Options

Computer running slow

My laptop is running really slow. I have Avg anti virus and it finds a trojan horse every few hours (started with zlob.fc and now getting generic3.aws, collected.11.b, generic3.glf, lop.ax). I also have Ad-aware, Pest Patrol, SpyBot, Ashampoo (all updated) and did a few scans and deleted all the crap they found. Not much happened though. Please help! Thanks.

Logfile of HijackThis v1.99.1
Scan saved at 4:37:09 PM, on 3/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Documents and Settings\Cristian\Desktop\hi\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.averatec.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.averatec.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in_1.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AudCtrl] RunDll32 AudCtrl.dll,RCMonitor
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\dpmetbjc.dll",setvm
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.averatec.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159157193169
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

Comments

  • edited March 2007
    Hi Cris_mih22!
    Rename Hijackthis.exe to Scanner.exe and create new log and post it back here.
    ;)
  • edited March 2007
    Logfile of HijackThis v1.99.1
    Scan saved at 2:28:29 AM, on 3/5/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\UStorSrv.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\PROGRA~1\PESTPA~1\PPControl.exe
    C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\RALINK\Common\RaUI.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Cristian\Desktop\hi\Scanner.exe.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.averatec.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.averatec.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: (no name) - {945C8260-5BC6-40AC-9E76-2FBA68A26FB0} - C:\WINDOWS\system32\yayvv.dll (file missing)
    O2 - BHO: (no name) - {C47A9554-195A-4769-9B13-04F15B450A39} - C:\WINDOWS\system32\opnlmnk.dll
    O2 - BHO: (no name) - {DCAFEFD5-FB59-4360-A03E-DAB279D6B5AC} - C:\WINDOWS\system32\pmkkh.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
    O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [AudCtrl] RunDll32 AudCtrl.dll,RCMonitor
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://www.averatec.com
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159157193169
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
    O20 - Winlogon Notify: opnlmnk - C:\WINDOWS\SYSTEM32\opnlmnk.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: yayvv - C:\WINDOWS\system32\yayvv.dll (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
  • edited March 2007
    Hi!

    Please download VundoFix.exe to your desktop.

    * Double-click VundoFix.exe to run it.
    * Click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will reboot your computer, click OK.
    * Please post the contents of C:\vundofix.txt and a new HiJackThis log.

    Important note -- It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
  • edited March 2007
    Scanned a few times. First I had an older version, then i downloaded the latest one.

    VundoFix V6.3.9

    Checking Java version...

    Java version is 1.5.0.9

    Scan started at 11:04:02 PM 3/4/2007

    Listing files found while scanning....

    C:\WINDOWS\system32\cjbtempd.ini
    C:\WINDOWS\system32\dpmetbjc.dll
    C:\WINDOWS\system32\jeouosyk.exe
    C:\WINDOWS\system32\ooycecwl.exe
    C:\WINDOWS\system32\pbgadqja.exe
    C:\WINDOWS\system32\pmkkh.dll
    C:\WINDOWS\system32\sscgswyt.dll
    C:\WINDOWS\system32\tywsgcss.ini
    C:\WINDOWS\system32\yayvv.dll

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\cjbtempd.ini
    C:\WINDOWS\system32\cjbtempd.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\dpmetbjc.dll
    C:\WINDOWS\system32\dpmetbjc.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\jeouosyk.exe
    C:\WINDOWS\system32\jeouosyk.exe Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ooycecwl.exe
    C:\WINDOWS\system32\ooycecwl.exe Has been deleted!

    Attempting to delete C:\WINDOWS\system32\pbgadqja.exe
    C:\WINDOWS\system32\pbgadqja.exe Has been deleted!

    Attempting to delete C:\WINDOWS\system32\pmkkh.dll
    C:\WINDOWS\system32\pmkkh.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\sscgswyt.dll
    C:\WINDOWS\system32\sscgswyt.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\tywsgcss.ini
    C:\WINDOWS\system32\tywsgcss.ini Has been deleted!

    Performing Repairs to the registry.
    Done!


    VundoFix V6.3.12

    Checking Java version...

    Java version is 1.5.0.9
    Old versions of java are exploitable and should be removed.

    Java version is 1.5.0.10

    Scan started at 7:54:21 AM 3/5/2007

    Listing files found while scanning....

    C:\Documents and settings\Cristian\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
    C:\Documents and settings\Cristian\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
    C:\Program Files\VSAdd-in\VSAdd-in.dll
    C:\WINDOWS\system32\csqvvmjo.ini
    C:\WINDOWS\system32\iijjl.bak1
    C:\WINDOWS\system32\iijjl.ini
    C:\WINDOWS\system32\ljjii.dll
    C:\WINDOWS\system32\ojmvvqsc.dll
    C:\WINDOWS\system32\opnlmnk.dll
    C:\WINDOWS\system32\rnwwbxrx.exe
    C:\WINDOWS\system32\vtuuvwx.dll
    C:\WINDOWS\system32\yayvv.dll

    Beginning removal...

    Attempting to delete C:\Documents and settings\Cristian\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
    C:\Documents and settings\Cristian\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt Has been deleted!

    Attempting to delete C:\Documents and settings\Cristian\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
    C:\Documents and settings\Cristian\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt Has been deleted!

    Attempting to delete C:\Program Files\VSAdd-in\VSAdd-in.dll
    C:\Program Files\VSAdd-in\VSAdd-in.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\csqvvmjo.ini
    C:\WINDOWS\system32\csqvvmjo.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\iijjl.bak1
    C:\WINDOWS\system32\iijjl.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\iijjl.ini
    C:\WINDOWS\system32\iijjl.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ljjii.dll
    C:\WINDOWS\system32\ljjii.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ojmvvqsc.dll
    C:\WINDOWS\system32\ojmvvqsc.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\opnlmnk.dll
    C:\WINDOWS\system32\opnlmnk.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\rnwwbxrx.exe
    C:\WINDOWS\system32\rnwwbxrx.exe Has been deleted!

    Attempting to delete C:\WINDOWS\system32\vtuuvwx.dll
    C:\WINDOWS\system32\vtuuvwx.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    VundoFix V6.3.12

    Checking Java version...

    Java version is 1.5.0.9
    Old versions of java are exploitable and should be removed.

    Java version is 1.5.0.10

    Scan started at 8:28:06 AM 3/5/2007

    Listing files found while scanning....

    C:\WINDOWS\system32\vvyay.bak1
    C:\WINDOWS\system32\vvyay.bak2
    C:\WINDOWS\system32\vvyay.ini
    C:\WINDOWS\system32\vvyay.ini2
    C:\WINDOWS\system32\vvyay.tmp
    C:\WINDOWS\system32\yayvv.dll

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\vvyay.bak1
    C:\WINDOWS\system32\vvyay.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\vvyay.bak2
    C:\WINDOWS\system32\vvyay.bak2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\vvyay.ini
    C:\WINDOWS\system32\vvyay.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\vvyay.ini2
    C:\WINDOWS\system32\vvyay.ini2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\vvyay.tmp
    C:\WINDOWS\system32\vvyay.tmp Has been deleted!

    Performing Repairs to the registry.
    Done!

    VundoFix V6.3.12

    Checking Java version...

    Java version is 1.5.0.9
    Old versions of java are exploitable and should be removed.

    Java version is 1.5.0.10

    Scan started at 8:47:20 AM 3/5/2007

    Listing files found while scanning....

    C:\WINDOWS\system32\yayvv.dll

    Beginning removal...

    Performing Repairs to the registry.
    Done!
  • edited March 2007
    Hi!

    Please post a new hijackthis log :)
  • edited March 2007
    Logfile of HijackThis v1.99.1
    Scan saved at 1:52:51 PM, on 3/5/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\UStorSrv.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\PROGRA~1\PESTPA~1\PPControl.exe
    C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Cristian\Desktop\hi\Scanner.exe.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.averatec.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.averatec.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: (no name) - {945C8260-5BC6-40AC-9E76-2FBA68A26FB0} - C:\WINDOWS\system32\yayvv.dll (file missing)
    O2 - BHO: (no name) - {C47A9554-195A-4769-9B13-04F15B450A39} - C:\WINDOWS\system32\opnlmnk.dll (file missing)
    O2 - BHO: (no name) - {DCAFEFD5-FB59-4360-A03E-DAB279D6B5AC} - C:\WINDOWS\system32\pmkkh.dll (file missing)
    O2 - BHO: (no name) - {FB034E1F-9ED7-432F-96B1-A63851565CF0} - C:\WINDOWS\system32\ljjii.dll (file missing)
    O3 - Toolbar: (no name) - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
    O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [AudCtrl] RunDll32 AudCtrl.dll,RCMonitor
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://www.averatec.com
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159157193169
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: yayvv - C:\WINDOWS\system32\yayvv.dll (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
  • edited March 2007
    Run HijackThis and Click Do a system scan only.
    Check following

    O2 - BHO: (no name) - {945C8260-5BC6-40AC-9E76-2FBA68A26FB0} - C:\WINDOWS\system32\yayvv.dll (file missing)
    O2 - BHO: (no name) - {C47A9554-195A-4769-9B13-04F15B450A39} - C:\WINDOWS\system32\opnlmnk.dll (file missing)
    O2 - BHO: (no name) - {DCAFEFD5-FB59-4360-A03E-DAB279D6B5AC} - C:\WINDOWS\system32\pmkkh.dll (file missing)
    O2 - BHO: (no name) - {FB034E1F-9ED7-432F-96B1-A63851565CF0} - C:\WINDOWS\system32\ljjii.dll (file missing)
    O3 - Toolbar: (no name) - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)
    O20 - Winlogon Notify: yayvv - C:\WINDOWS\system32\yayvv.dll (file missing)


    Click Fix Checked.

    **********************************

    * Uninstall all old versions of Java via Add/Remove Programs
    * Click the Remove or Change/Remove button
    * Reboot your PC if prompted


    Go here and download and install JRE 6.0. Click the link that says Download JRE 6.0 .
    You will then need to select Accept License Agreement and click the Continue button that is beside it.
    Then click the link that says Windows Offline Installation, Multi-language. Save it to your Desktop.
    Then go back to your Desktop and double click jre-6-windows-i586.exe to start the install.

    ********************

    Send a fresh hijack log.
  • edited March 2007
    Logfile of HijackThis v1.99.1
    Scan saved at 8:54:33 AM, on 3/6/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\PESTPA~1\PPControl.exe
    C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\Program Files\Java\jre1.6.0\bin\jusched.exe
    C:\Program Files\RALINK\Common\RaUI.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\UStorSrv.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Cristian\Desktop\hi\Scanner.exe.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.averatec.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.averatec.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
    O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [AudCtrl] RunDll32 AudCtrl.dll,RCMonitor
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://www.averatec.com
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159157193169
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
  • edited March 2007
    Hi!

    Please do the following...

    1. Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.
    This program is for XP and Windows 2000 only!

    Double-click ATF Cleaner.exe to open it.

    Under Main select the following:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch
    • Java Cache
    *The other boxes are optional*
    Then click the Empty Selected button.

    Click Exit on the Main menu to close the program.

    Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
    http://www.ewido.net/en/download/
    • Install AVG Anti-Spyware by double clicking the installer.
    • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
    • On the main screen under Your Computer's security.
      • Click on Change state next to Resident shield. It should now change to inactive.
      • Click on Change state next to Automatic updates. It should now change to inactive.
      • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
      • Wait until you see the Update succesfull message.
    • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
    • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
    If you are having problems with the updater, you can use this link to manually update ewido.
    AVG Anti-Spyware manual updates.
    Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

    Reboot your computer in Safe Mode.
    • If the computer is running, shut down Windows, and then turn off the power.
    • Wait 30 seconds, and then turn the computer on.
    • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
    • Ensure that the Safe Mode option is selected.
    • Press Enter. The computer then begins to start in Safe mode.
    • Login on your usual account.
    Once in Safe Mode:

    Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
    • Click on Scanner on the toolbar.
    • Click on the Settings tab.
      • Under How to act?
        • Click on Recommended Action and choose Quarantine from the popup menu.
      • Under How to scan?
        • All checkboxes should be ticked.
      • Under Possibly unwanted software:
        • All checkboxes should be ticked.
      • Under Reports:
        • Select Automatically generate report after every scan and uncheck Only if threats were found.
      • Under What to scan?
        • Select Scan every file.
    • Click on the Scan tab.
    • Click on Complete System Scan to start the scan process.
    • Let the program scan the machine.
    • When the scan has finished, follow the instructions below.
      IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
      • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
      • At the bottom of the window click on the Apply all Actions button. (3)
        scanavgjk2.jpg
    • When done, click the Save Scan Report button. (4)
      • Click the Save Report as button.
      • Save the report to your Desktop.
    • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
    Reboot back into Normal Mode, and post a new HJT log, along with the AVG Anti-Spyware raport.
  • edited March 2007
    avg report:

    C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP254\A0038470.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP254\A0038471.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
    :mozilla.359:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.49:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.50:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.51:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.52:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.53:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.54:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.55:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.56:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.57:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.136:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.138:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.185:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.186:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.115:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.116:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.117:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.118:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.158:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
    :mozilla.46:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
    :mozilla.94:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    :mozilla.172:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
    :mozilla.173:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
    :mozilla.174:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
    :mozilla.175:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
    :mozilla.323:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
    :mozilla.324:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
    :mozilla.325:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
    :mozilla.326:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
    :mozilla.327:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
    :mozilla.81:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.236:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
    :mozilla.332:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
    :mozilla.126:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.127:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.128:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.129:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.256:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.258:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.60:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.61:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.63:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.87:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
    :mozilla.86:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
    :mozilla.358:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.298:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.299:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.300:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.301:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.35:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.36:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.362:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.363:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.225:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
    :mozilla.91:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.92:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.93:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.95:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.98:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.333:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
    :mozilla.334:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
    :mozilla.316:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.367:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.368:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.369:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.370:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.371:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.296:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    :mozilla.297:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    :mozilla.378:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    :mozilla.88:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
    :mozilla.70:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.71:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.72:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.73:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.142:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.143:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.144:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.145:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.146:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.147:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.148:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.149:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.379:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
    :mozilla.180:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.205:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.159:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    :mozilla.160:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    :mozilla.161:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    :mozilla.162:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    :mozilla.163:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    :mozilla.164:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    :mozilla.165:C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP254\A0037289.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP254\A0038451.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
  • edited March 2007
    Logfile of HijackThis v1.99.1
    Scan saved at 5:04:09 PM, on 3/6/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\UStorSrv.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\PESTPA~1\PPControl.exe
    C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\Program Files\Java\jre1.6.0\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\Cristian\Desktop\hi\Scanner.exe.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.averatec.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.averatec.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
    O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [AudCtrl] RunDll32 AudCtrl.dll,RCMonitor
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://www.averatec.com
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159157193169
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
  • edited March 2007
    Hi! ;)

    Lets clean system restore, INSTRUCTIONS

    I`ll think that your computer is clean after that ;)
  • edited March 2007
    cool. thanks for helping me.
  • edited March 2007
    :)

    Your welcome
  • edited March 2007
    avg anti-virus found 2 trojan horse lop.ax
    avg anti-spyware found 1 trojan kill.av today

    Yesterday, avg found 1 trojan lop.ax

    Apparently, I am still having problems.
  • edited March 2007
    hmm.. Post your hijackthis log here :)
  • edited March 2007
    Logfile of HijackThis v1.99.1
    Scan saved at 10:30:17 PM, on 3/15/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\PESTPA~1\PPControl.exe
    C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Cristian\Desktop\hi\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.averatec.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.averatec.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
    O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [AudCtrl] RunDll32 AudCtrl.dll,RCMonitor
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe"
    O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
    O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.averatec.com
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159157193169
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
  • edited March 2007
    Do you have the Avg-Antispyware log, when it founds 1 trojan lop.ax?
    Please, post it here :)
  • edited March 2007
    this is the log from the 12th till now

    - <rec time="2007/03/12 14:25:44" user="NETWORK SERVICE" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\WINDOWS\system32\vtusr.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/12 14:28:04" user="NETWORK SERVICE" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\WINDOWS\system32\vtusr.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/12 15:22:52" user="Cristian" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\WINDOWS\system32\vtusr.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/12 15:22:58" user="Cristian" source="Virus">
    <value>@HL_ActionTaken&lt;/value>

    <attr name="filename">C:\WINDOWS\system32\vtusr.dll</attr>

    <attr name="action">@HL_ActCleaned&lt;/attr>

    </rec>


    - <rec time="2007/03/13 15:22:15" user="Cristian" source="General">
    <value>@HL_TestStarted&lt;/value>

    <attr name="testname">@TestName_13&lt;/attr>

    </rec>


    - <rec time="2007/03/13 17:22:19" user="Cristian" source="Virus">
    <value>@HL_ReportFind&lt;/value>

    <attr name="where">C:\VundoFix Backups\ljjii.dll.bad</attr>

    <attr name="type">@EID_Id_trj&lt;/attr>

    <attr name="what">Lop.AX</attr>

    </rec>


    - <rec time="2007/03/13 17:22:22" user="Cristian" source="Virus">
    <value>@HL_ReportFind&lt;/value>

    <attr name="where">C:\VundoFix Backups\pmkkh.dll.bad</attr>

    <attr name="type">@EID_Id_trj&lt;/attr>

    <attr name="what">Lop.AX</attr>

    </rec>


    - <rec time="2007/03/13 18:50:48" user="Cristian" source="General">
    <value>@HL_TestEnded&lt;/value>

    <attr name="testname">@TestName_13&lt;/attr>

    <attr name="infectedfiles">2</attr>

    </rec>


    - <rec time="2007/03/13 18:51:07" user="Cristian" source="Virus">
    <value>@HL_ActionTaken&lt;/value>

    <attr name="filename">C:\VundoFix Backups\ljjii.dll.bad</attr>

    <attr name="action">@HL_ActCleaned&lt;/attr>

    </rec>


    - <rec time="2007/03/13 18:51:08" user="Cristian" source="Virus">
    <value>@HL_ActionTaken&lt;/value>

    <attr name="filename">C:\VundoFix Backups\pmkkh.dll.bad</attr>

    <attr name="action">@HL_ActCleaned&lt;/attr>

    </rec>


    - <rec time="2007/03/14 02:19:46" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/14 18:20:58" user="SYSTEM" source="Update">
    <value>@HL_UpdateOK&lt;/value>

    <attr name="version">avi:974-972;iavi:732-729;</attr>

    </rec>


    - <rec time="2007/03/14 19:51:07" user="Cristian" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/14 20:56:24" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/15 08:01:25" user="SYSTEM" source="Update">
    <value>@HL_UpdateOK&lt;/value>

    <attr name="version">iavi:733-732;</attr>

    </rec>


    - <rec time="2007/03/15 14:54:30" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/15 15:13:10" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/15 19:55:49" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/15 21:57:04" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/15 23:35:41" user="Cristian" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/16 00:53:18" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/16 01:50:58" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/16 15:22:27" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/16 17:11:41" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/16 17:20:19" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/16 18:59:09" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    - <rec time="2007/03/16 19:41:49" user="SYSTEM" source="Virus">
    <value>@HL_ReportFindRS&lt;/value>

    <attr name="filename">C:\System Volume Information\_restore{D62CA84F-F786-4600-AE5E-DE1A847A28BF}\RP275\A0039337.dll</attr>

    <attr name="finding">@EID_Id_trj&lt;/attr>

    <attr name="virusname">Lop.BC</attr>

    </rec>


    </history>
  • edited March 2007
    Hi!


    * Double-click VundoFix.exe to run it.
    * Click the Scan for Vundo button.
    * Then click Add more files
    Copy and insert follow lines in TWO uppers box:

    C:\WINDOWS\system32\vtusr.dll
    C:\WINDOWS\system32\rsutv.*

    * Clikc Add Files and then Click Close Window.
    * When scan is ready, Cklick Remove Vundo.
    * Ansver "yes", when its asking to perform remov
    * After that your desktop disappeared,Its normal.
    * When fix is ready, It inform you to boot comp Click OK.
    * Send C:\vundofix.txt and a Fresh HijackThis log.

    ******************

    You can remove this folder

    C:\VundoFix Backups


    ******************

    Lets clean system restore, INSTRUCTIONS

    ******************

    Panda ActiveScan

    - Once you are on the Panda site, click the Scan your PC button
    - A new window will open...click the Check Now button
    - Enter your Country
    - Enter your State/Province
    - Enter your e-mail address and click send
    - Select either Home User or Company
    - Click the big Scan Now button
    - If it wants to install an ActiveX component allow it
    - It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    - When download is complete, click on Local Disks to start the scan
    - When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Do NOT lose it!

    ******************

    Please, send C:\vundofix.txt and the panda activescan report.
  • edited March 2007
    VundoFix V6.3.16

    Checking Java version...

    Scan started at 5:50:28 PM 3/17/2007

    Listing files found while scanning....

    C:\WINDOWS\system32\opnlmnk.dll
    C:\WINDOWS\system32\rsutv.*
    C:\WINDOWS\system32\vtusr.dll

    Beginning removal...

    Performing Repairs to the registry.
    Done!

    Logfile of HijackThis v1.99.1
    Scan saved at 9:29:41 PM, on 3/17/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\PESTPA~1\PPControl.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\UStorSrv.exe
    C:\Program Files\RALINK\Common\RaUI.exe
    C:\Program Files\palmOne\HOTSYNC.EXE
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Cristian\Desktop\hi\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.averatec.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.averatec.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
    O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [AudCtrl] RunDll32 AudCtrl.dll,RCMonitor
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe"
    O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
    O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.averatec.com
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159157193169
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    Panda

    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt[ad.yieldmanager.com/]
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt[.atdmt.com/]
    Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt[.2o7.net/]
    Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt[.atwola.com/]
    Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt[.casalemedia.com/]
    Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt[.revenue.net/]
    Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Cristian\Application Data\Mozilla\Firefox\Profiles\v6sb4wsw.default\cookies.txt[.casalemedia.com/]
    Virus:Eicar.Mod Not disinfected C:\Program Files\PestPatrol\Help.chm[/HowCanITestDetection.html]
  • edited March 2007
    Download and Save blacklight to your desktop.
    F-Secure Blacklight: https://europe.f-secure.com/blacklight/try.shtml
    Double-click blbeta.exe then accept the agreement.
    click > scan then > next,
    You'll see a list of all items found.
    Don't choose for rename yet! I want to see the log first, because legit items can also be present there...
    There must be also a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers)
    Post the contents of the log in your next reply.
  • edited March 2007
    It did not find anything. I turned off system restore, which deleted all the restore point so the lop.bc that the avg anti-virus was finding in system volume information is gone.
  • edited March 2007
    Hi! I think your comp is clean :)

    Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

    Reenable system restore with instructions from tutorial above
    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
    • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

    • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

    • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

      For a tutorial on Firewalls and a listing of some available ones see the link below:

      Understanding and Using Firewalls

    • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

    • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

      A tutorial on installing & using this product can be found here:

      Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

    • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.

      This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:

      Instructions for - Spybot S & D and Ad-aware

    • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

      A tutorial on installing & using this product can be found here:

      Using SpywareBlaster to protect your computer from Spyware and Malware

    • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
    Follow this list and your potential for being infected again will reduce dramatically.

    Here are some additional utilities that will enhance your safety
    • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
    • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
    • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
    • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
      Using Winpatrol to protect your computer from malicious software

    Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

    The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

    Also, please read this great article by Tony Klein So How Did I Get Infected In First Place

    Happy surfing and stay clean!
Sign In or Register to comment.