Options
a malware like kxvo... need help
vtUonolK.dll then when I restarted it became another file(opnoonND.dll) so, basically it went to HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Run
also the nod32 flashed it was a variant of virtumonde and it also seems so
Registry characteristic:
Name: MSServer
Type:RG_SZ
ValueData:rundll32.exe C:\Windows\system32\opnoonND.dll,#1
I ran the combofix but it did not detect that... I attached here a copy of my hijack log before I rebooted... Please help me and make me more knowledgable... Oh, I almost forgot it also does not allow you to open messengers like Yahoo Messenger and MSN Messenger... like the other malware I forgot about
also the nod32 flashed it was a variant of virtumonde and it also seems so
Registry characteristic:
Name: MSServer
Type:RG_SZ
ValueData:rundll32.exe C:\Windows\system32\opnoonND.dll,#1
I ran the combofix but it did not detect that... I attached here a copy of my hijack log before I rebooted... Please help me and make me more knowledgable... Oh, I almost forgot it also does not allow you to open messengers like Yahoo Messenger and MSN Messenger... like the other malware I forgot about
0
Comments
Code: 1000007e
And my machine also crashes now I am attaching here the 2 dumps I have
You posted a response in your own new request here, which gave it the appearance someone had already responded. But perhaps I can see why anyone would be hesitant to respond. You know ComboFix started by warning you not to run it without assistance. Even let's out two loud internal speaker beeps to drive home the point. Since there has been a delay since you posted I would have to wonder what other guessed changes you might have made there.
I took a peek at the minidumps. Most are from a previous XP install, so not associated with current events. The most recent have a Vista net transmission protocol driver, tdi.sys, attempting to write to a non-existent memory location while interacting with a NOD32 driver.
If you have not yet resolved the issues, and the system is still bootable, let's take a current look there. Be sure to post any requested logs directly here in the forum thread and not as attachments.
To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.
Download Deckard's System Scanner (dss.exe) to your Desktop. Note: You must be logged onto an account with administrator privileges.
Making sure dss.exe is directly on your desktop, go to Start - Run, and copy/paste the following (then press OK):
"%userprofile%\desktop\dss.exe" /config
When the DSS Configuration display opens click the "Check All" button (if the "Uncheck All" button shows, click that, then click "Check All"). Next, Under Main Log, uncheck the following:
System Restore
Temp Cleanup
Process Modules
Then under Options, place a check next to the following:
Backup Registry Hives
Don't make any other changes at this time. Then click the "Scan!" button to start the scan.
Once the scan has completed a textbox will appear - copy/paste those contents back here (main.txt). Also a second text file, extra.txt, will show as minimized in your Task Bar. Maximize/Open this, and copy/paste those contents back here along with the main.txt please. (The logs can also be found in the C:\Deckard\System Scanner folder)
You can use extra posts here if needed for that.
Oh about the messenger, it was my damn stupidity concerning the proxies
I really want to broaden my knowledge concerning these things.
You can use extra posts if needed.
EXTRA.TXT
Here it is... Thomas what was the program you used to open the minidump?
EXTRA.TXT
Here it is... Thomas what was the program you used to open the minidump?
Careful on the posting - in review yu will probably notice you posted mulitple copies of the same info. Also no need to use the "Code" function when posting.
Infection remains, as well as some autoloading malware there. If you have used any thumb/flash drives on this computer while it was infected those all will need to be inserted now, and let inserted until all repairs are completed.
I am sorta starting behind the eight ball here, as I see active infection but not sure why the scan softwares I see there left some of it. To be sure on at least one let's use that now.
To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs. This is a given, so be sure to make sure on this for every step you do.
Go here and download Flash_Disinfector.exe and save it to your desktop.
Doubleclick on Flash_Disinfector.exe to run it and follow the prompts. Wait until it has finished scanning and then exit the program.
The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the utility to clean up those drives as well.
Open and update Malwarebytes.
Then select "Perform Quick Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy and Paste the entire report in your next reply. If it calls for a reboot to complete the repairs do that as well then.
Then a new Deckards log after Malwarebytes does any removals and any flash drives had been installed, and we'll go with some manual repair steps.
Still making sure dss.exe is directly on your desktop, go to Start - Run, and copy/paste the following (then press OK):
"%userprofile%\desktop\dss.exe" /config
When the DSS Configuration display opens click the "Check All" button. Next, under Main Log, again uncheck the following:
System Restore
Temp Cleanup
Process Modules
Then under Extra Log, uncheck all the boxes except this one:
Security Center
Don't make any other changes at this time. Then click the "Scan!" button to start the scan.
Once the scan has completed a textbox will appear - copy/paste those contents back here please (main.txt). (The logs can also be found in the C:\Deckard\System Scanner folder)
Post that along with the Malwarebytes log please.
MAIN.TXT
Open Notepad (Start - Run, type notepad and OK) and copy and paste the above text (inside the box) into the text file. Now go to File > Save As and call it fixer.reg. Where it says "Files of Type", select All Files and click on Save. Exit Notepad, double-click on the file and ok the prompt asking if you wish to merge the file with your registry.
Then go here and run the Kaspersky online scan, and post back the log it creates (it requires IE).
To use the scan, accept the agreement and make sure you allow the ActiveX object to download and install (check the "yellow bar" at the top of IE if needed to allow this). Once the download has completed click Next, then Scan Settings, then make sure the "extended option" is checked (leave all others as they are) and click OK. Then click "My Computer" to begin the scan. Save the Report as a text file and post that back here.
To save it as a text file, still with the page in Internet Explorer, go to the top of the page and select File - Save As... Then make sure in the "Save as type" drop down you change it to "Text File(*.txt)".
And run a new Deckards scan using the same procedures as before, and post that along with the Kaspersky log please.
Deckard's System Scanner v20071014.68
Run by sins616 on 2008-05-30 18:07:55
Computer is in Normal Mode.
Percentage of Memory in Use: 77% (more than 75%).
-- HijackThis (run as sins616.exe)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:08:10 PM, on 5/30/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Users\sins616\Desktop\utorrent.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Chikka\chikka.exe
C:\PROGRA~1\Chikka\BnrRepo2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\sins616\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\sins616.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_PH&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_PH&c=73&bd=Pavilion&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.admu.edu.ph:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\sins616\Desktop\utorrent.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
--
End of file - 7187 bytes
-- Files created between 2008-04-30 and 2008-05-30
2008-05-30 10:24:52 0 d
C:\Users\All Users\Kaspersky Lab
2008-05-30 10:24:51 0 d
C:\Windows\system32\Kaspersky Lab
2008-05-29 12:42:54 0 d
c- C:\Yod'm 3D
2008-05-29 10:29:56 0 drahs--c- C:\autorun.inf
2008-05-29 10:28:08 0 d
C:\Users\All Users\Malwarebytes
2008-05-29 10:28:07 0 d
C:\Program Files\Malwarebytes' Anti-Malware
2008-05-26 20:59:21 0 d
C:\Users\All Users\Sonic
2008-05-26 13:43:33 0 d
C:\Windows\system32\Adobe
2008-05-25 00:41:18 4682 --a
C:\Windows\system32\npptNT2.sys <Not Verified; INCA Internet Co., Ltd.; nProtect NPSC Kernel Mode Driver for NT>
2008-05-25 00:41:05 0 d
C:\Program Files\Common Files\INCA Shared
2008-05-25 00:17:57 0 --a----c- C:\end
2008-05-24 11:48:01 0 d
C:\Program Files\e-Games
2008-05-23 12:16:53 0 d
C:\Program Files\OGPlanet
2008-05-20 13:54:42 298104 --a
C:\Windows\system32\imon.dll <Not Verified; Eset; NOD32 Antivirus System>
2008-05-19 18:34:56 0 d
c- C:\hotfix
2008-05-19 10:06:57 0 d
C:\Program Files\Yahoo!
2008-05-19 10:06:03 0 d
C:\Program Files\Eusing Free Registry Cleaner
2008-05-18 13:28:59 0 d
C:\Users\All Users\SUPERAntiSpyware.com
2008-05-18 09:06:35 56320 --a
C:\Windows\system32\wVpnLdCV.dll
2008-05-17 15:04:14 0 d
C:\Users\All Users\ESET
2008-05-17 14:46:37 68096 --a
C:\Windows\zip.exe
2008-05-17 14:46:37 161792 --a
C:\Windows\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-05-17 14:46:37 98816 --a
C:\Windows\sed.exe
2008-05-17 14:46:37 80412 --a
C:\Windows\grep.exe
2008-05-17 14:46:36 49152 --a
C:\Windows\VFind.exe
2008-05-17 14:46:36 212480 --a
C:\Windows\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-05-17 14:46:36 136704 --a
C:\Windows\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-05-17 14:46:36 73728 --a
C:\Windows\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-05-16 12:41:44 53248 --a----c- C:\t1no
2008-05-16 12:40:28 0 d
c- C:\SAVE
2008-05-16 12:13:55 0 d
C:\Program Files\half-life
2008-05-16 11:30:04 0 d
C:\Program Files\starcraft1151
2008-05-14 16:33:18 104409 --a
C:\Users\All Users\nvModes.dat
2008-05-08 18:44:53 4810 --a
C:\Windows\system32\Mapx16w6.dll
2008-05-07 21:41:23 0 d
C:\Program Files\Common Files\Hewlett-Packard
2008-05-07 21:36:12 148866 --a
C:\Windows\hpoins19.dat
2008-05-07 21:34:48 26952 --a
C:\Windows\hpomdl19.dat
2008-05-07 09:59:05 0 d
C:\Program Files\Trend Micro
2008-05-06 23:31:53 0 d
C:\Users\sins616\.housecall6.6
2008-05-06 22:52:44 0 d
C:\Program Files\Space Strike
2008-05-06 22:52:28 0 d
C:\Program Files\ReflexiveArcade
2008-05-06 21:27:16 409600 --a
C:\Windows\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2008-05-06 21:27:16 114688 --a
C:\Windows\system32\OpenAL32.dll <Not Verified; Portions (C) Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL(TM) Library>
2008-05-06 21:27:16 0 d
C:\Program Files\OpenAL
2008-05-06 21:23:01 0 d
C:\Program Files\Paradox Interactive
2008-05-06 12:40:30 0 d
C:\Program Files\Chikka
2008-05-06 01:23:53 0 d
C:\Program Files\Ninja Reflex
2008-05-04 21:37:00 0 d
C:\Windows\Zombie Shooter
2008-05-04 21:37:00 0 d
C:\Program Files\Zombie Shooter
-- Find3M Report
2008-05-30 18:08:01 0 d
C:\Users\sins616\AppData\Roaming\uTorrent
2008-05-27 21:43:57 1559 --a
C:\Windows\mozver.dat
2008-05-25 00:41:05 0 d
C:\Program Files\Common Files
2008-05-23 11:40:56 0 d
C:\Program Files\Microsoft Silverlight
2008-05-21 09:13:10 0 d
C:\Program Files\SpeedFan
2008-05-18 14:52:44 0 d
C:\Users\sins616\AppData\Roaming\SUPERAntiSpyware.com
2008-05-18 08:59:22 0 d
C:\Users\sins616\AppData\Roaming\Malwarebytes
2008-05-17 15:05:14 0 d
C:\Users\sins616\AppData\Roaming\ESET
2008-05-15 11:40:55 0 d
C:\Users\sins616\AppData\Roaming\Google
2008-05-15 11:40:38 0 d
C:\Program Files\Google
2008-05-15 10:55:43 0 d
C:\Users\sins616\AppData\Roaming\Mozilla
2008-05-14 14:30:07 24257 --a
C:\Users\sins616\AppData\Roaming\UserTile.png
2008-05-14 14:29:58 0 d
C:\Users\sins616\AppData\Roaming\PeerNetworking
2008-05-14 14:27:10 104409 --a
C:\Users\sins616\AppData\Roaming\nvModes.001
2008-05-13 14:49:41 104409 --a
C:\Users\sins616\AppData\Roaming\nvModes.dat
2008-05-12 09:26:29 0 d
C:\Users\sins616\AppData\Roaming\Microsoft Game Studios
2008-05-09 20:01:36 0 d
C:\Users\sins616\AppData\Roaming\HP
2008-05-08 13:36:37 0 d
C:\Users\sins616\AppData\Roaming\PlayFirst
2008-05-08 11:12:33 0 d--h
C:\Program Files\InstallShield Installation Information
2008-05-07 21:38:27 0 d
C:\Program Files\HP
2008-05-06 11:39:22 0 d
C:\Users\sins616\AppData\Roaming\Intenium
-- Registry Dump
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [01/16/2007 10:34 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [01/18/2008 07:31 PM]
"RtHDVCpl"="RtHDVCpl.exe" [03/10/2007 01:50 AM C:\WINDOWS\RtHDVCpl.exe]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [02/12/2007 10:37 PM]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [04/24/2007 09:11 AM]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [02/14/2007 02:38 AM]
"HP Health Check Scheduler"="[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" []
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [03/02/2007 04:18 AM]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [01/11/2007 07:12 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [09/15/2007 02:29 AM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [12/11/2007 10:56 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [02/27/2008 04:48 AM]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [02/27/2008 04:48 AM]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [05/20/2008 01:53 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [11/02/2006 08:35 PM]
"uTorrent"="C:\Users\sins616\Desktop\utorrent.exe" [05/03/2008 10:29 PM]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [08/30/2007 05:43 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"Launcher"=%WINDIR%\SMINST\launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableLUA"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E23136A1-1AC4-4D1B-926F-5D537CFFF359}"= C:\Windows\system32\wVpnLdCV.dll [05/18/2008 09:17 AM 56320]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yodm3D]
C:\Yod'm 3D\Yodm3D.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
HPZ12 Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt hpqcxs08 hpqddsvc
*Newly Created Service* - NPPTNT2
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
-- End of Deckard's System Scanner: finished at 2008-05-30 18:10:24
D:\Applications\Ninja Reflex cracked\ninja_reflex_setup.exe
> Trojan-Dropper.Win32.Agent.qzl skipped
Icrontic forums does not provide assistance when information indicates the presence or use of illegal software, so I will have to stop at this point. Best I can offer is a suggestion to reformat and reinstall to be assured the infeciton is removed.