.Ezula application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\HelpAssistant\My Documents\Data\all_files4.exe &raquo;NSIS &raquo;apropos_client_loader.exe&#9;probably a variant of Win32/Adware.Apropos.downloader application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\HelpAssistant\My Documents\Data\Data\all_files4.exe&#9;multiple infiltrations (deleted)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\HelpAssistant\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;install_soundfil.exe&#9;Win32/TrojanDownloader.Mendwar.A trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\HelpAssistant\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;dist1_1_00.exe&#9;Win32/TrojanDownloader.Agent.EC trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\HelpAssistant\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;ezStub.exe&#9;a variant of Win32/Adware.Ezula application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Documents and Settings\HelpAssistant\My Documents\Data\Data\all_files4.exe &raquo;NSIS &raquo;apropos_client_loader.exe&#9;probably a variant of Win32/Adware.Apropos.downloader application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>C:\Program Files\Common Files\fzkf\fzkfd\vocabulary&#9;Win32/TrojanDownloader.TSUpdate.J trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\RECYCLER\S-1-5-21-1232131049-2556053944-2317078862-500\Dc1.exe&#9;a variant of Win32/Adware.SpySheriff application (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\Downloaded Program Files\installer_MARKETING11.exe&#9;Win32/TrojanDownloader.Adload.A.gen trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\system32\Ahm8.exe&#9;Win32/VB.NB1 trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\system32\Awav20.exe&#9;Win32/VB.NB trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\system32\DluL.exe&#9;Win32/VB.NB trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\system32\Gekd3L.exe&#9;Win32/VB.NB trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\system32\Ixc1.exe&#9;Win32/VB.NB trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\system32\KdfL6BY.exe&#9;Win32/VB.NB1 trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\system32\Szw2E5.exe&#9;Win32/VB.NB trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\system32\Whn5y.exe&#9;Win32/VB.NB trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\system32\YmxB.exe&#9;Win32/VB.NB1 trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>C:\WINDOWS\system32\drivers\kbd.sys&#9;probably a variant of Win32/Injector.V trojan (unable to clean - deleted)&#9;00000000000000000000000000000000<br>D:\Computer Tools\Internet Tools\agmfree.exe&#9;Win32/Adware.Aureate application (deleted)&#9;00000000000000000000000000000000<br>D:\Computer Tools\Internet Tools\agmfree.exe &raquo;ZIP &raquo;AJJ.EXE&#9;Win32/Adware.Aureate application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>D:\Computer Tools\Internet Tools\agmfree.exe &raquo;ZIP &raquo;AJJ.EXE&#9;Win32/Adware.Aureate application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000<br>D:\Computer Tools\Internet Tools\agmfree.exe &raquo;ZIP &raquo;ADVERT.DLL&#9;Win32/Adware.Aureate application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)&#9;00000000000000000000000000000000]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20381034</guid>
<pubDate>Thu, 24 Apr 2008 16:49:29 EDT</pubDate>
</item>

</channel>
</rss>
