Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice
Status
Not open for further replies.

Big spyware, Trojan problem

1K views 8 replies 2 participants last post by  MFDnNC 
#1 ·
I did run housecall, it cleaned a few viruses/spyware: there's still loads remaining I think. Symantec keeps popping up as well with a Trojan.vundo and a geeb.dll. Any help appreciated!

Logfile of HijackThis v1.99.1
Scan saved at 5:52:28 PM, on 6/6/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\NavNT\DefWatch.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\cba\pds.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\PROGRA~1\NavNT\vptray.exe
C:\windows\system32\mldsregs.exe
C:\WINDOWS\System32\rwinmndt.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\DOCUME~1\Pari\MYDOCU~1\YSTEM~1\nslookup.exe
C:\PROGRA~1\NavNT\rtvscan.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cba\xfr.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\Program Files\?ssembly\w?crtupd.exe
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPRV10.EXE
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUMENTS AND SETTINGS\PARI\DESKTOP\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [E9VjjBA] C:\WINDOWS\thnqsmgg.exe
O4 - HKLM\..\Run: [Ihoooj] C:\Program Files\Cererf\Qxnhufh.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [{54-44-40-00-ZN}] C:\windows\system32\mldsregs.exe CHD003
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\System32\rwinmndt.exe CHD003
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKLM\..\Run: [Genuine] rundll32.exe "C:\WINDOWS\System32\iqfjhrpp.dll",realset
O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\System32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Rwar] "C:\DOCUME~1\Pari\MYDOCU~1\YSTEM~1\nslookup.exe" -vt yazb
O4 - HKCU\..\Run: [Viho] "C:\Program Files\?ssembly\w?crtupd.exe"
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\rwinmndt.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2005\spy.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2005\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2005\spy.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantivirus.com/downloa...wp_wa7p_mtrt_us_en&lid=288&affid=pp_809237075
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_6us.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://125.22.240.175/dwa7W.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\cba\pds.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\NavNT\rtvscan.exe
 
See less See more
#2 ·
Ugly - this will take a while - do it all and then post the logs and one hijack log at the end

==================
Download this file :

http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
or
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe

Double click combofix.exe & follow the prompts.
When finished, it shall produce a log for you. Post that log and a HiJack log in your next reply

Note:
Do not mouseclick combofix's window while its running. That may cause it to stall
====================
If you have vundofix, remove it and get the current version

Please download http://www.atribune.org/ccount/click.php?id=4 to C:\
Double-click VundoFix.exe to run it.
click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES.
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will shutdown your computer, click OK.
Turn your computer back on.
Please post the contents of C:\vundofix.txt and a new HijackThis log.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

Please let Vundo finish its thing, sometimes it can take multiple passes
====================
Download Superantispyware (SAS)

http://www.superantispyware.com/superantispywarefreevspro.html

Install it and double-click the icon on your desktop to run it.
· It will ask if you want to update the program definitions, click Yes.
· Under Configuration and Preferences, click the Preferences button.
· Click the Scanning Control tab.
· Under Scanner Options make sure the following are checked:
o Close browsers before scanning
o Scan for tracking cookies
o Terminate memory threats before quarantining.
o Please leave the others unchecked.
o Click the Close button to leave the control center screen.
· On the main screen, under Scan for Harmful Software click Scan your computer.
· On the left check C:\Fixed Drive.
· On the right, under Complete Scan, choose Perform Complete Scan.
· Click Next to start the scan. Please be patient while it scans your computer.
· After the scan is complete a summary box will appear. Click OK.
· Make sure everything in the white box has a check next to it, then click Next.
· It will quarantine what it found and if it asks if you want to reboot, click Yes.
· To retrieve the removal information for me please do the following:
o After reboot, double-click the SUPERAntispyware icon on your desktop.
o Click Preferences. Click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o It will open in your default text editor (such as Notepad/Wordpad).
o Please highlight everything in the notepad, then right-click and choose copy.
· Click close and close again to exit the program.
· Please paste that information here for me with a new HijackThis log.
 
#3 ·
Combofix log:

"Pari" - 2007-06-06 22:52:14 Service Pack 1 NTFS
ComboFix 07-06-3B - Running from: "C:\Documents and Settings\Pari\Desktop\"

(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

C:\WINDOWS\system32\bdeeg.bak1
C:\WINDOWS\system32\bdeeg.bak2
C:\WINDOWS\system32\bdeeg.ini
C:\WINDOWS\system32\bdeeg.ini2
C:\WINDOWS\system32\bdeeg.tmp
C:\WINDOWS\system32\bdeeg.bak1
C:\WINDOWS\system32\bdeeg.bak2
C:\WINDOWS\system32\bdeeg.ini
C:\WINDOWS\system32\bdeeg.ini2
C:\WINDOWS\system32\bdeeg.tmp
C:\WINDOWS\system32\bdeeg.bak1
C:\WINDOWS\system32\bdeeg.bak2
C:\WINDOWS\system32\bdeeg.ini
C:\WINDOWS\system32\bdeeg.ini2
C:\WINDOWS\system32\bdeeg.tmp
C:\WINDOWS\system32\geedb.dll

* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

-- Purity Folders:
C:\DOCUME~1\Pari\MYDOCU~1\YSTEM~1
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\Messenger\ryji.dll
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\RACLE~1
C:\Program Files\SSEMBL~1
C:\Temp\0b9
C:\Temp\0b9\tmpTF.log
C:\WINDOWS\system32\dwdsregt.exe
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\pog
C:\WINDOWS\system32\T3
C:\WINDOWS\system32\T4
C:\WINDOWS\system32\wnscpisv.exe

((((((((((((((((((((((((( Files Created from 2007-05-07 to 2007-06-07 )))))))))))))))))))))))))))))))

2007-06-06 17:37 60,928 --a------ C:\WINDOWS\system32\htna.dll
2007-06-05 11:33 10,240 --a------ C:\WINDOWS\tchxdpbs.exe
2007-06-04 19:25 19,520 --a------ C:\WINDOWS\system32\h4R7mNWk.exe
2007-06-04 13:42 d-------- C:\DOCUME~1\Pari\APPLIC~1\Help
2007-06-04 11:30 dr------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SalesMonitor
2007-06-04 11:30 d-------- C:\DOCUME~1\Pari\APPLIC~1\WinAntiVirus Pro 2007
2007-06-04 11:29 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-06-04 11:29 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-06-04 11:29 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-06-04 11:29 d-------- C:\Program Files\WinAntiVirus Pro 2007
2007-06-04 11:29 d-------- C:\Program Files\Common Files\WinAntiVirus Pro 2007
2007-06-04 11:29 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007
2007-06-04 11:25 49,177 --a------ C:\WINDOWS\system32\mldsregs.exe
2007-06-04 11:06 930 --a------ C:\WINDOWS\system32\winpfz32.sys
2007-06-04 11:06 192,606 --a------ C:\WINDOWS\system32\rwinmndt.exe
2007-06-04 11:06 105,434 --a------ C:\WINDOWS\qwr67.exe
2007-06-04 11:06 d-------- C:\WINDOWS\system32\TQ0
2007-06-04 11:06 d-------- C:\WINDOWS\system32\T9
2007-06-04 11:06 d-------- C:\WINDOWS\system32\T7
2007-06-04 11:06 d-------- C:\WINDOWS\system32\T6
2007-06-04 11:06 d-------- C:\WINDOWS\system32\T1QaSQ
2007-06-04 11:06 d-------- C:\Temp\x2b
2007-06-04 11:06 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\myCleanerPC

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-07 03:57:48 -------- d-----w C:\Program Files\Messenger
2007-06-05 18:40:35 -------- d-----w C:\Program Files\Cererf
2007-06-04 18:42:55 -------- d-----w C:\Program Files\NavNT
2007-03-19 04:43:03 83,208 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2006-10-26 11:28]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 21:38]
{1E837572-97E8-4CB8-9FF1-8C3362167FC9}=C:\Program Files\Windows Media Player\niwykavu.dll [2007-04-06 14:27]
{970A4B44-D3D1-AF29-DD0A-FAADD3E82995}=C:\WINDOWS\System32\htna.dll [2007-05-21 08:59]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar2.dll [2007-01-20 00:55]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-02-14 22:16]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 16:42]
"Ihoooj"="C:\Program Files\Cererf\Qxnhufh.exe" []
"vptray"="C:\PROGRA~1\NavNT\vptray.exe" [2003-05-21 01:21]
"Salestart"="C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Skype.exe" [2005-01-29 19:32]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2006-11-30 22:49]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2006-01-24 14:37]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-22 21:38]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45]
"Rwar"="C:\DOCUME~1\Pari\MYDOCU~1\YSTEM~1\nslookup.exe" []
"Viho"="C:\Program Files\?ssembly\w?crtupd.exe" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyaayv]
xxyaayv.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

Contents of the 'Scheduled Tasks' folder
2007-06-06 05:00:00 C:\WINDOWS\tasks\At1.job
2007-06-06 14:00:00 C:\WINDOWS\tasks\At10.job
2007-06-06 15:01:48 C:\WINDOWS\tasks\At11.job
2007-06-05 16:02:10 C:\WINDOWS\tasks\At12.job
2007-06-05 17:00:40 C:\WINDOWS\tasks\At13.job
2007-06-05 18:00:36 C:\WINDOWS\tasks\At14.job
2007-06-05 19:00:37 C:\WINDOWS\tasks\At15.job
2007-06-05 20:00:33 C:\WINDOWS\tasks\At16.job
2007-06-05 21:00:34 C:\WINDOWS\tasks\At17.job
2007-06-05 22:00:37 C:\WINDOWS\tasks\At18.job
2007-06-06 23:01:33 C:\WINDOWS\tasks\At19.job
2007-06-06 06:00:01 C:\WINDOWS\tasks\At2.job
2007-06-07 00:00:45 C:\WINDOWS\tasks\At20.job
2007-06-07 01:00:47 C:\WINDOWS\tasks\At21.job
2007-06-07 02:00:33 C:\WINDOWS\tasks\At22.job
2007-06-07 03:00:35 C:\WINDOWS\tasks\At23.job
2007-06-07 04:00:01 C:\WINDOWS\tasks\At24.job
2007-06-06 07:00:01 C:\WINDOWS\tasks\At3.job
2007-06-06 08:00:01 C:\WINDOWS\tasks\At4.job
2007-06-06 09:00:01 C:\WINDOWS\tasks\At5.job
2007-06-06 10:00:01 C:\WINDOWS\tasks\At6.job
2007-06-06 11:00:02 C:\WINDOWS\tasks\At7.job
2007-06-06 12:00:01 C:\WINDOWS\tasks\At8.job
2007-06-06 13:00:01 C:\WINDOWS\tasks\At9.job

**************************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-06 23:02:30
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-06-06 23:03:40 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-06 23:03

--- E O F ---

Hijack This Log:

Logfile of HijackThis v1.99.1
Scan saved at 11:09:43 PM, on 6/6/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\NavNT\DefWatch.exe
C:\WINDOWS\system32\cba\pds.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\PROGRA~1\NavNT\rtvscan.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cba\xfr.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\NavNT\vptray.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Pari\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E837572-97E8-4CB8-9FF1-8C3362167FC9} - C:\Program Files\Windows Media Player\niwykavu.dll
O2 - BHO: (no name) - {970A4B44-D3D1-AF29-DD0A-FAADD3E82995} - C:\WINDOWS\System32\htna.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B4A43810-C682-4C06-B17F-663C50960E1B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Ihoooj] C:\Program Files\Cererf\Qxnhufh.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Rwar] "C:\DOCUME~1\Pari\MYDOCU~1\YSTEM~1\nslookup.exe" -vt yazb
O4 - HKCU\..\Run: [Viho] "C:\Program Files\?ssembly\w?crtupd.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2005\spy.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2005\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2005\spy.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantivirus.com/downloa...wp_wa7p_mtrt_us_en&lid=288&affid=pp_809237075
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_6us.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://125.22.240.175/dwa7W.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: xxyaayv - xxyaayv.dll (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\cba\pds.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\NavNT\rtvscan.exe
 
#4 ·
VundoFix did not find any files (!), but here is the new HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 11:16:29 PM, on 6/6/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\NavNT\DefWatch.exe
C:\WINDOWS\system32\cba\pds.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\PROGRA~1\NavNT\rtvscan.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cba\xfr.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\NavNT\vptray.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Documents and Settings\Pari\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E837572-97E8-4CB8-9FF1-8C3362167FC9} - C:\Program Files\Windows Media Player\niwykavu.dll
O2 - BHO: (no name) - {970A4B44-D3D1-AF29-DD0A-FAADD3E82995} - C:\WINDOWS\System32\htna.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B4A43810-C682-4C06-B17F-663C50960E1B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Ihoooj] C:\Program Files\Cererf\Qxnhufh.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Rwar] "C:\DOCUME~1\Pari\MYDOCU~1\YSTEM~1\nslookup.exe" -vt yazb
O4 - HKCU\..\Run: [Viho] "C:\Program Files\?ssembly\w?crtupd.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2005\spy.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2005\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2005\spy.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantivirus.com/downloa...wp_wa7p_mtrt_us_en&lid=288&affid=pp_809237075
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_6us.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://125.22.240.175/dwa7W.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: xxyaayv - xxyaayv.dll (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\cba\pds.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\NavNT\rtvscan.exe
 
#5 ·
HJT LOG After the Super Anti Spyware Scan:

Logfile of HijackThis v1.99.1
Scan saved at 12:44:43 AM, on 6/7/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\NavNT\vptray.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\NavNT\DefWatch.exe
C:\WINDOWS\system32\cba\pds.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\PROGRA~1\NavNT\rtvscan.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cba\xfr.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Pari\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.googlecom/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B4A43810-C682-4C06-B17F-663C50960E1B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Ihoooj] C:\Program Files\Cererf\Qxnhufh.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\System32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Rwar] "C:\DOCUME~1\Pari\MYDOCU~1\YSTEM~1\nslookup.exe" -vt yazb
O4 - HKCU\..\Run: [Viho] "C:\Program Files\?ssembly\w?crtupd.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2005\spy.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2005\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2005\spy.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantivirus.com/downloa...wp_wa7p_mtrt_us_en&lid=288&affid=pp_809237075
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_6us.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://125.22.240.175/dwa7W.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: xxyaayv - xxyaayv.dll (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\cba\pds.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\NavNT\rtvscan.exe

Super Anti-Spyware Log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/07/2007 at 00:36 AM

Application Version : 3.8.1002

Core Rules Database Version : 3250
Trace Rules Database Version: 1261

Scan type : Complete Scan
Total Scan Time : 01:11:42

Memory items scanned : 329
Memory threats detected : 0
Registry items scanned : 5608
Registry threats detected : 43
File items scanned : 60564
File threats detected : 158

Trojan.ZQuest
HKLM\Software\Classes\CLSID\{1E837572-97E8-4CB8-9FF1-8C3362167FC9}
HKCR\CLSID\{1E837572-97E8-4CB8-9FF1-8C3362167FC9}
HKCR\CLSID\{1E837572-97E8-4CB8-9FF1-8C3362167FC9}
HKCR\CLSID\{1E837572-97E8-4CB8-9FF1-8C3362167FC9}\InProcServer32
HKCR\CLSID\{1E837572-97E8-4CB8-9FF1-8C3362167FC9}\InProcServer32#ThreadingModel
C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\NIWYKAVU.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E837572-97E8-4CB8-9FF1-8C3362167FC9}
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MESSENGER\RYJI.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP340\A0031018.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP340\A0031039.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP340\A0031059.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP340\A0031076.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP340\A0031093.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP341\A0031128.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP341\A0031170.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP341\A0031181.DLL

Adware.ClickSpring/Resident
HKLM\Software\Classes\CLSID\{970A4B44-D3D1-AF29-DD0A-FAADD3E82995}
HKCR\CLSID\{970A4B44-D3D1-AF29-DD0A-FAADD3E82995}
HKCR\CLSID\{970A4B44-D3D1-AF29-DD0A-FAADD3E82995}\InprocServer32
HKCR\CLSID\{970A4B44-D3D1-AF29-DD0A-FAADD3E82995}\InprocServer32#ThreadingModel
HKCR\CLSID\{970A4B44-D3D1-AF29-DD0A-FAADD3E82995}\Programmable
HKCR\CLSID\{970A4B44-D3D1-AF29-DD0A-FAADD3E82995}\TypeLib
C:\WINDOWS\SYSTEM32\HTNA.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{970A4B44-D3D1-AF29-DD0A-FAADD3E82995}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP341\A0031182.DLL

Adware.Tracking Cookie
C:\Documents and Settings\Pari\Cookies\pari@specificclick[2].txt
C:\Documents and Settings\Pari\Cookies\pari@www.amaena[1].txt
C:\Documents and Settings\Pari\Cookies\pari@reduxads.valuead[2].txt
C:\Documents and Settings\Pari\Cookies\pari@tradedoubler[2].txt
C:\Documents and Settings\Pari\Cookies\pari@media.top-banners[1].txt
C:\Documents and Settings\Pari\Cookies\pari@perf.overture[1].txt
C:\Documents and Settings\Pari\Cookies\pari@ehg-pcsecurityshield.hitbox[1].txt
C:\Documents and Settings\Pari\Cookies\pari@drivecleaner[2].txt
C:\Documents and Settings\Pari\Cookies\pari@entrepreneur.122.2o7[1].txt
C:\Documents and Settings\Pari\Cookies\pari@winantivirus[2].txt
C:\Documents and Settings\Pari\Cookies\pari@mediatraffic[1].txt
C:\Documents and Settings\Pari\Cookies\pari@atwola[1].txt
C:\Documents and Settings\Pari\Cookies\pari@adbrite[1].txt
C:\Documents and Settings\Pari\Cookies\pari@ex=1_[2].txt
C:\Documents and Settings\Pari\Cookies\pari@ads.z-quest[1].txt
C:\Documents and Settings\Pari\Cookies\pari@campagnes[1].txt
C:\Documents and Settings\Pari\Cookies\pari@bs.serving-sys[1].txt
C:\Documents and Settings\Pari\Cookies\pari@sylmarkidealmedia.112.2o7[1].txt
C:\Documents and Settings\Pari\Cookies\pari@exitexchange[1].txt
C:\Documents and Settings\Pari\Cookies\pari@ehg-meevee.hitbox[2].txt
C:\Documents and Settings\Pari\Cookies\pari@ex=0_[2].txt
C:\Documents and Settings\Pari\Cookies\pari@86793153[1].txt
C:\Documents and Settings\Pari\Cookies\pari@linksynergy[2].txt
C:\Documents and Settings\Pari\Cookies\pari@ads.pointroll[2].txt
C:\Documents and Settings\Pari\Cookies\pari@zedo[1].txt
C:\Documents and Settings\Pari\Cookies\pari@h.starware[2].txt
C:\Documents and Settings\Pari\Cookies\pari@findwhat[1].txt
C:\Documents and Settings\Pari\Cookies\pari@adultfriendfinder[2].txt
C:\Documents and Settings\Pari\Cookies\pari@emarketmakers[2].txt
C:\Documents and Settings\Pari\Cookies\pari@tribalfusion[1].txt
C:\Documents and Settings\Pari\Cookies\pari@edge.ru4[1].txt
C:\Documents and Settings\Pari\Cookies\pari@sonycorporate.122.2o7[1].txt
C:\Documents and Settings\Pari\Cookies\pari@mediaplex[1].txt
C:\Documents and Settings\Pari\Cookies\pari@ad[1].txt
C:\Documents and Settings\Pari\Cookies\pari@2o7[2].txt
C:\Documents and Settings\Pari\Cookies\pari@go.winantivirus[2].txt
C:\Documents and Settings\Pari\Cookies\pari@pch.122.2o7[1].txt
C:\Documents and Settings\Pari\Cookies\pari@atdmt[2].txt
C:\Documents and Settings\Pari\Cookies\pari@stats[2].txt
C:\Documents and Settings\Pari\Cookies\pari@serving-sys[2].txt
C:\Documents and Settings\Pari\Cookies\pari@tacoda[1].txt
C:\Documents and Settings\Pari\Cookies\pari@stats1.reliablestats[2].txt
C:\Documents and Settings\Pari\Cookies\pari@ad.outerinfo[2].txt
C:\Documents and Settings\Pari\Cookies\pari@ehg-adaptivemarketing.hitbox[1].txt
C:\Documents and Settings\Pari\Cookies\pari@revsci[1].txt
C:\Documents and Settings\Pari\Cookies\pari@elitemate[1].txt
C:\Documents and Settings\Pari\Cookies\pari@ad.yieldmanager[1].txt
C:\Documents and Settings\Pari\Cookies\pari@ehg-maniatv.hitbox[1].txt
C:\Documents and Settings\Pari\Cookies\pari@adrevolver[2].txt
C:\Documents and Settings\Pari\Cookies\pari@partner2profit[1].txt
C:\Documents and Settings\Pari\Cookies\pari@overture[2].txt
C:\Documents and Settings\Pari\Cookies\pari@mdlfr[1].txt
C:\Documents and Settings\Pari\Cookies\pari@bluestreak[1].txt
C:\Documents and Settings\Pari\Cookies\pari@fastclick[2].txt
C:\Documents and Settings\Pari\Cookies\pari@1070909243[1].txt
C:\Documents and Settings\Pari\Cookies\pari@banners.searchingbooth[1].txt
C:\Documents and Settings\Pari\Cookies\pari@ads.k8l[2].txt
C:\Documents and Settings\Pari\Cookies\pari@marthastewart.122.2o7[1].txt
C:\Documents and Settings\Pari\Cookies\pari@count1.exitexchange[2].txt
C:\Documents and Settings\Pari\Cookies\pari@adopt.specificclick[2].txt
C:\Documents and Settings\Pari\Cookies\pari@burstnet[1].txt
C:\Documents and Settings\Pari\Cookies\pari@www.drivecleaner[1].txt
C:\Documents and Settings\Pari\Cookies\pari@casalemedia[2].txt
C:\Documents and Settings\Pari\Cookies\pari@qnsr[1].txt
C:\Documents and Settings\Pari\Cookies\pari@cpvfeed[1].txt
C:\Documents and Settings\Pari\Cookies\pari@ads.adbrite[2].txt
C:\Documents and Settings\Pari\Cookies\pari@www.xctrk[2].txt
C:\Documents and Settings\Pari\Cookies\pari@c2.zedo[2].txt
C:\Documents and Settings\Pari\Cookies\pari@adopt.euroclick[2].txt
C:\Documents and Settings\Pari\Cookies\pari@ehg-hollywood.hitbox[1].txt
C:\Documents and Settings\Pari\Cookies\pari@questionmarket[2].txt
C:\Documents and Settings\Pari\Cookies\pari@adrevolver[1].txt
C:\Documents and Settings\Pari\Cookies\pari@statse.webtrendslive[2].txt
C:\Documents and Settings\Pari\Cookies\pari@stats.drivecleaner[2].txt
C:\Documents and Settings\Pari\Cookies\pari@try.starware[1].txt
C:\Documents and Settings\Pari\Cookies\pari@interclick[1].txt
C:\Documents and Settings\Pari\Cookies\pari@4.adbrite[1].txt
C:\Documents and Settings\Pari\Cookies\pari@ads.think-adz[2].txt
C:\Documents and Settings\Pari\Cookies\pari@tremor.adbureau[2].txt
C:\Documents and Settings\Pari\Cookies\pari@entrepreneur[1].txt
C:\Documents and Settings\Pari\Cookies\pari@anad.tacoda[2].txt
C:\Documents and Settings\Pari\Cookies\pari@hc2.humanclick[2].txt
C:\Documents and Settings\Pari\Cookies\pari@trafficmp[1].txt
C:\Documents and Settings\Pari\Cookies\pari@50881381[1].txt
C:\Documents and Settings\Pari\Cookies\pari@adinterax[1].txt
C:\Documents and Settings\Pari\Cookies\pari@cgi-bin[2].txt
C:\Documents and Settings\Pari\Cookies\pari@franceguide[2].txt
C:\Documents and Settings\Pari\Cookies\pari@adserver[1].txt
C:\Documents and Settings\Pari\Cookies\pari@advertising[1].txt
C:\Documents and Settings\Pari\Cookies\pari@ex=0_[3].txt
C:\Documents and Settings\Pari\Cookies\pari@enhance[1].txt
C:\Documents and Settings\Pari\Cookies\pari@msnportal.112.2o7[1].txt
C:\Documents and Settings\Pari\Cookies\pari@nba.112.2o7[1].txt
C:\Documents and Settings\Pari\Cookies\pari@revenue[2].txt
C:\Documents and Settings\Pari\Cookies\pari@doubleclick[2].txt
C:\Documents and Settings\Pari\Cookies\pari@hitbox[1].txt
C:\Documents and Settings\Pari\Cookies\pari@adlegend[1].txt
C:\Documents and Settings\Pari\Cookies\pari@realmedia[2].txt
C:\Documents and Settings\Pari\Cookies\pari@ads.allthatsearch[1].txt
C:\Documents and Settings\Pari\Cookies\pari@server.iad.liveperson[2].txt
C:\Documents and Settings\Binx\Cookies\binx@2o7[2].txt
C:\Documents and Settings\Binx\Cookies\binx@atdmt[2].txt
C:\Documents and Settings\Binx\Cookies\binx@atwola[1].txt
C:\Documents and Settings\CCMS\Cookies\ccms@partner2profit[1].txt
C:\Documents and Settings\CCMS\Cookies\ccms@y-1shz2prbmdj6wvny-1sez2pra2dj6wjloegcjscogqdj6x9ny-1seq-2-2.stats.esomniture[2].txt
C:\Documents and Settings\CCMS\Cookies\ccms@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmykkazsdoamdj6x9ny-1seq-2-2.stats.esomniture[1].txt
C:\Documents and Settings\Pari\Cookies\pari@advertising[2].txt
C:\Documents and Settings\Pari\Cookies\pari@tracking.sms[2].txt

Trojan.WinAntiSpyware/WinAntiVirus 2006/2007
HKU\S-1-5-21-861567501-2147119035-725345543-1005\Software\WinAntiVirus Pro 2007
HKCR\UWAP7.PCheck.1
HKCR\UWAP7.PCheck.1\CurVer
HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}
HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}\InprocServer32
HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}\InprocServer32#ThreadingModel
HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}\ProgID
HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}\Programmable
HKCR\CLSID\{2A5C2E6D-864B-4f2c-9542-8B272741D78B}\VersionIndependentProgID
HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}
HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}\1.0
HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}\1.0\0
HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}\1.0\0\win32
HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}\1.0\FLAGS
HKCR\TypeLib\{6F520BE0-9B54-4558-816F-224E67997DF3}\1.0\HELPDIR
HKCR\Interface\{459F4226-1AAB-43B6-9DC1-B6313EF83749}
HKCR\Interface\{459F4226-1AAB-43B6-9DC1-B6313EF83749}\ProxyStubClsid
HKCR\Interface\{459F4226-1AAB-43B6-9DC1-B6313EF83749}\ProxyStubClsid32
HKCR\Interface\{459F4226-1AAB-43B6-9DC1-B6313EF83749}\TypeLib
HKCR\Interface\{459F4226-1AAB-43B6-9DC1-B6313EF83749}\TypeLib#Version
C:\Program Files\Common Files\WinAntiVirus Pro 2007\err.log
C:\Program Files\Common Files\WinAntiVirus Pro 2007
C:\Program Files\WinAntiVirus Pro 2007\ResErrors.log
C:\Program Files\WinAntiVirus Pro 2007
C:\Documents and Settings\Pari\Application Data\WinAntiVirus Pro 2007\avtasks.dat
C:\Documents and Settings\Pari\Application Data\WinAntiVirus Pro 2007\CookieList.dat
C:\Documents and Settings\Pari\Application Data\WinAntiVirus Pro 2007\history.db
C:\Documents and Settings\Pari\Application Data\WinAntiVirus Pro 2007\Logs\update.log
C:\Documents and Settings\Pari\Application Data\WinAntiVirus Pro 2007\Logs\wa7Support.log
C:\Documents and Settings\Pari\Application Data\WinAntiVirus Pro 2007\Logs\winav.log
C:\Documents and Settings\Pari\Application Data\WinAntiVirus Pro 2007\Logs
C:\Documents and Settings\Pari\Application Data\WinAntiVirus Pro 2007\PGE.dat
C:\Documents and Settings\Pari\Application Data\WinAntiVirus Pro 2007
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP340\A0031005.OLD

Adware.ClickSpring/Outer Info Network
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#HelpLink
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#InstallLocation
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoModify
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoRepair
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayVersion
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayIcon
C:\Documents and Settings\Pari\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Pari\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\Pari\Start Menu\Programs\Outerinfo

Browser Hijacker.Favorites
C:\DOCUMENTS AND SETTINGS\PARI\DESKTOP\CLICK TO FIND AND FIX ERRORS.URL

Adware.k8l
C:\PROGRAM FILES\MESSENGER\VIRO.HTML

Adware.ClickSpring
C:\QOOBOX\QUARANTINE\C\DOCUME~1\PARI\MYDOCU~1\YSTEM~1\NSLOOKUP.EXE
C:\QooBox\Quarantine\C\Program Files\SSEMBL~1\WCRTUP~1.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP340\A0031123.EXE

Adware.ClickSpring/Yazzle
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1281OINADMIN.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1281OINUNINSTALLER.EXE.VIR

Adware.ZenoSearch
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DWDSREGT.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP341\A0031171.EXE
C:\WINDOWS\SYSTEM32\MLDSREGS.EXE

Trojan.Unknown Origin
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WNSCPISV.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP341\A0031157.EXE
C:\WINDOWS\TCHXDPBS.EXE

Trojan.ZQuest-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP340\A0031118.EXE

Adware.Avenue Media
C:\SYSTEM VOLUME INFORMATION\_RESTORE{54F71031-A55D-43AD-9235-07BB0B6FB3A7}\RP340\A0031125.EXE

Malware.SystemDoctor
C:\WINDOWS\DOWNLOADED PROGRAM FILES\USDR6_9999_N18M1603NETINSTALLER.EXE

Trojan.ZenoSearch
C:\WINDOWS\SYSTEM32\RWINMNDT.EXE
C:\WINDOWS\Prefetch\RWINMNDT.EXE-138FE622.pf

Trojan.Downloader-Gen/Inst2
C:\WINDOWS\SYSTEM32\T6\AMWR.EXE

Trojan.Downloader-Gen
C:\WINDOWS\SYSTEM32\WINPFZ32.SYS

Adware.Unknown Origin
C:\WINDOWS\SYSTEM32\ZXDNT3D.CFG
 
#7 ·
Patience, I have a life off the boards and this is not real time support!

Please click here http://www.majorgeeks.com/Sun_Java_Runtime_Environment_d4648.html to download the latest version of JAVA Install the application, then go to the Add/Remove Programs options in the Control Panel and Remove ALL previous versions of JAVA.

===============
You may want to print this or save it to notepad as we will go to safe mode.

Fix these with HiJackThis – mark them, close IE, click fix checked

O4 - HKLM\..\Run: [Ihoooj] C:\Program Files\Cererf\Qxnhufh.exe

O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"

O4 - HKCU\..\Run: [Rwar] "C:\DOCUME~1\Pari\MYDOCU~1\YSTEM~1\nslookup.exe" -vt yazb

O4 - HKCU\..\Run: [Viho] "C:\Program Files\?ssembly\w?crtupd.exe"

O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantivirus.com/download...d=pp_809237075

O20 - Winlogon Notify: xxyaayv - xxyaayv.dll (file missing)

DownLoad http://www.downloads.subratam.org/KillBox.zip or
http://www.thespykiller.co.uk/files/killbox.exe

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

C:\Program Files\Common Files\WinAntiVirus Pro 2007
C:\Program Files\Cererf
C:\DOCUME~1\Pari\MYDOCU~1\YSTEM~1
C:\Program Files\?ssembly

Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

START – RUN – type in %temp% - OK - Edit – Select all – File – Delete

Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

Not all temp files will delete and that is normal
Empty the recycle bin
Boot and post a new hijack log from normal NOT safe mode

Please give feedback on what worked/didn’t work and the current status of your system
 
#8 ·
Sorry about that, did'nt mean to bother you.

This is the most recent HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 9:05:05 PM, on 6/8/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\NavNT\DefWatch.exe
C:\WINDOWS\system32\cba\pds.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\PROGRA~1\NavNT\rtvscan.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cba\xfr.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\NavNT\vptray.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\Pari\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.googlecom/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B4A43810-C682-4C06-B17F-663C50960E1B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2005\spy.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2005\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2005\spy.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_6us.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://125.22.240.175/dwa7W.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\cba\pds.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\NavNT\rtvscan.exe
 
Status
Not open for further replies.
You have insufficient privileges to reply here.
Top