HELP! W32/Virut.gen and W32/Cholera

edited December 2007 in Spyware & Virus Removal
My pc is getting out of control. Please help. Here's the log:
Logfile of HijackThis v1.99.1
Scan saved at 1:11:13 AM, on 12/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\update.exe
c:\program files\mcafee.com\vso\mcmnhdlr.exe
c:\program files\mcafee.com\shared\mghtml.exe
C:\Documents and Settings\End User\Desktop\hijackthis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system\svchost.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [EPSON Stylus C59 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBHP.EXE /FU "C:\WINDOWS\TEMP\E_SB3.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB004" /M "Stylus C45"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo R230 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P30 "EPSON Stylus Photo R230 Series" /O6 "USB007" /M "Stylus Photo R230"
O4 - HKLM\..\Run: [EPSON Stylus Photo R230 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P39 "EPSON Stylus Photo R230 Series (Copy 1)" /O6 "USB008" /M "Stylus Photo R230"
O4 - HKLM\..\Run: [EPSON Stylus Photo R230 Series (Copy 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P39 "EPSON Stylus Photo R230 Series (Copy 2)" /O6 "USB009" /M "Stylus Photo R230"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

It's very urgent. Please prioritize. Thanks.

Comments

  • ScottyScotty Haggistown, Kiltland
    edited December 2007
    Hi! Welcome to the Icrontic forums.
    My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.

    Please be patient as my posts to you have to be checked before I reply, so they make take longer.

    Please make a uninstall list using HijackThis
    To access the Uninstall Manager you would do the following:

    1. Start HijackThis
    2. Click on the Config button
    3. Click on the Misc Tools button
    4. Click on the Open Uninstall Manager button.
    5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
  • ScottyScotty Haggistown, Kiltland
    edited December 2007
    Hi again

    Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then start to download the latest definition files.
    • Once the scanner is installed and the definitions downloaded, click Next.
    • Now click on Scan Settings
    • In the scan settings make sure that the following are selected:
      • Scan using the following Anti-Virus database:
        + Extended(If available otherwise Standard)
      • Scan Options:
        + Scan Archives
        + Scan Mail Bases
    • Click OK
    • Now under select a target to scan select C:\Windows
    • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button
    • Save the file to your desktop.
    • Copy and paste that information in your next post.
    With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete.
  • edited December 2007

    KASPERSKY ONLINE SCANNER REPORT
    Saturday, December 08, 2007 9:15:26 PM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 9/12/2007
    Kaspersky Anti-Virus database records: 477517

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    C:\
    D:\
    E:\

    Scan Statistics:
    Total number of scanned objects: 28663
    Number of viruses found: 1
    Number of infected objects: 65
    Number of suspicious objects: 0
    Duration of the scan process: 01:19:56

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd000.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    C:\Documents and Settings\End User\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\End User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\End User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\End User\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\End User\Local Settings\Temp\~DFA734.tmp Object is locked skipped
    C:\Documents and Settings\End User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\End User\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\End User\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\67Z975FV\unpr[1].exe/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\67Z975FV\unpr[1].exe Embedded EXE: infected - 1 skipped
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QOJKI7KL\unpr[1].exe/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QOJKI7KL\unpr[1].exe Embedded EXE: infected - 1 skipped
    C:\WINDOWS\system32\unpr.sys Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\Temp\VRR1.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR1.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR10.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR10.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR11.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR11.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR12.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR12.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR13.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR13.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR14.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR14.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR15.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR15.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR16.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR16.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR17.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR17.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR2.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR2.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR28.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR28.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR3.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR3.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR4.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR4.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR4A.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR4A.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR4B.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR4B.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR4C.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR4C.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR4D.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR4D.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR5.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR5.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR55.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR55.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR6.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR6.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR7.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR7.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR8.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR8.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRR9.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRR9.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRRA.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRRA.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRRAD.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRRAD.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRRB.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRRB.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRRC.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRRC.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRRD.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRRD.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRRE.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRRE.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\Temp\VRRF.tmp/EXE-file Infected: Trojan.Win32.KillAV.cn skipped
    C:\WINDOWS\Temp\VRRF.tmp Embedded EXE: infected - 1 skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.
    Adobe Bridge 1.0
    Adobe Common File Installer
    Adobe Flash Player ActiveX
    Adobe Flash Player Plugin
    Adobe Help Center 1.0
    Adobe Photoshop CS2
    Adobe Stock Photos 1.0
    Avira AntiVir PersonalEdition Classic
    Azureus
    EPSON Attach To Email
    EPSON Easy Photo Print
    EPSON File Manager
    EPSON Print CD
    EPSON Printer Software
    EPSON Scan Assistant
    EPSON Web-To-Page
    ESPR230 User's Guide
    HijackThis 1.99.1
    Java(TM) 6 Update 3
    Kaspersky Online Scanner
    LimeWire 4.14.10
    McAfee SecurityCenter
    McAfee VirusScan
    Mozilla Firefox (2.0.0.11)
    PIF DESIGNER
    PowerISO
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB939653)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB943460)
    SSC Service Utility v4.30
    Update for Windows XP (KB894391)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB908531)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB933360)
    Update for Windows XP (KB936357)
    Update for Windows XP (KB938828)
    Windows Installer 3.1 (KB893803)
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    Yahoo! Messenger
    Yahoo! Toolbar
  • ScottyScotty Haggistown, Kiltland
    edited December 2007
    Hello

    You are operating your computer with multiple Anti Virus programs running in memory at once:
    McAfee & AntiVir

    Anti-virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash.

    If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

    There are basically two types of these programs:
    On-Access and On-Demand

    On-Access Scanners
    As the name implies, it runs in the background all the time the PC is turned on and running. The main function of an on-access scanner is to monitor activity on your machine.

    On-Demand Scanners
    As the name implies, are scanners that only run when you ask them to.
    Such as:
    Online Scans and scanners that run on your machine but are not actively scanning your machine.

    Please disable one or the other so they do not conflict then post a new HijackThis log to show this has been done.
  • edited December 2007
    here you go...
    Adobe Bridge 1.0
    Adobe Common File Installer
    Adobe Flash Player ActiveX
    Adobe Flash Player Plugin
    Adobe Help Center 1.0
    Adobe Photoshop CS2
    Adobe Stock Photos 1.0
    Azureus
    EPSON Attach To Email
    EPSON Easy Photo Print
    EPSON File Manager
    EPSON Print CD
    EPSON Printer Software
    EPSON Scan Assistant
    EPSON Web-To-Page
    ESPR230 User's Guide
    HijackThis 1.99.1
    Java(TM) 6 Update 3
    Kaspersky Online Scanner
    LimeWire 4.14.10
    McAfee SecurityCenter
    McAfee VirusScan
    Mozilla Firefox (2.0.0.11)
    PIF DESIGNER
    PowerISO
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB939653)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB943460)
    SSC Service Utility v4.30
    Update for Windows XP (KB894391)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB908531)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB933360)
    Update for Windows XP (KB936357)
    Update for Windows XP (KB938828)
    Windows Installer 3.1 (KB893803)
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    Yahoo! Messenger
    Yahoo! Toolbar
    Logfile of HijackThis v1.99.1
    Scan saved at 7:42:20 PM, on 12/9/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\notepad.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Documents and Settings\End User\Desktop\hijackthis\HijackThis.exe
    C:\WINDOWS\system32\notepad.exe

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system\svchost.exe
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [EPSON Stylus C59 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBHP.EXE /FU "C:\WINDOWS\TEMP\E_SB3.tmp" /EF "HKLM"
    O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB004" /M "Stylus C45"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [EPSON Stylus Photo R230 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P30 "EPSON Stylus Photo R230 Series" /O6 "USB007" /M "Stylus Photo R230"
    O4 - HKLM\..\Run: [EPSON Stylus Photo R230 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P39 "EPSON Stylus Photo R230 Series (Copy 1)" /O6 "USB008" /M "Stylus Photo R230"
    O4 - HKLM\..\Run: [EPSON Stylus Photo R230 Series (Copy 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P39 "EPSON Stylus Photo R230 Series (Copy 2)" /O6 "USB009" /M "Stylus Photo R230"
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
  • ScottyScotty Haggistown, Kiltland
    edited December 2007
    Hello

    Download and Save ComboFix
    • Download this file from below:

      Here
      or
      Here
    • Save it to your Desktop.
    • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
    • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
    • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
    Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
    Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.

    In your next reply post:
    ComboFix.txt
    New HijackThis log taken after the above scan has run
  • edited December 2007
    Here are the items you've requested:
    ComboFix 07-12-09.1 - End User 2007-12-12 18:42:38.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.115 [GMT -8:00]
    Running from: C:\Documents and Settings\End User\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((( Files Created from 2007-11-13 to 2007-12-13 )))))))))))))))))))))))))))))))
    .

    2007-12-07 01:53 . 2007-12-07 01:53 <DIR> d
    C:\WINDOWS\system32\Kaspersky Lab
    2007-12-07 01:53 . 2007-12-07 01:53 <DIR> d
    C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2007-12-07 00:26 . 2007-12-07 00:26 <DIR> d
    C:\Documents and Settings\End User\Application Data\Yahoo!
    2007-12-07 00:26 . 2007-12-07 00:26 <DIR> d
    C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2007-12-06 02:13 . 2007-12-06 02:13 <DIR> d
    C:\Documents and Settings\End User\DoctorWeb
    2007-12-06 01:59 . 2007-12-06 01:59 <DIR> d
    C:\KAV
    2007-12-06 00:50 . 2007-12-10 18:51 <DIR> d
    C:\Documents and Settings\All Users\Application Data\Avira
    2007-12-05 02:22 . 2007-12-05 02:22 <DIR> d
    C:\Documents and Settings\All Users\Application Data\Yahoo!
    2007-12-05 01:59 . 2007-12-05 02:09 <DIR> d
    C:\Program Files\Yahoo!
    2007-12-04 20:40 . 2005-08-10 11:22 114,464 --a
    C:\WINDOWS\system32\drivers\naiavf5x.sys
    2007-12-04 01:35 . 2007-12-04 01:50 <DIR> d
    C:\Program Files\McAfee.com
    2007-12-04 01:35 . 2007-12-04 20:35 <DIR> d
    C:\Documents and Settings\All Users\Application Data\McAfee.com
    2007-12-04 01:35 . 2005-10-18 11:08 349,760 --a
    C:\WINDOWS\system32\mcinsctl.dll
    2007-12-04 01:35 . 2005-05-24 19:23 288,320 --a
    C:\WINDOWS\system32\McGDMgr.dll
    2007-12-03 22:12 . 2007-12-03 22:12 2,432
    C:\WINDOWS\system32\unpr.sys
    2007-12-02 22:03 . 2007-12-02 22:03 3,560,059 --a
    C:\IvanTsang.psd
    2007-12-01 23:27 . 2007-12-01 23:27 <DIR> d
    C:\WINDOWS\Sun
    2007-12-01 22:52 . 2007-12-01 22:52 1,854,629 --a
    C:\diret model.psd
    2007-11-26 23:18 . 2007-11-26 23:22 <DIR> d
    C:\misc documents
    2007-11-26 21:21 . 2007-12-10 20:11 7,680 --ahs---- C:\WINDOWS\Thumbs.db
    2007-11-26 01:55 . 2007-11-26 01:55 <DIR> d
    C:\Program Files\uTorrent
    2007-11-26 01:54 . 2007-12-12 18:41 <DIR> d
    C:\Documents and Settings\End User\Application Data\uTorrent
    2007-11-23 00:50 . 2007-11-25 00:46 <DIR> d
    C:\Shared
    2007-11-23 00:50 . 2007-11-25 03:08 <DIR> d
    C:\Incomplete
    2007-11-23 00:50 . 2007-11-23 00:50 <DIR> d
    C:\Documents and Settings\End User\Incomplete
    2007-11-23 00:50 . 2007-11-25 00:46 <DIR> d
    C:\Documents and Settings\End User\Application Data\LimeWire
    2007-11-20 16:23 . 2007-11-20 16:24 <DIR> d
    C:\Program Files\EPSON Print CD
    2007-11-20 16:21 . 2007-11-20 16:33 <DIR> d
    C:\Documents and Settings\All Users\Application Data\UDL
    2007-11-20 16:18 . 2007-11-20 16:36 <DIR> d
    C:\Program Files\Common Files\InstallShield
    2007-11-20 16:17 . 2004-11-25 04:07 79,679 --a
    C:\WINDOWS\system32\E_FLMAIP.DLL
    2007-11-20 16:17 . 2003-05-21 01:27 64,000 --a
    C:\WINDOWS\system32\E_FBCBAIP.DLL
    2007-11-20 16:17 . 2000-06-07 00:01 34,304 --a
    C:\WINDOWS\system32\E_FBCHAIP.DLL
    2007-11-20 16:13 . 2007-11-20 16:13 25 --a
    C:\WINDOWS\CDER230.ini
    2007-11-20 16:10 . 2007-11-20 16:11 13,096,620 --a
    C:\z31.psd
    2007-11-19 16:22 . 2004-08-03 23:08 31,616 --a
    C:\WINDOWS\system32\drivers\usbccgp.sys
    2007-11-19 16:22 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
    2007-11-19 15:10 . 2007-11-22 22:14 <DIR> d
    C:\Program Files\Guitar Pro 5
    2007-11-19 14:59 . 2007-11-19 14:59 <DIR> d
    C:\Program Files\PowerISO
    2007-11-18 11:05 . 2007-11-19 15:08 <DIR> d
    C:\Documents and Settings\End User\Application Data\Azureus
    2007-11-18 11:04 . 2007-09-24 23:31 69,632 --a
    C:\WINDOWS\system32\javacpl.cpl
    2007-11-18 11:03 . 2007-11-18 11:04 <DIR> d
    C:\Program Files\Java
    2007-11-18 11:02 . 2007-11-18 11:02 <DIR> d
    C:\Program Files\Common Files\Java
    2007-11-18 11:01 . 2007-12-04 20:34 1,482 --a
    C:\WINDOWS\mozver.dat
    2007-11-18 10:58 . 2007-11-19 15:08 <DIR> d
    C:\Program Files\Azureus
    2007-11-13 14:48 . 2007-11-14 10:46 <DIR> d
    C:\WINDOWS\My Disc (G)

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-12-06 08:05 77,312 ----a-w C:\WINDOWS\system32\alg.exe
    2007-12-05 07:32 1,098,752 ----a-w C:\WINDOWS\explorer.exe
    2007-12-05 04:45 123,392 ----a-w C:\WINDOWS\system32\spoolsv.exe
    2007-11-23 08:49
    d
    w C:\Program Files\LimeWire
    2007-11-21 00:38
    d--h--w C:\Program Files\InstallShield Installation Information
    2007-11-21 00:25
    d
    w C:\Program Files\EPSON
    2007-11-13 03:45
    d
    w C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2007-11-12 21:16
    d
    w C:\Program Files\Common Files\Adobe
    2007-11-12 21:10
    d
    w C:\Program Files\Common Files\Adobe Systems Shared
    2007-11-12 21:10
    d
    w C:\Documents and Settings\All Users\Application Data\Adobe Systems
    2007-11-02 19:28
    d
    w C:\Program Files\SSC Service Utility
    2007-10-31 19:43
    d
    w C:\Program Files\microsoft frontpage
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2007-11-26 01:55]
    "Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "EPSON Stylus C45 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.exe" [2004-01-13 10:00]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
    "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-12-06 00:05]
    "EPSON Stylus Photo R230 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.exe" [2005-03-09 03:00]
    "EPSON Stylus Photo R230 Series (Copy 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.exe" [2005-03-09 03:00]
    "EPSON Stylus Photo R230 Series (Copy 2)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.exe" [2005-03-09 03:00]
    "VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2007-12-04 23:32]
    "VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2007-12-04 20:45]
    "MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2007-12-04 23:32]
    "MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 12:05]
    "OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2007-12-06 00:45]

    R0 UNPR;UNPR;C:\WINDOWS\system32\unpr.sys
    R3 S3SAVAGE4M;S3SAVAGE4M;C:\WINDOWS\system32\DRIVERS\s3sav4m.sys
    S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2cdb9298-96f4-11dc-a8e4-0050fcf01b80}]
    \Shell\0pen\command - krag.exe
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL krag.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{46cf1bf3-a3d8-11dc-a8f8-0050fcf01b80}]
    \Shell\Autoplay\Command - F:\smss.exe
    \Shell\AutoRun\command - F:\smss.exe
    \Shell\Explore\Command - F:\smss.exe
    \Shell\Open\Command - F:\smss.exe

    .
    **************************************************************************

    catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-12 18:44:58
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-12-12 18:46:13
    C:\ComboFix2.txt ... 2007-12-10 20:20
    .
    --- E O F ---

    Hijack This log:

    Logfile of HijackThis v1.99.1
    Scan saved at 6:57:22 PM, on 12/12/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\WINDOWS\system32\taskmgr.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    c:\program files\mcafee.com\agent\mcagent.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\Documents and Settings\End User\Desktop\hijackthis\HijackThis.exe

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB004" /M "Stylus C45"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [EPSON Stylus Photo R230 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P30 "EPSON Stylus Photo R230 Series" /O6 "USB007" /M "Stylus Photo R230"
    O4 - HKLM\..\Run: [EPSON Stylus Photo R230 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P39 "EPSON Stylus Photo R230 Series (Copy 1)" /O6 "USB008" /M "Stylus Photo R230"
    O4 - HKLM\..\Run: [EPSON Stylus Photo R230 Series (Copy 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /P39 "EPSON Stylus Photo R230 Series (Copy 2)" /O6 "USB009" /M "Stylus Photo R230"
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
  • ScottyScotty Haggistown, Kiltland
    edited December 2007
    Hi

    When replying, please just copy and paste the logs, and dont use the quote boxes.:smiles:

    Step 1:

    Go to http://www.virustotal.com/en/indexf.html
    Copy the following line into the white textbox:
    C:\IvanTsang.psd
    Click Send.
    Please post the results of this scan to this thread.

    Do the same for the following:
    C:\diret model.psd
    C:\WINDOWS\CDER230.ini
    C:\z31.psd


    Step 2:

    Download Flash_Disinfector from here and save it to your desktop.
    Doubleclick on Flash_Disinfector.exe to run it and follow the prompts.
    Wait until it has finished scanning and then exit the program.
    The utility may ask you to insert your flash drive and/or other removable drives. This may include your mobile phone.
    Please do so and allow the utility to clean up those drives as well.

    Step 3:

    Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


    Open Notepad - it must be Notepad, not Wordpad.
    Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

    File::
    C:\WINDOWS\system32\unpr.sys 
    F:\smss.exe
    
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2cdb9298-96f4-11dc-a8e4-0050fcf01b80}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{46cf1bf3-a3d8-11dc-a8f8-0050fcf01b80}]
    
    Driver::
    UNPR
    


    Go to the Notepad window and click Edit > Paste
    Then click File > Save
    Name the file "CFScript.txt" (including the quotes)
    Save the file to your Desktop

    CFScript.gif


    Refering to the picture above, drag CFScript into ComboFix.exe

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.

    In your next reply post:
    Virustotal results
    ComboFix.txt
    New HJT log taken after the above scan has run


Sign In or Register to comment.