1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: pls help.....i got infected

Discussion in 'Virus & Other Malware Removal' started by prophercer, Jul 22, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    Hi.folks pls help. i went to some chinese websites and download some softwares and in the end got infected.my pc was shut down at ist and i restart and quickly delete those programs.my desktop keep changing.the folders i got after infected are DoDoorRSSFinder,pcast.IE - BAR and HuaCi

    below is a list of my Hijackthis log.
    Logfile of HijackThis v1.98.0
    Scan saved at 7:44:48 AM, on 7/23/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\system32\LoadPlugin.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Program Files\ICQLite\ICQLite.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\Program Files\ProxyWay\proxyway.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
    C:\unzipped\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.sg/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\E26Start.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\inituser.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4795.dll
    O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll (file missing)
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\unzipped\Norton AntiVirus 2004 Pro FINAL\Norton.Antivirus.2004.PRO FINAL\NAV\EXTERNAL\NORTON\APP\NAVShExt.dll
    O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINDOWS\system32\CoolBho.dll
    O2 - BHO: IEHlprObj Class - {F5B3ECED-9BF3-4f7e-882B-A6E75343C499} - C:\Progra~1\NetMeeting\netinit.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\unzipped\Norton AntiVirus 2004 Pro FINAL\Norton.Antivirus.2004.PRO FINAL\NAV\EXTERNAL\NORTON\APP\NAVShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn0\ycomp5_5_7_0.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int113777.exe -auto
    O4 - HKLM\..\Run: [win32] winhost.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Registry Crawler] C:\PROGRA~1\RCRAWLER\RCrawler.exe -TRAYONLY
    O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
    O4 - HKLM\..\Run: [] C:\WINDOWS\system32\E26Start.exe
    O4 - HKLM\..\Run: [LetsCool] C:\Program Files\LetsCool\LetsCool.exe
    O4 - HKLM\..\Run: [xw7i] RunDll32 "C:\WINDOWS\Downlo~1\xw7i.dll",Run
    O4 - HKLM\..\RunServices: [win32] winhost.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
    O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE
    O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120338589703
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
    O16 - DPF: {87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} (pcastup Class) - http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.8_20051009.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.75_20051031.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll"

    pls help!!!!!!!!
     
  2. JSntgRvr

    JSntgRvr Moderator Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, prophercer.

    Welcome to TSG.

    Your Hijackthis is outdated.

    * Click here to download HJTsetup.exe
    • Save HJTsetup.exe to your desktop.
    • Doubleclick on the HJTsetup.exe icon on your desktop.
    • By default it will install to C:\Program Files\Hijack This.
    • Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
    • Put a check by Create a desktop icon then click Next again.
    • Continue to follow the rest of the prompts from there.
    • At the final dialogue box click Finish and it will launch Hijack This.
    • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    • Come back here to this thread and Paste the log in your next reply.
    • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
     
  3. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    using AVG anti virus software..i found the follwing virus

    Trojan horse Dropper.Small.19.AO C:\Documents and Settings\fai\Local Settings\Temporary Internet Files\Content.IE5\XTRXIRRW\20060708[1].exe 7/23/2006 6:35 20060708[1].exe 2.77 MB

    Trojan horse Downloader.Agent.EDZ C:\Program Files\Internet Explorer\LoadDriver.exe 7/23/2006 6:38 LoadDriver.exe 100 KB

    Trojan horse Generic.XLX C:\WINDOWS\System32\msicn\plugins\bse.dll 7/23/2006 6:38 bse.dll 92 KB

    Trojan horse Downloader.Agent.EHU C:\WINDOWS\System32\VIPTray.exe 7/23/2006 6:39 VIPTray.exe 124 KB

    Trojan horse PSW.Agent.BXK C:\Documents and Settings\fai\Local Settings\Temp\s5wg\ServeHost.exe 7/23/2006 6:50 ServeHost.exe 52 KB

    Trojan horse Generic.XLX C:\WINDOWS\System32\MSICN\plugins\bse.dll 7/23/2006 7:22 bse.dll 92 KB
     
  4. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    Logfile of HijackThis v1.99.1
    Scan saved at 8:29:32 AM, on 7/23/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\system32\LoadPlugin.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Program Files\ICQLite\ICQLite.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\Program Files\ProxyWay\proxyway.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.sg/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\E26Start.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\inituser.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4644.dll
    O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll (file missing)
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: ActiveBHO Class - {63C55A7F-6E29-8D4F-5C76-4F850F28D13A} - C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\unzipped\Norton AntiVirus 2004 Pro FINAL\Norton.Antivirus.2004.PRO FINAL\NAV\EXTERNAL\NORTON\APP\NAVShExt.dll
    O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINDOWS\system32\CoolBho.dll
    O2 - BHO: IEHlprObj Class - {F5B3ECED-9BF3-4f7e-882B-A6E75343C499} - C:\Progra~1\NetMeeting\netinit.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\unzipped\Norton AntiVirus 2004 Pro FINAL\Norton.Antivirus.2004.PRO FINAL\NAV\EXTERNAL\NORTON\APP\NAVShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn0\ycomp5_5_7_0.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int113777.exe -auto
    O4 - HKLM\..\Run: [win32] winhost.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Registry Crawler] C:\PROGRA~1\RCRAWLER\RCrawler.exe -TRAYONLY
    O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
    O4 - HKLM\..\Run: [] C:\WINDOWS\system32\E26Start.exe
    O4 - HKLM\..\Run: [LetsCool] C:\Program Files\LetsCool\LetsCool.exe
    O4 - HKLM\..\Run: [xw7i] RunDll32 "C:\WINDOWS\Downlo~1\xw7i.dll",Run
    O4 - HKLM\..\RunServices: [win32] winhost.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
    O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE
    O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120338589703
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
    O16 - DPF: {87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} (pcastup Class) - http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.8_20051009.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.75_20051031.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
    O23 - Service: ClipBoard - Unknown owner - C:\WINDOWS\system32\LoadPlugin.exe
    O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Remote Log - Unknown owner - C:\WINDOWS\system32\ServeHost.exe (file missing)
    O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton AntiVirus\SAVScan.exe (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
     
  5. JSntgRvr

    JSntgRvr Moderator Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, prophercer. :)

    Using the Norton Removal Tool

    Please click here and follow the instructions therein to completely remove Norton Antivirus from your computer.

    Please download ATF Cleaner by Atribune.
    This program is for XP and Windows 2000 only

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.
    For Technical Support, double-click the e-mail address located at the bottom of each menu.

    Please download ewido anti-spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program
    1. Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    2. Once the setup is complete you will need run ewido and update the definition files.
    3. On the main screen select the icon "Update" then select the "Update now" link.
      • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    6. Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
    Close ewido anti-spyware, Do Not run a scan just yet, we will shortly in Safe Mode.

    Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.

    Boot into Safe Mode:

    Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

    Perform the following steps in safe mode:

    IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
    • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
    • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    • ewido will now begin the scanning process, be patient this may take a little time.
      Once the scan is complete do the following:
    • If you have any infections you will prompted, then select "Apply all actions"
    • Next select the "Reports" icon at the top.
    • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    • Close ewido .
    Restart back into Windows normally now.

    Please go HERE to run Panda's ActiveScan
    • Once you are on the Panda site click the Scan your PC button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    Post a fresh Hijackthis log along with the Ewido and ActiveScan reports.
     
  6. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    Logfile of HijackThis v1.99.1
    Scan saved at 10:56:35 AM, on 7/23/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\system32\LoadPlugin.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
    C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Program Files\ICQLite\ICQLite.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE
    C:\Program Files\LetsCool\LetsCool.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Program Files\ProxyWay\proxyway.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.sg/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\E26Start.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\inituser.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4795.dll (file missing)
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: ActiveBHO Class - {63C55A7F-6E29-8D4F-5C76-4F850F28D13A} - C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll (file missing)
    O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINDOWS\system32\CoolBho.dll
    O2 - BHO: IEHlprObj Class - {F5B3ECED-9BF3-4f7e-882B-A6E75343C499} - C:\Progra~1\NetMeeting\netinit.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn0\ycomp5_5_7_0.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int113777.exe -auto
    O4 - HKLM\..\Run: [win32] winhost.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Registry Crawler] C:\PROGRA~1\RCRAWLER\RCrawler.exe -TRAYONLY
    O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [LetsCool] C:\Program Files\LetsCool\LetsCool.exe
    O4 - HKLM\..\Run: [xw7i] RunDll32 "C:\WINDOWS\Downlo~1\xw7i.dll",Run
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\HuaCi\huaci\zsearch.exe
    O4 - HKLM\..\Run: [] C:\WINDOWS\system32\E26Start.exe
    O4 - HKLM\..\RunServices: [win32] winhost.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
    O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE
    O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Startup: »®´ÊËÑË÷.lnk = C:\Program Files\HuaCi\huaci\zsearch.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120338589703
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
    O16 - DPF: {87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} (pcastup Class) - http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.8_20051009.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.75_20051031.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: ClipBoard - Unknown owner - C:\WINDOWS\system32\LoadPlugin.exe
    O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Remote Log - Unknown owner - C:\WINDOWS\system32\ServeHost.exe (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
     
  7. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    Activescan report

    Incident Status Location

    Adware:adware/igetnet Not disinfected c:\windows\system\rules.dat
    Adware:adware/clocksync Not disinfected c:\windows\downloaded program files\ClockSyncInst.inf
    Adware:adware/virtualbouncer Not disinfected c:\windows\downloaded program files\VbouncerOuter1124030508.exe
    Spyware:application/bestoffer Not disinfected c:\windows\smdat32m.sys
    Adware:adware/xupiter Not disinfected C:\Documents and Settings\fai\Favorites\Cool Stuff
    Spyware:spyware/escorcher Not disinfected Windows Registry
    Adware:adware/diytoolbar Not disinfected Windows Registry
    Adware:adware/pigsearch Not disinfected Windows Registry
    Adware:adware/fastlook Not disinfected Windows Registry
    Adware:adware/dudu Not disinfected Windows Registry
    Potentially unwanted tool:application/altnet Not disinfected hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\AltnetDM
    Adware:adware/ncase Not disinfected Windows Registry
    Adware:Adware Program Not disinfected C:\WINDOWS\Downloaded Program Files\test.INF
    Hacktool:HackTool/EvID Not disinfected C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe
    Hacktool:HackTool/EvID Not disinfected C:\Program Files\PPLive TV\SynaLiveSetup.exe[EvID4226Patch.exe]
    Adware:Adware/WSearch Not disinfected C:\Program Files\HuaCi\huaci\Mouse1.dll
    Adware:Adware/WSearch Not disinfected C:\Program Files\HuaCi\huaci\SearchM.dll
    Adware:Adware/WSearch Not disinfected C:\Program Files\HuaCi\huaci\zsup.exe
    Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\fai\Cookies\[email protected][1].txt
    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\fai\Cookies\[email protected][2].txt
     
  8. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 10:17:51 AM 7/23/2006

    + Scan result:



    C:\WINDOWS\SYSTEM32\wuwebex.dll -> Adware.Accelerator : Cleaned with backup (quarantined).
    C:\Program Files\NetMeeting\nmview.dll -> Adware.AdMedia : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\1116\ntjdo\ntjcn.emm -> Adware.AllSum : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\1116\tqppmtw\tqppmtw.fyf -> Adware.AllSum : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\msicn\msibm.dll -> Adware.AllSum : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\spoolsv\spoolsv.exe -> Adware.AllSum : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\shdocvw2.dll -> Adware.Baidu : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bargain Buddy -> Adware.BargainBuddy : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
    C:\Documents and Settings\fai\tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007862.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007864.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007871.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007872.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008915.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008917.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008921.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008922.exe -> Adware.Dm : Error during cleaning.
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009857.exe/tool.exe -> Adware.Dm : Error during cleaning.
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009859.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009867.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009868.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010866.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010867.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011136.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011153.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\caishow.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\tool6.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\tool9.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\wmpcda.exe -> Adware.Dmad : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0006873.exe -> Adware.Dmedia : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{0A00D11E-B1E7-44b5-AD88-C9190876AAC4} -> Adware.Dyibar : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher -> Adware.eScorcher : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\General -> Adware.eScorcher : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\URL1 -> Adware.eScorcher : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\URL2 -> Adware.eScorcher : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\URL3 -> Adware.eScorcher : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\URL4 -> Adware.eScorcher : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\URL5 -> Adware.eScorcher : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\debug -> Adware.eScorcher : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{2A0176FE-008B-4706-90F5-BBA532A49731} -> Adware.Generic : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0176FE-008B-4706-90F5-BBA532A49731} -> Adware.Generic : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A0176FE-008B-4706-90F5-BBA532A49731} -> Adware.Generic : Cleaned with backup (quarantined).
    C:\Program Files\DoDoorRSSFinder\ActiveBandObject.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\Program Files\DoDoorRSSFinder\BandObjs.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\Program Files\NetMeeting\netinit.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007857.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007870.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008912.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008920.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009854.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009866.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010868.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010874.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010882.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010883.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011121.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4644.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4708.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4795.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\RssInstaller.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\dllcache\netup.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\inituser.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\PerfectNav -> Adware.KeenValue : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009852.exe -> Adware.Netw : Cleaned with backup (quarantined).
    C:\WINDOWS\estAlive.dll -> Adware.Netw : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP56\snapshot\MFEX-3.DAT -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP56\snapshot\MFEX-4.DAT -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP57\snapshot\MFEX-3.DAT -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP57\snapshot\MFEX-4.DAT -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP68\A0005247.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP68\A0005253.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP68\A0005254.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP68\A0005255.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP68\A0005256.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP69\A0005546.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\Program Files\HuaCi\huaci\Mouse1.dll -> Adware.WSearch : Error during cleaning.
    C:\Program Files\HuaCi\huaci\SearchM.dll -> Adware.WSearch : Error during cleaning.
    C:\Program Files\HuaCi\huaci\abhcop.sys -> Adware.WSearch : Error during cleaning.
    C:\Program Files\HuaCi\huaci\mUin.exe -> Adware.WSearch : Error during cleaning.
    C:\Program Files\HuaCi\huaci\reg.exe/DeskUn.exe -> Adware.WSearch : Error during cleaning.
    C:\Program Files\HuaCi\huaci\zsearch.exe -> Adware.WSearch : Error during cleaning.
    C:\Program Files\HuaCi\huaci\zsup.exe -> Adware.WSearch : Error during cleaning.
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007847.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007848.dll -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007850.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008893.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008894.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008895.dll -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008897.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008898.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008904.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009871.dll -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009872.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010858.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010859.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010860.dll -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010862.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010863.EXE -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010876.dll -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010877.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010879.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010880.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011149.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011155.dll -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011156.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\DRIVERS\hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\DRIVERS\s5wg.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\tool4.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\tool4.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\tool4.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\tool4.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\tool4.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\tool4.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\tool4.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008905.exe -> Adware.Zhongsou : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\DialerX.ocx -> Dialer.Telemedia.b : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\E26Start.exe -> Downloader.Delf.ald : Cleaned with backup (quarantined).
    C:\Program Files\pcast\PodcastbarMini\update.exe -> Downloader.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008926.rbf -> Downloader.Small : Cleaned with backup (quarantined).
    C:\Program Files\starhub\starhub.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\windrvNT.sys -> Rootkit.NtRootKit.131 : Cleaned with backup (quarantined).
    :mozilla.23:C:\Documents and Settings\fai\Application Data\Mozilla\Firefox\Profiles\rdq0dy4k.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).


    ::Report end
     
  9. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    what should i do now????
     
  10. JSntgRvr

    JSntgRvr Moderator Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, prophercer :)

    Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.

    This will likely be a few step process in removing the malware that has infected your system. I encourage you to stick with it and follow my directions as closely as possible so as to avoid complicating the problem further.

    Please download the Killbox by Option^Explicit.

    Note: In the event you already have Killbox, this is a new version that I need you to download.
    • Save it to your desktop.

    The steps that I am about to suggest involve modifying the registry. Modifying the registry can be dangerous so we will make a backup of the registry first.
    Modification of the registry can be EXTREMELY dangerous if you do not know exactly what you are doing so follow the steps that are listed below EXACTLY. if you cannot preform some of these steps or if you have ANY questions please ask BEFORE proceeding.

    Backing Up Your Registry
    1. Go Here and download ERUNT
      (ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
    2. Install ERUNT by following the prompts
      (use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
    3. Start ERUNT
      (either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
    4. Choose a location for the backup
      (the default location is C:\WINDOWS\ERDNT which is acceptable).
    5. Make sure that at least the first two check boxes are ticked
    6. Press OK
    7. Press YES to create the folder.
    Registry Modifications

    Download the enclosed file and extract its contents to the desktop. It is a registry entries file, Shellfix.reg. Do nothing with it yet.

    Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

    O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4795.dll (file missing)
    O2 - BHO: IEHlprObj Class - {F5B3ECED-9BF3-4f7e-882B-A6E75343C499} - C:\Progra~1\NetMeeting\netinit.dll (file missing)
    O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int113777.exe -auto
    O4 - HKLM\..\Run: [win32] winhost.exe
    O4 - HKLM\..\Run: [xw7i] RunDll32 "C:\WINDOWS\Downlo~1\xw7i.dll",Run
    O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\HuaCi\huaci\zsearch.exe
    O4 - HKLM\..\Run: [] C:\WINDOWS\system32\E26Start.exe
    O4 - HKLM\..\RunServices: [win32] winhost.exe
    O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE
    O4 - Startup: »®´ÊËÑË÷.lnk = C:\Program Files\HuaCi\huaci\zsearch.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
    O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCast...5_20051031.cab

    Now close all windows and browsers, other than HiJackThis, then click Fix Checked.

    Close Hijackthis.

    Double click on the Shellfix.reg file and select Yes when prompted to merge it into your registry.

    Go to Start->Run, type CMD and click Ok. The MSDOS window will be displayed. At the prompt type the following and press Enter after each line:

    SC Stop "Symantec Core LC"
    SC Delete "Symantec Core LC"
    Exit

    • Please double-click Killbox.exe to run it.
    • Select:
      • Delete on Reboot
      • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

      C:\WINDOWS\system32\winhost.exe
      C:\WINDOWS\winhost.exe
      C:\WINDOWS\downloaded program files\xw7i.dll
      C:\WINDOWS\system32\inituser.exe
      C:\WINDOWS\system32\E26Start.exe
      C:\WINDOWS\Downloaded Program Files\test.INF
      C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe
      C:\Program Files\PPLive TV\SynaLiveSetup.exe
      c:\windows\system\rules.dat
      c:\windows\downloaded program files\ClockSyncInst.inf
      c:\windows\downloaded program files\VbouncerOuter1124030508.exe
      c:\windows\smdat32m.sys
      C:\Documents and Settings\fai\Favorites\Cool Stuff\
      C:\Program Files\HuaCi\
      C:\Program Files\websx\
      C:\Program Files\CaiShow Tech\


    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

    If your computer does not restart automatically, please restart it manually.

    If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

    1. Launch Notepad, and copy/paste the contents of the quote box below into a new Notepad file. Save it with file name options.txt and save as file type: all files to your desktop.

    2. Download Registry Search to your desktop.
    • Right click on the compressed RegSearch folder, and choose "Extract All". In the box that pops open, click "Next", then "Next" again, and then "Finish". You now have another RegSearch folder on your desktop.
    • Open the new folder, and double click on regsearch.exe
    • Click "Import" in the lower left corner and browse to the options.txt file that you just saved on your desktop. Do not choose the one in the RegSearch folder itself.
    • Click OK and Registry Search will scan your registry for the file(s), and a Notepad box will open with a report.
    • Please reply here with the entire contents of the Notepad file from RegSearch.

    Also re-scan with Hijackthis and post a fresh log.
     

    Attached Files:

  11. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    REGEDIT4

    ; Registry Search 2.0 by Bobbi Flekman © 2005
    ; Version: 2.0.1.0

    ; Results at 7/23/2006 8:17:37 PM for strings:
    ; 'escorcher'
    ; 'diytoolbar'
    ; 'pigsearch'
    ; 'fastlook'
    ; 'dudu'
    ; 'altnet'
    ; 'ncase'
    ; Strings excluded from search:
    ; (None)
    ; Search in:
    ; Registry Keys Registry Values Registry Data
    ; HKEY_LOCAL_MACHINE HKEY_USERS


    [HKEY_LOCAL_MACHINE\SOFTWARE\Ahead\Nero - Burning Rom\Browser]
    "ShowPureUpperNamesInDownCases"=dword:00000000

    [HKEY_LOCAL_MACHINE\SOFTWARE\dudu]

    [HKEY_LOCAL_MACHINE\SOFTWARE\dudu\pCast]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AltnetDM]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DIYTOOLBARV1]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DIYTOOLBARV1]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DIYTOOLBARV1]
    "DisplayName"="DIYTOOLBAR - Toolbar"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\Pcast\\VOD\\dudupros.exe"="C:\\Program Files\\Pcast\\VOD\\dudupros.exe:*:Enabled:dudupros"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\Pcast\\VOD\\dudupros.exe"="C:\\Program Files\\Pcast\\VOD\\dudupros.exe:*:Enabled:dudupros"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\Pcast\\VOD\\dudupros.exe"="C:\\Program Files\\Pcast\\VOD\\dudupros.exe:*:Enabled:dudupros"

    [HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\ahead\Nero - Burning Rom\Browser]
    "ShowPureUpperNamesInDownCases"=dword:00000000

    [HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\DIYTOOLBAR]

    [HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\DIYTOOLBAR\V1]

    [HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\DIYTOOLBAR\V1\Historys1]

    [HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\dudu]

    [HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\dudu\pCast]

    [HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Altnet]

    ; End Of The Log...
     
  12. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    Logfile of HijackThis v1.99.1
    Scan saved at 8:20:13 PM, on 7/23/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\system32\LoadPlugin.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Program Files\ICQLite\ICQLite.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE
    C:\Program Files\LetsCool\LetsCool.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\Program Files\ProxyWay\proxyway.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.sg/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: ActiveBHO Class - {63C55A7F-6E29-8D4F-5C76-4F850F28D13A} - C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll (file missing)
    O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINDOWS\system32\CoolBho.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn0\ycomp5_5_7_0.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Registry Crawler] C:\PROGRA~1\RCRAWLER\RCrawler.exe -TRAYONLY
    O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [LetsCool] C:\Program Files\LetsCool\LetsCool.exe
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
    O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120338589703
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
    O16 - DPF: {87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} (pcastup Class) - http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.8_20051009.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: ClipBoard - Unknown owner - C:\WINDOWS\system32\LoadPlugin.exe
    O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Remote Log - Unknown owner - C:\WINDOWS\system32\ServeHost.exe (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
     
  13. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    i received this message PendingFileRenameOperations prompt
     
  14. JSntgRvr

    JSntgRvr Moderator Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, prophercer :)

    The steps that I am about to suggest involve modifying the registry. Modifying the registry can be dangerous so we will make a backup of the registry first.
    Modification of the registry can be EXTREMELY dangerous if you do not know exactly what you are doing so follow the steps that are listed below EXACTLY. if you cannot preform some of these steps or if you have ANY questions please ask BEFORE proceeding.

    Backing Up Your Registry
    1. Go Here and download ERUNT
      (ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
    2. Install ERUNT by following the prompts
      (use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
    3. Start ERUNT
      (either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
    4. Choose a location for the backup
      (the default location is C:\WINDOWS\ERDNT which is acceptable).
    5. Make sure that at least the first two check boxes are ticked
    6. Press OK
    7. Press YES to create the folder.
    Registry Modifications

    Download the enclosed file and extract its contents to the desktop. It is a registry entries file, Regfix.reg. Once extracted doubleclick on the Regfix.reg file and select Yes when propted to merge it into your registry.

    1. Please download The Avenger by Swandog46 to your Desktop.
    • Click on Avenger.zip to open the file
    • Extract avenger.exe to your desktop

    2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):


    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


    3. Now, start The Avenger program by clicking on its icon on your desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    4. The Avenger will automatically do the following:
    • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
    5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply

    How is the computer doing?
     

    Attached Files:

  15. prophercer

    prophercer Thread Starter

    Joined:
    Dec 25, 2003
    Messages:
    157
    ogfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Services\tqxfomub

    *******************

    Script file located at: \??\C:\Program Files\mjjxnesp.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:



    File C:\WINDOWS\system32\winhost.exe not found!
    Deletion of file C:\WINDOWS\system32\winhost.exe failed!

    Could not process line:
    C:\WINDOWS\system32\winhost.exe
    Status: 0xc0000034



    File C:\WINDOWS\winhost.exe not found!
    Deletion of file C:\WINDOWS\winhost.exe failed!

    Could not process line:
    C:\WINDOWS\winhost.exe
    Status: 0xc0000034



    File C:\WINDOWS\downloaded program files\xw7i.dll not found!
    Deletion of file C:\WINDOWS\downloaded program files\xw7i.dll failed!

    Could not process line:
    C:\WINDOWS\downloaded program files\xw7i.dll
    Status: 0xc0000034



    File C:\WINDOWS\system32\inituser.exe not found!
    Deletion of file C:\WINDOWS\system32\inituser.exe failed!

    Could not process line:
    C:\WINDOWS\system32\inituser.exe
    Status: 0xc0000034



    File C:\WINDOWS\system32\E26Start.exe not found!
    Deletion of file C:\WINDOWS\system32\E26Start.exe failed!

    Could not process line:
    C:\WINDOWS\system32\E26Start.exe
    Status: 0xc0000034



    File C:\WINDOWS\Downloaded Program Files\test.INF not found!
    Deletion of file C:\WINDOWS\Downloaded Program Files\test.INF failed!

    Could not process line:
    C:\WINDOWS\Downloaded Program Files\test.INF
    Status: 0xc0000034



    File C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe not found!
    Deletion of file C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe failed!

    Could not process line:
    C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe
    Status: 0xc0000034



    File C:\Program Files\PPLive TV\SynaLiveSetup.exe not found!
    Deletion of file C:\Program Files\PPLive TV\SynaLiveSetup.exe failed!

    Could not process line:
    C:\Program Files\PPLive TV\SynaLiveSetup.exe
    Status: 0xc0000034



    File c:\windows\system\rules.dat not found!
    Deletion of file c:\windows\system\rules.dat failed!

    Could not process line:
    c:\windows\system\rules.dat
    Status: 0xc0000034



    File c:\windows\downloaded program files\ClockSyncInst.inf not found!
    Deletion of file c:\windows\downloaded program files\ClockSyncInst.inf failed!

    Could not process line:
    c:\windows\downloaded program files\ClockSyncInst.inf
    Status: 0xc0000034



    File c:\windows\downloaded program files\VbouncerOuter1124030508.exe not found!
    Deletion of file c:\windows\downloaded program files\VbouncerOuter1124030508.exe failed!

    Could not process line:
    c:\windows\downloaded program files\VbouncerOuter1124030508.exe
    Status: 0xc0000034



    File c:\windows\smdat32m.sys not found!
    Deletion of file c:\windows\smdat32m.sys failed!

    Could not process line:
    c:\windows\smdat32m.sys
    Status: 0xc0000034



    Folder C:\Documents and Settings\fai\Favorites\Cool Stuff not found!
    Deletion of folder C:\Documents and Settings\fai\Favorites\Cool Stuff failed!

    Could not process line:
    C:\Documents and Settings\fai\Favorites\Cool Stuff
    Status: 0xc0000034

    Folder C:\Program Files\HuaCi deleted successfully.


    Folder C:\Program Files\websx not found!
    Deletion of folder C:\Program Files\websx failed!

    Could not process line:
    C:\Program Files\websx
    Status: 0xc0000034



    Folder C:\Program Files\CaiShow Tech not found!
    Deletion of folder C:\Program Files\CaiShow Tech failed!

    Could not process line:
    C:\Program Files\CaiShow Tech
    Status: 0xc0000034

    Folder C:\Program Files\Pcast deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/485486

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice