logo1_.exe, rundll16.exe and zts2.exe

CalypzeCalypze Stockholm, Sweden
edited August 2007 in Spyware & Virus Removal
Hello.

In my Windows folder the is a folder called logo1_.exe. It appears that there is a trojan that has this name.

I couldn't find any process with that name or similar. However, is this folder dangerous (I would guess so) and should I get rid of it? If so, how?

The folder is (according to Properties) of the size of 0 bytes and it refuses me to open it, even I use administator rights.

There is also two similar folders in the Windows directory called zts2.exe and rundll16.exe. I can enter the first mentioned without problems, but not the last one, same problem as with logo1_.exe.

These are those strange folders I've found, probably there are more.

Please help me with this. Thanks in advance.

Comments

  • edited July 2007
    Hi Calypze
    Welcome to Icrontic Malware Removal Forum.
    My name is peku006 and I will be assisting you.

    Please Click here to download HJTsetup.exe
    * Save HJTsetup.exe to your desktop.
    * Double click on the HJTsetup.exe icon on your desktop.
    * By default it will install to C:\Program Files\Hijack This.
    * Continue to click Next(three times) in the setup dialogue boxes until you get to the Select Additional Tasks dialogue.
    * Put a check by Create a desktop icon then click Next again.
    * Then you will need to click on install
    * At the final dialogue box click Finish and it will launch Hijack This.
    * Click on the Do a system scan and save a log file button. It will scan and then notepad will open up
    * Click file>save as and save it to your desktop
    * Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    * Come back here to this thread and Paste the log in your next reply.
    * DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
  • CalypzeCalypze Stockholm, Sweden
    edited July 2007
    Hello, and thank you :)

    If it is important, the installation didn't exactly took place as you mentioned. Nevertheless, the program was installed without any problems. In any case, here is the log:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:02:45, on 2007-07-19
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\WINDOWS\CTHELPER.EXE
    C:\WINDOWS\System32\CTXFIHLP.EXE
    C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Program Files\Spyware Terminator\Spywareterminatorshield.Exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\SYSTEM32\CTXFISPI.EXE
    C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\hp\kbd\kbd.exe
    C:\Windows\system32\conime.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bitdefender.com/scan8/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=71&bd=Pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=71&bd=Pavilion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=C:\Windows\system32\Userinit.exe
    O1 - Hosts: ::1 localhost
    O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
    O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
    O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
    O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJÄNST')
    O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NÄTVERKSTJÄNST')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
    O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
    O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
    O9 - Extra button: (no name) - {AEF9B8DB-0DEF-4c0b-8209-661C9E82B8C3} - C:\Program Files\WinSysClean 2008 Trial\UDManager\UDManager.exe
    O13 - Gopher Prefix:
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Automatisk LiveUpdate-schemaläggare - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
    O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\System32\ZoneLabs\vsmon.exe

    --
    End of file - 7832 bytes
  • edited July 2007
    Hi Calypze

    I'll need more information from you. Download Deckard's System Scanner (DSS) to your Desktop.

    What DSS will do:
    * create a new System Restore point in Windows XP and Vista.
    * clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
    * check some important areas of your system and produce a report for your analyst to review.
    * DSS automatically runs HijackThis 1.99.1 for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.

    Note: You must be logged onto an account with administrator privileges.

    1. Close all applications and windows.
    2. Double-click on dss.exe to run it, and follow the prompts.
    3. When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt <-this one will be minimized
    4. Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt in your next reply.
    5. Please attach extra.txt to your post.
  • CalypzeCalypze Stockholm, Sweden
    edited July 2007
    I downloaded it and the documents appeared as you said. However, due to that Spyware Terminator blocked some things, I had to inactivate its real-time protection and redo scanning, but now I get only the main.txt document. I even tried to re-download it, but to no avail.

    In any case, here is the content of main.txt:
    Deckard's System Scanner v20070711.54
    Run by Johan on 2007-07-19 at 22:13:26
    Computer is in Normal Mode.



    -- HijackThis (run as Johan.exe)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:13:28, on 2007-07-19
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\WINDOWS\CTHELPER.EXE
    C:\WINDOWS\System32\CTXFIHLP.EXE
    C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Program Files\Spyware Terminator\Spywareterminatorshield.Exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\SYSTEM32\CTXFISPI.EXE
    C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
    C:\Windows\system32\taskeng.exe
    C:\hp\kbd\kbd.exe
    C:\Windows\system32\conime.exe
    C:\Windows\system32\taskeng.exe
    C:\Users\Johan\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\Johan.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bitdefender.com/scan8/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=71&bd=Pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=SV_SE&c=71&bd=Pavilion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=C:\Windows\system32\Userinit.exe
    O1 - Hosts: ::1 localhost
    O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
    O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
    O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
    O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJÄNST')
    O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NÄTVERKSTJÄNST')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
    O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
    O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
    O9 - Extra button: (no name) - {AEF9B8DB-0DEF-4c0b-8209-661C9E82B8C3} - C:\Program Files\WinSysClean 2008 Trial\UDManager\UDManager.exe
    O13 - Gopher Prefix:
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Automatisk LiveUpdate-schemaläggare - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
    O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\System32\ZoneLabs\vsmon.exe

    --
    End of file - 7803 bytes

    -- Files created between 2007-06-19 and 2007-07-19

    2007-07-19 21:02:10 0 d
    C:\Program Files\Trend Micro
    2007-07-16 02:35:54 0 d
    C:\Windows\Registration
    2007-07-15 18:40:48 0 d
    C:\RootkitNO
    2007-07-15 17:05:51 0 d
    C:\Program Files\Microsoft.NET
    2007-07-15 17:03:09 0 d
    C:\Users\All Users\Microsoft Help
    2007-07-15 17:02:21 0 dr-h
    C:\MSOCache
    2007-07-13 19:27:00 0 d
    C:\UDManager Downloads
    2007-07-13 19:26:22 0 d--h
    C:\Users\All Users\{500CC753-0F73-4B22-B56C-0C3CA219E31E}
    2007-07-13 19:26:21 0 d
    C:\Program Files\WinSysClean 2008 Trial
    2007-07-13 18:19:25 0 d
    C:\Program Files\RemoveIT
    2007-07-12 21:04:38 0 -rahs---- C:\MSDOS.SYS
    2007-07-12 21:04:38 0 -rahs---- C:\IO.SYS
    2007-07-11 19:25:34 756736
    n--- C:\Windows\system32\ir41_32.dll <Not Verified; Intel Corporation; Intel Indeo(R) Video Interactive 32-bit Driver>
    2007-07-08 19:14:04 0 d
    C:\Windows\system32\ZoneLabs
    2007-07-08 19:14:04 0 d
    C:\Users\All Users\CheckPoint
    2007-07-08 19:11:29 0 d
    C:\Windows\Internet Logs
    2007-07-05 21:13:00 0 d
    C:\Users\All Users\Age of Empires 3
    2007-07-05 21:11:02 0 d
    C:\Program Files\Common Files\Microsoft Games
    2007-07-02 18:01:21 170 --a
    C:\combo.vbs
    2007-06-27 19:00:17 0 d
    C:\Program Files\SEGA
    2007-06-26 15:38:27 0 d
    C:\Program Files\Common Files\Adobe
    2007-06-26 15:38:23 0 d
    C:\Users\All Users\Adobe
    2007-06-26 15:33:32 0 d
    C:\Users\All Users\Documents
    2007-06-26 14:51:05 0 d
    C:\Program Files\Game_Maker7
    2007-06-24 17:30:19 0 d
    C:\Program Files\Sophos


    -- Find3M Report

    2007-07-19 20:03:05 0 d
    C:\Program Files\Spyware Terminator
    2007-07-19 19:08:18 0 d
    C:\Program Files\WinClamAVShield
    2007-07-19 18:55:10 472176 --a
    C:\Windows\system32\perfh01D.dat
    2007-07-19 18:55:10 81308 --a
    C:\Windows\system32\perfc01D.dat
    2007-07-18 17:52:25 0 d
    C:\Program Files\PC-Doctor 5 for Windows
    2007-07-18 17:52:21 0 d
    C:\Program Files\a-squared Free
    2007-07-18 12:59:18 0 d
    C:\Program Files\SUPERAntiSpyware
    2007-07-18 11:37:12 0 d
    C:\Program Files\Microsoft Games
    2007-07-17 17:11:05 0 d
    C:\Program Files\SpywareBlaster
    2007-07-16 08:34:11 0 d
    C:\Program Files\CCleaner
    2007-07-16 02:27:16 0 d
    C:\Program Files\Microsoft Works
    2007-07-16 02:15:46 0 d
    C:\Program Files\Common Files\Symantec Shared
    2007-07-13 22:35:15 0 d
    C:\Users\Johan\AppData\Roaming\HouseCall 6.6
    2007-07-10 21:54:28 0 d
    C:\Program Files\Windows Mail
    2007-07-05 21:11:17 0 d--h
    C:\Program Files\InstallShield Installation Information
    2007-06-27 18:59:51 0 d
    C:\Users\Johan\AppData\Roaming\InstallShield
    2007-06-26 15:33:38 0 d
    C:\Users\Johan\AppData\Roaming\Adobe
    2007-06-15 21:32:59 0 d
    C:\Users\Johan\AppData\Roaming\dvdcss
    2007-06-15 11:13:00 0 d
    C:\Users\Johan\AppData\Roaming\Real
    2007-06-09 19:03:15 0 --a
    C:\Windows\PowerReg.dat
    2007-06-09 19:00:34 0 d
    C:\Program Files\Infogrames Interactive
    2007-06-09 19:00:23 0 d
    C:\Program Files\Common Files\InstallShield
    2007-06-09 18:28:19 0 d
    C:\Users\Johan\AppData\Roaming\.BitTornado
    2007-06-09 18:25:00 0 d
    C:\Program Files\BitTornado
    2007-06-09 01:02:41 0 d
    C:\Program Files\KeyScrambler
    2007-06-06 23:41:43 0 d
    C:\Users\Johan\AppData\Roaming\SUPERAntiSpyware.com
    2007-06-06 23:40:54 0 d
    C:\Program Files\Common Files\Wise Installation Wizard
    2007-06-06 19:35:03 0 d
    C:\Users\Johan\AppData\Roaming\Application Data
    2007-06-05 19:22:28 77312 --a
    C:\Windows\ua2.dll
    2007-06-05 19:15:44 0 d
    C:\Program Files\Spyware Doctor
    2007-06-05 18:49:29 0 d
    C:\Users\Johan\AppData\Roaming\CleanMyPC Software
    2007-06-05 18:49:20 0 d
    C:\Program Files\CleanMyPC
    2007-06-05 18:20:30 0 d
    C:\Program Files\Security Task Manager
    2007-06-05 08:51:23 0 d
    C:\Users\Johan\AppData\Roaming\vlc
    2007-06-05 08:50:29 0 d
    C:\Program Files\VideoLAN
    2007-06-05 08:35:13 0 d
    C:\Users\Johan\AppData\Roaming\WinPatrol
    2007-06-05 08:35:08 0 d
    C:\Program Files\BillP Studios
    2007-06-04 22:16:45 0 d
    C:\Program Files\MSN Messenger
    2007-06-04 17:27:05 0 d
    C:\Users\Johan\AppData\Roaming\Europa Barbarorum
    2007-06-04 17:07:09 0 d
    C:\Program Files\Activision
    2007-06-04 15:37:39 0 d
    C:\Program Files\IObit
    2007-06-04 15:35:52 0 d
    C:\Users\Johan\AppData\Roaming\Lavasoft
    2007-06-04 15:35:44 0 d
    C:\Program Files\Lavasoft
    2007-06-04 15:03:00 0 d
    C:\Users\Johan\AppData\Roaming\Mozilla
    2007-06-04 14:46:42 0 d
    C:\Program Files\Windows Defender
    2007-06-04 14:46:01 0 d
    C:\Program Files\Google
    2007-06-04 14:41:50 0 d
    C:\Program Files\MSXML 4.0
    2007-06-04 14:36:58 0 d
    C:\Users\Johan\AppData\Roaming\Google
    2007-06-04 14:33:28 0 d
    C:\Program Files\Belkin
    2007-06-04 14:28:45 0 d
    C:\Users\Johan\AppData\Roaming\AdobeUM
    2007-06-04 14:15:17 0 d
    C:\Users\Johan\AppData\Roaming\Identities
    2007-06-04 14:14:06 0 d
    C:\Users\Johan\AppData\Roaming\Macromedia
    2007-06-04 14:11:21 0 d
    C:\Users\Johan\AppData\Roaming\Hewlett-Packard
    2007-06-04 14:06:06 0 d
    C:\Program Files\Windows NT
    2007-06-04 14:06:06 0 d--hs---- C:\Program Files\Delade filer


    -- Registry Dump

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
    {2B9F5787-88A5-4945-90E7-C4B18563BC5E} C:\Program Files\KeyScrambler\keyscramblerIE.dll
    {53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    {AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar2.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "Windows Defender"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,57,69,\
    "hpsysdrv"="c:\\hp\\support\\hpsysdrv.exe"
    "KBD"="C:\\HP\\KBD\\KbdStub.EXE"
    "OsdMaestro"="\"C:\\Program Files\\Hewlett-Packard\\On-Screen OSD Indicator\\OSD.exe\""
    "NvSvc"="RUNDLL32.EXE C:\\Windows\\system32\\nvsvc.dll,nvsvcStart"
    "NvCplDaemon"="RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup"
    "NvMediaCenter"="RUNDLL32.EXE C:\\Windows\\system32\\NvMcTray.dll,NvTaskbarInit"
    "CTHelper"="CTHELPER.EXE"
    "CTxfiHlp"="CTXFIHLP.EXE"
    "VolPanel"="\"C:\\Program Files\\Creative\\Sound Blaster X-Fi\\Volume Panel\\VolPanlu.exe\" /r"
    "CTXFIREG"="CTxfiReg.exe"
    "HP Software Update"="c:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
    "avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
    "WinPatrol"="C:\\Program Files\\BillP Studios\\WinPatrol\\winpatrol.exe"
    "SpywareTerminator"="\"C:\\Program Files\\Spyware Terminator\\SpywareTerminatorShield.exe\""
    "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter"
    "Sidebar"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\OsdMaestro]
    "ModelName"="5189URF"
    "Version"="1.00.004"
    "Language"=dword:0000001c
    "KeyboardID"=dword:00000000
    "MouseID"=dword:00000000
    "KeyboardSID"=dword:00000000
    "MouseSID"=dword:00000000
    "RxSecret"=dword:00000000
    "RMenuSel"=dword:00000000
    "KeyboardBat"=dword:00000000
    "MouseBat"=dword:00000000
    "KeyboardCh"=dword:00000000
    "MouseCh"=dword:00000000
    "FilterLMouse"=dword:00000000
    "FilterRMouse"=dword:00000000

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\OsdMaestro\Config]
    "DisplayLabel"=dword:00000000
    "TaskbarIcon"=dword:00000001
    "F091"="0Q;my music"
    "L091"="Min musik"
    "F090"="0P;my pictures"
    "L090"="Mina bilder"
    "F089"="0J;joystick on"
    "L089"="Stryspak P?"
    "F088"="0J;joystick off"
    "L088"="Styrspak AV"
    "F087"="F;next track"
    "L087"="5:e + Hjul ner"
    "F086"="G;previous track"
    "L086"="5:e + Hjul upp"
    "F085"="E;stop"
    "L085"="Dubbelklicka p?5:e knapp"
    "F084"="0H;mouse fifth button"
    "L084"="Musens 5:e knapp"
    "F083"="C;volume down"
    "L083"="4:e + Hjul ner"
    "F082"="B;volume up"
    "L082"="4:e + Hjul upp"
    "F081"="D;play"
    "L081"="Dubbelklicka p?4:e knapp"
    "F080"="0G;mouse fourth button"
    "L080"="Musens 4:e knapp"
    "F079"="0F;scroll right"
    "L079"="Mitten + Hjul ner"
    "F078"="0E;scroll left"
    "L078"="Mitten + Hjul upp"
    "F077"="J;www(AC)"
    "L077"="Dubbelklicka p?mittknapp"
    "F076"="0I;quick jump"
    "L076"="Musens mittknapp"
    "F075"="0F;scroll right"
    "L075"="Mitten + Höger"
    "F074"="0E;scroll left"
    "L074"="Mitten + Vänster"
    "F073"="m;scroll down"
    "L073"="Rullningshjul ner"
    "F072"="l;scroll up"
    "L072"="Rullningshjul upp"
    "F071"="0I;quick jump"
    "L071"="Snabbhoppa"
    "F070"="0F;scroll right"
    "L070"="Rulla höger"
    "F069"="0E;scroll left"
    "L069"="Rulla vänster"
    "F068"="0D:set SID final"
    "L068"="Ställ in SID Sista"
    "F067"="0C:paint"
    "L067"="Paint"
    "F066"="0B;mouse middle button"
    "L066"="Musens mittknapp"
    "F065"="0A;europe dollar(OF)"
    "L065"="Europa Dollar"
    "F064"="0-;reply all(OF)"
    "L064"="Svara alla"
    "F063"="09;eject 2"
    "L063"="Mata ut/Stäng 2"
    "F062"="08:help(OF)"
    "L062"="Hjälp"
    "F061"="07;redo(OF)"
    "L061"="Gör om"
    "F060"="06;undo(OF)"
    "L060"="Ångra"
    "F059"="05;task pane(OF)"
    "L059"="Aktivitetsfält"
    "F058"="04;send(OF)"
    "L058"="Skicka"
    "F057"="03;f'ward(OF)"
    "L057"="Framåt"
    "F056"="02;reply(OF)"
    "L056"="Svara"
    "F055"="01;bullets(OF)"
    "L055"="Punkter"
    "F054"="00;spell(OF)"
    "L054"="Stavning"
    "F053"="z;bold(OF)"
    "L053"="Fetstil"
    "F052"="y;replace(OF)"
    "L052"="Ersätt"
    "F051"="x;save(OF)"
    "L051"="Spara"
    "F050"="w;open(OF)"
    "L050"="Öppna"
    "F049"="v;new(OF)"
    "L049"="Nytt"
    "F048"="u;copy(OF)"
    "L048"="Kopiera"
    "F047"="t;cut(OF)"
    "L047"="Klipp ut"
    "F046"="s;mark(OF)"
    "L046"="Markera"
    "F045"="r;paste(OF)"
    "L045"="Klistra in"
    "F044"="q;calendar(OF)"
    "L044"="Kalender"
    "F043"="p;power point(OF)"
    "L043"="Power Point"
    "F042"="o;excel(OF)"
    "L042"="Excel"
    "F041"="n;word(OF)"
    "L041"="Word"
    "F040"="m;scroll down"
    "L040"="Rulla ner"
    "F039"="l;scroll up"
    "L039"="Rulla upp"
    "F038"="k;Configure"
    "L038"="Konfigurera"
    "F037"="j;keyboard and mouse battery low"
    "L037"="Svagt batteri i tangentbord och mus"
    "F036"="i;mouse battery low"
    "L036"="Svagt musbatteri"
    "F035"="h;keyboard battery low"
    "L035"="Svagt tangentbordsbatteri"
    "F034"="g;keyboard and mouse battery OK"
    "L034"=""
    "F033"="f:wake up"
    "L033"="Vakna"
    "F032"="e:sleep"
    "L032"="Vila"
    "F031"="d;power off"
    "L031"="Ström av"
    "F030"="c;mf"
    "L030"="F-Lås"
    "F029"="b;app. close"
    "L029"="Prog. Stäng"
    "F028"="a;app. switch"
    "L028"="Prog. Växla"
    "F027"="Z;log off"
    "L027"="Logga ut"
    "F026"="Y;my computer"
    "L026"="Den här datorn"
    "F025"="X;refresh(AC)"
    "L025"="www Uppdatera"
    "F024"="W;print(OF)"
    "L024"="Skriv ut"
    "F023"="V;notepad"
    "L023"="Anteckningar"
    "F022"="U;explorer"
    "L022"="Utforskaren"
    "F021"="T;mediaplayer"
    "L021"="Mediaspelare"
    "F020"="S;my documents"
    "L020"="Mina dokument"
    "F019"="R;calculator"
    "L019"="Kalkylator"
    "F018"="Q;help(manual)"
    "L018"="OsdMaestro-hjälp"
    "F017"="P;help(OS)"
    "L017"="OS-hjälp"
    "F016"="O;favorite(AC)"
    "L016"="www Favorit"
    "F015"="N;search(AC)"
    "L015"="www Sök"
    "F014"="M;forward(AC)"
    "L014"="www Framåt"
    "F013"="L;back(AC)"
    "L013"="www Bakåt"
    "F012"="K;stop(AC)"
    "L012"="www Stopp"
    "F011"="J;www(AC)"
    "L011"="www"
    "F010"="I;email(AL)"
    "L010"="E-post"
    "F009"="H;eject"
    "L009"="Mata ut/Stäng"
    "F008"="G;previous track"
    "L008"="Föregående spår"
    "F007"="F;next track"
    "L007"="Nästa spår"
    "F006"="E;stop"
    "L006"="Stopp"
    "F005"="D;play"
    "L005"="Spela/Paus"
    "F004"="C;volume down"
    "L004"="Volym ner"
    "F003"="B;volume up"
    "L003"="Volym upp"
    "F002"="A;mute"
    "L002"="Ljud av"
    "F001"="-;none"
    "L001"="Ingen"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\ApprovedByRegRun2]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\ApprovedByRegRun2\AntiRepl]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\ApprovedByRegRun2\AntiRepl\0]
    "Operation"=dword:00000001
    "Target"="\\??\\C:\\PROGRAM FILES\\PREVX2\\PXVISTASVC.EXE"
    "Source"=""

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\ApprovedByRegRun2\AntiRepl\1]
    "Operation"=dword:00000001
    "Target"="C:\\PROGRAM FILES\\COMMON FILES\\EACCELERATION\\EACSVC.EXE"
    "Source"=""

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
    "SetDefaultMIDI"="MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy'"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"=dword:00000002
    "ConsentPromptBehaviorUser"=dword:00000001
    "EnableInstallerDetection"=dword:00000001
    "EnableLUA"=dword:00000001
    "EnableSecureUIAPaths"=dword:00000001
    "EnableVirtualization"=dword:00000001
    "PromptOnSecureDesktop"=dword:00000001
    "ValidateAdminCodeSignatures"=dword:00000000
    "scforceoption"=dword:00000000
    "FilterAdministratorToken"=dword:00000000

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system\UIPI]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system\UIPI\Clipboard]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system\UIPI\Clipboard\ExceptionFormats]
    "CF_TEXT"=dword:00000001
    "CF_BITMAP"=dword:00000002
    "CF_OEMTEXT"=dword:00000007
    "CF_DIB"=dword:00000008
    "CF_PALETTE"=dword:00000009
    "CF_UNICODETEXT"=dword:0000000d
    "CF_DIBV5"=dword:00000011

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
    Notification Packages REG_MULTI_SZ scecli\0\0
    Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0tspkg\0\0
    Authentication Packages REG_MULTI_SZ msv1_0\0\0

    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AppInfo
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\KeyIso
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\NTDS
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\ProfSvc
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sacsvr
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\SWPRV
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\TabletInputService
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\TBS
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\TrustedInstaller
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\volmgr.sys
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\volmgrx.sys
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    LocalService REG_MULTI_SZ nsi\0lltdsvc\0SSDPSRV\0upnphost\0SCardSvr\0w32time\0EventSystem\0RemoteRegistry\0WinHttpAutoProxySvc\0lanmanworkstation\0TBS\0SLUINotify\0THREADORDER\0fdrespub\0netprofm\0fdphost\0wcncsvc\0QWAVE\0Mcx2Svc\0WebClient\0\0
    LocalSystemNetworkRestricted REG_MULTI_SZ hidserv\0UxSms\0WdiSystemHost\0Netman\0trkwks\0AudioEndpointBuilder\0WUDFSvc\0irmon\0sysmain\0IPBusEnum\0dot3svc\0PcaSvc\0EMDMgmt\0TabletInputService\0wlansvc\0WPDBusEnum\0\0
    NetworkServiceNetworkRestricted REG_MULTI_SZ PolicyAgent\0\0
    LocalServiceNoNetwork REG_MULTI_SZ PLA\0DPS\0BFE\0mpssvc\0ehstart\0\0
    NetworkService REG_MULTI_SZ CryptSvc\0DHCP\0TermService\0KtmRm\0DNSCache\0NapAgent\0nlasvc\0WinRM\0WECSVC\0Tapisrv\0\0
    termsvcs REG_MULTI_SZ TermService\0\0
    WerSvcGroup REG_MULTI_SZ wersvc\0\0
    swprv REG_MULTI_SZ swprv\0\0
    LocalServiceNetworkRestricted REG_MULTI_SZ DHCP\0eventlog\0AudioSrv\0LmHosts\0wscsvc\0p2pimsvc\0PNRPSvc\0p2psvc\0WPCSvc\0PnrpAutoReg\0\0
    rpcss REG_MULTI_SZ RpcSs\0\0
    regsvc REG_MULTI_SZ RemoteRegistry\0\0
    wcssvc REG_MULTI_SZ WcsPlugInService\0\0
    DcomLaunch REG_MULTI_SZ PlugPlay\0DcomLaunch\0\0
    wdisvc REG_MULTI_SZ WdiServiceHost\0\0
    sdrsvc REG_MULTI_SZ sdrsvc\0\0
    imgsvc REG_MULTI_SZ StiSvc\0\0
    secsvcs REG_MULTI_SZ WinDefend\0\0

    hklm\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
    AeLookupSvc
    wercplsupport
    CertPropSvc
    SCPolicySvc
    gpsvc
    IKEEXT
    LogonHours
    PCAudit
    iphlpsvc
    AppInfo
    msiscsi
    MMCSS
    ProfSvc
    EapHost
    SessionEnv
    hkmsvc


    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0267c91b-139d-11dc-9d20-00173f51895d}]
    shell\adobe\command F:\goodies\ar405eng.exe
    shell\AutoRun\command F:\aocsetup.exe /autorun
    shell\log\command F:\goodies\machine\machine.exe -l
    shell\machine\command F:\goodies\machine\machine.exe
    shell\setup\command F:\aocsetup.exe /autorun
    shell\zone\command F:\goodies\mszone\zonea660.exe


    -- End of Deckard's System Scanner: finished at 2007-07-19 at 22:13:45
  • edited July 2007
    Hi Calypze

    Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then start to download the latest definition files.
    • Once the scanner is installed and the definitions downloaded, click Next.
    • Now click on Scan Settings
    • In the scan settings make sure that the following are selected:

      o Scan using the following Anti-Virus database:

      + Extended (If available otherwise Standard)

      o Scan Options:

      + Scan Archives
      + Scan Mail Bases
    • Click OK
    • Now under select a target to scan select My Computer
    • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button
    • Save the file to your desktop.
    • Copy and paste that information in your next post.
    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
  • CalypzeCalypze Stockholm, Sweden
    edited July 2007
    Ok, here is the report (it is quite long). It is quite bothersome that it didn't find anything. I've suspected for a long while that something isn't alright with the computer, and then these nonsensial and suspect folders.

    The forum refuses me to post in this post, so I'll have to attach the document. I hope you don't mind.
  • edited July 2007
    Hi Calypze
    Not seeing anything Suspicious in your Logfiles.
    Your comp looks clean.
    You can delete these files (logo1_.exe.,zts2.exe.and rundll16.exe. if present)
    Did you try changing the ownership of the file ?
    Make sure to change the ownership of the file and also select the option to change the ownership of everything inside that folder
    take ownership of the file
  • CalypzeCalypze Stockholm, Sweden
    edited July 2007
    Ok thank you.

    I searched on Google and found some stuff: http://forums.spywareinfo.com/lofiversion/index.php/t96388.html

    It appears that MWAV eScan creates those folders is some odd attempt to prevent the malware with the same name from taking root. Do you think this could be the case here as well?
  • edited July 2007
    Hi Calypze
    I am not sure
    Let us take a deeper look.

    Please make sure that you can view all hidden files. Instructions on how to do this can be found here:
    How to see hidden files in Windows

    Please click this link-->Jotti
    When the jotti page has finished loading, click the Browse button and navigate to the following file and click Submit.
    (filepath)logo1_.exe.
    Do the same for the following Files: zts2.exe ,and rundll16.exe
    Please post back the results of the scan in your next post.
    If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/flash/index_en.html
  • CalypzeCalypze Stockholm, Sweden
    edited July 2007
    I tried to upload them, but as they are folders (and at the size of 0 KB), I wasn't allowed to upload them.
  • edited July 2007
    Hi Calypze
    You can delete these folders (logo1_.exe.,zts2.exe.and rundll16.exe. if present)
  • CalypzeCalypze Stockholm, Sweden
    edited July 2007
    Ok, thanks.

    So it is fine I guess. I mean, are the earlier logs ok?

    And I have a general question about the Kaspersky Online Scanner: When I run it, should I run IE as an administrator or not (keep in mind that I have Vista)?
  • edited July 2007
    Hi Calypze
    Sorry about the delay in responding
    I'm not seeing anything malicious in your logs
    Your comp looks clean.
    And I have a general question about the Kaspersky Online Scanner: When I run it, should I run IE as an administrator or not (keep in mind that I have Vista)?
    what says Kaspersky Online Virus Scanner if you run that?

    Requirements and limitations:

    When using this service for the first time, you have to run with Administrator privileges in order to install the product. Also, you will need to download and install files about 400 KB in size
  • CalypzeCalypze Stockholm, Sweden
    edited August 2007
    Hello again.

    Can I ask one more question before we consider this thread resolved? It's a rather dumb question, but better safe than sorry:

    Does the "extended" definitions include the "standard" definitions for scanning? Or do I have to make another scan using the "standard" definitions to be able to find that suff as well?
  • edited August 2007
    Hi Calypze
    Does the "extended" definitions include the "standard" definitions for scanning?
    YES
    Configuration

    Before selecting a target you can configure the scan settings. This is done by pressing the "Scan Settings" button in Target Selection frame. The following settings can be configured:

    Scan using standard antivirus database: standard antivirus databases solution protects you from all viruses, Internet worms, Trojans and other malicious programs

    Scan using extended antivirus database: this database identifies several types of ads and related programs and also contains texts identifying various pornographic sites: programs that auto-dial porn sites and programs for auto download of files containing explicit materials. This option is primarily for use by experienced users. We do not recommend this option to beginners or inexperienced users.
    Scan Archives - scan files inside archives
    Scan Mail Bases - scan e-mails/attachments inside mail base files
  • CalypzeCalypze Stockholm, Sweden
    edited August 2007
    Hello again.

    I'm not sure wether I should start a new thread for this or continue in this, I continue in this because this is still recent, and it is in part connected to this thread.

    Today I made a scan with the Kaspersky Online Scanner. It detected dss.exe, the file you told me to download earlier, as being infected with IM-Worm.Win32.Sohanad.aw. It has never done so before. Do you think it is a false positive? Or could the file really be infected by that worm? I uploaded the file to Jotti as well, and there both Kaspersky and F-Secure detected is as that worm. What shoud I do?

    About the worm, from Kaspersky: http://www.viruslist.com/en/viruses/encyclopedia?virusid=161634
  • edited August 2007
    Hi Calypze
    Sorry about the delay in responding
    Please do the following...
    Please Print out these instructions or copy them to a NotePad file so they will be accessible


    Please download DrWeb-CureIt & save it to your desktop. DO NOT perform a scan yet.
    Reboot your computer in "SAFE MODE" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".
    Scan with DrWeb-CureIt as follows:
    * Double-click on drweb-cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
    * Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
    * Once the short scan has finished, Click Options > Change settings
    * Choose the "Scan tab" and UNcheck "Heuristic analysis"
    * Back at the main window, click "Select drives" (a red dot will show which drives have been chosen)
    * Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
    * When done, a message will be displayed at the bottom advising if any viruses were found.
    * Click "Yes to all" if it asks if you want to cure/move the file.
    * When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
    (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
    * Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
    * Save the DrWeb.csv report to your desktop.
    * Exit Dr.Web Cureit when done.
    * Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    * After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
  • CalypzeCalypze Stockholm, Sweden
    edited August 2007
    Thanks for the help, and here is the conent of the report:
    Current Home Page_HKCU.reg;C:\Documents and Settings\Johan\Documents\RegRun2\back16d_07m_07y_012747;Trojan.StartPage.1505;Deleted.;
    Current Home Page_HKCU.reg;C:\Documents and Settings\Johan\Documents\RegRun2\back16d_07m_07y_012801;Trojan.StartPage.1505;Deleted.;
    Current Home Page_HKCU.reg;C:\Documents and Settings\Johan\Documents\RegRun2\back16d_07m_07y_012810;Trojan.StartPage.1505;Deleted.;
    Current Home Page_HKCU.reg;C:\Documents and Settings\Johan\Documents\RegRun2\back16d_07m_07y_012821;Trojan.StartPage.1505;Deleted.;
    Nice program btw. I didn't expect that Kaspersky would miss stuff that this would pick up.

    If this is of any interest, the progress of the program didn't work out exactly as in your post. When it found the first thing, a notice appeared immediately, asking me if I wanted to remove/cure it, and I selected "Yes to all", so that it would remove potential other malwares without prompt. As for the dss.exe file, I removed it after the Kaspersky scanner had finished, because I could stand having a potential malware right in my face. Again, I don't know if this information is of any value, but I'm telling you just in case.
  • edited August 2007

    Glad I could be of assistance! The help you received here was free. Please read through some of these Prevention Tips that Short-Media offers.

    This topic is now closed. If you wish it reopened, please send a Private Message (PM) to one of the Spyware Mods with a link to your thread.

    Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required.

    If you are not the user who started this thread, you must start a new Thread instead :)

    Would you also be interested to join Short-Media (Team #93) with the Folding@Home Project? More information available here
Sign In or Register to comment.