Touch Forum Moderator Date Joined Jun 2004 Total Posts : 17983 Posted 2-8-2009 4:48 (GMT +1) Hello
Please post latest Bullguard antivirus scan log.
Look here how to copy it to Desktop -Picture 7
Back to Top
norsenoddy New Member Date Joined Feb 2009 Total Posts : 7 Posted 2-8-2009 5:09 (GMT +1) Hello are just having problems getting a full scan it keeps shutting down before it can finnish but showing infections before it shuts down I'll see what we can do. Thanks for the contact Back to Top
norsenoddy New Member Date Joined Feb 2009 Total Posts : 7 Posted 2-8-2009 8:00 (GMT +1) Hi, i've managed to get a full scan done now, for some reason the system would shut itself down when i tried to do the scan in safe mode, but allowed it to finish in normal mode. The scan found and solved many serious problems, but not all. It told me that i should restart to delete the remaining problems, but after I did that it failed to solve them, so I have two scan logs, one from immediatly before restarting, and another after the restart. Here is the one before the restart: ___________________________________________________________ BullGuard Scan Report Scan Profile: "My Computer" ___________________________________________________________ ----[ System Info ]------------ OS Version: Microsoft Windows XP Professional - Service Pack 3 (Build 2600) [2 * x86 CPUs] Physical memory: 2048 MB System up-time: 0 days, 02 hours, 20 minutes, 54 seconds BullGuard up-time: 0 days, 02 hours, 20 minutes, 12 seconds TopLayer Version: 8, 5, 0, 17 FileSpy5 Version: N/A BdFileSpy Version: 3.14.0.64 built by: WinDDK BsFileScan Version: 8, 5, 0, 70 Reconn Version: 1.1.0.5 built by: WinDDK MailProxy Version: 8, 5, 0, 20 AntiVirus Version: 8, 5, 0, 48 ----[ Scan Parameters ]------------ Folders to scan: A:\ C:\ Excluded folders: None Files to scan: None Scan type: [o] Scan all files [ ] Scan program files only [ ] Scan custom extensions: [X] Exclude user extensions: lnk [X] Scan boot sectors [X] Scan packed files [X] Scan archives [X] Scan emails [X] Scan running processes [X] Scan registry [X] Scan IE cookies [X] Enable heuristic detection [ ] Scan default action ___________________________________________________________ Scan Statistics ___________________________________________________________ Scan started: Sunday, February 08, 2009 18:38:46 Scan duration: 0 days, 02 hours, 18 minutes, 18 seconds Completion status: Successful Total files scanned: 603501 Total files skipped: 55 Identified viruses: 7 Scan speed: 72.73 files/sec Files skipped: A:\ [Open Failed] C:\Documents and Settings\Gareth\Application Data\Adobe\Acrobat\7.0\Messages\ENU\read0600win_ENUadbe0700b.pdf [Password protected] C:\Documents and Settings\Gareth\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [Open Failed] C:\Documents and Settings\Gareth\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [Open Failed] C:\Documents and Settings\Gareth\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{04F70607-2B12-4076-A58A-F6A2612AB2F7} [Open Failed] C:\Documents and Settings\Gareth\My Documents\Downloads\B - D\C\Caesars Palace 2000\caesars2k.part01.rar=>caesars2k.cdi [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\Downloads\B - D\C\Caesars Palace 2000\caesars2k.part01.rar=>caesars2k.cdi [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\Downloads\B - D\C\Caesars Palace 2000\caesars2k.part01.rar=>caesars2k.cdi [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\Downloads\B - D\C\Caesars Palace 2000\caesars2k.part01.rar=>caesars2k.cdi [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\Downloads\B - D\C\Capcon vs SNK\capvsnk.part01.rar=>capvsnk.cdi [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\Downloads\B - D\C\Centipede\kal-cent.part01.rar=>UNPACK.EXE [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\Downloads\B - D\C\Centipede\kal-cent.part01.rar=>KAL-CENT.BIN [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\Downloads\B - D\C\Centipede\kal-cent.part01.rar=>KAL-CENT.BIN [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\Downloads\B - D\C\Charge 'N Blast\chargeblast.part01.rar=>chargeblast.cdi [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\Downloads\B - D\C\Charge 'N Blast\chargeblast.part01.rar=>chargeblast.cdi [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\Downloads\Darkstalkers 3 PSX NTSC-U.rar=>Darkstalkers 3\PSX - Darkstalkers 3 [NTSC US - CCD].img [Corrupted archive] C:\Documents and Settings\Gareth\My Documents\My Completed Downloads\PCSX2.v2.0.9.4.Bios.Plugins.BlackVinta_1.rar [Password protected] C:\Documents and Settings\Gareth\My Documents\stuff from abroad\cdr and mp3 & audio programs\digital 1200sl.zip=>IMPORTANT.txt [Password protected] C:\Documents and Settings\Gareth\My Documents\stuff from abroad\cdr and mp3 & audio programs\digital 1200sl.zip=>Install.exe [Password protected] C:\Documents and Settings\Gareth\My Documents\stuff from abroad\cdr and mp3 & audio programs\digital 1200sl.zip=>sikvorez.txt [Password protected] C:\Documents and Settings\Gareth\My Documents\stuff from abroad\cdr and mp3 & audio programs\hmast.zip=>f4cg.nfo [Password protected] C:\Documents and Settings\Gareth\My Documents\stuff from abroad\cdr and mp3 & audio programs\hmast.zip=>file_id.diz [Password protected] C:\Documents and Settings\Gareth\My Documents\stuff from abroad\cdr and mp3 & audio programs\hmast.zip=>Setup.arv [Password protected] C:\Documents and Settings\Gareth\My Documents\stuff from abroad\cdr and mp3 & audio programs\hmast.zip=>Setup.exe [Password protected] C:\Documents and Settings\Gareth\My Documents\stuff from abroad\cdr and mp3 & audio programs\SteinbergQuadraFuzz.v1.0.zip=>Steinberg QuadraFuzz v1.0/setupqfz.EXE [Password protected] C:\Documents and Settings\Gareth\NTUSER.DAT [Open Failed] C:\Documents and Settings\Gareth\ntuser.dat.LOG [Open Failed] C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [Open Failed] C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [Open Failed] C:\Documents and Settings\LocalService\NTUSER.DAT [Open Failed] C:\Documents and Settings\LocalService\ntuser.dat.LOG [Open Failed] C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [Open Failed] C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [Open Failed] C:\Documents and Settings\NetworkService\NTUSER.DAT [Open Failed] C:\Documents and Settings\NetworkService\ntuser.dat.LOG [Open Failed] C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\ENU\RdrMsgENU.pdf [Password protected] C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\RdrMsgSplash.pdf [Password protected] C:\Program Files\Adobe\Acrobat 7.0\Reader\WebSearch\WebSearchENU.pdf [Password protected] C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig708\ENU\Data1.cab=>WebSearchENU.pdf [Password protected] C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig708\ENU\Data1.cab=>RdrMsgENU.pdf [Password protected] C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig708\ENU\Data1.cab=>RdrMsgSplash.pdf [Password protected] C:\System Volume Information\MountPointManagerRemoteDatabase [Open Failed] C:\WINDOWS\system32\CatRoot2\edb.log [Open Failed] C:\WINDOWS\system32\CatRoot2\tmp.edb [Open Failed] C:\WINDOWS\system32\config\default [Open Failed] C:\WINDOWS\system32\config\default.LOG [Open Failed] C:\WINDOWS\system32\config\SAM [Open Failed] C:\WINDOWS\system32\config\SAM.LOG [Open Failed] C:\WINDOWS\system32\config\SECURITY [Open Failed] C:\WINDOWS\system32\config\SECURITY.LOG [Open Failed] C:\WINDOWS\system32\config\software [Open Failed] C:\WINDOWS\system32\config\software.LOG [Open Failed] C:\WINDOWS\system32\config\system [Open Failed] C:\WINDOWS\system32\config\system.LOG [Open Failed] C:\WINDOWS\system32\drivers\sptd.sys [Open Failed] C:\WINDOWS\TempFile [Open Failed] ___________________________________________________________ Infected Files ___________________________________________________________ ----[ Infected Files ]------------ Malware: Gen:Trojan.Heur.544453 C:\WINDOWS\system32\xxyARjgD.dll Malware: MemScan:Trojan.FakeAV.CH C:\Documents and Settings\Gareth\Local Settings\Temp\winsinstall.exe Malware: Trojan.Generic.1338256 C:\Documents and Settings\Gareth\Local Settings\Temp\snapsnet.tmp Malware: Trojan.Generic.1412838 C:\Documents and Settings\Gareth\Local Settings\Temp\winvsnet.tmp Malware: Trojan.Zlob.49617 C:\Documents and Settings\Gareth\Local Settings\Temporary Internet Files\Content.IE5\0DLOF2A2\setup_lib_srl.exe C:\Documents and Settings\Gareth\Local Settings\Temporary Internet Files\Content.IE5\3USG04HR\setup_lib_srl.exe ----[ Infected Cookies ]------------ Malware: Cookie.Advertising <System>=>C:\Documents and Settings\Gareth\Cookies\gareth@advertising.txt ----[ Infected Registry Entries ]------------ Malware: Gen:Trojan.Heur.544453 <System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B61EBBC4-DF04-467F-8D4B-F8379881953C}=>C:\WINDOWS\SYSTEM32\XXYARJGD.DLL ___________________________________________________________ Results after ROUND 0 ___________________________________________________________ Scan started: Sunday, February 08, 2009 16:20:28 Scan duration: 0 days, 02 hours, 18 minutes, 18 seconds Infections solved: 0 Infections left: 8 Viruses left: 6 ----[ Files Still Infected ]------------ Malware: Gen:Trojan.Heur.544453 C:\WINDOWS\system32\xxyARjgD.dll Malware: MemScan:Trojan.FakeAV.CH C:\Documents and Settings\Gareth\Local Settings\Temp\winsinstall.exe Malware: Trojan.Generic.1338256 C:\Documents and Settings\Gareth\Local Settings\Temp\snapsnet.tmp Malware: Trojan.Generic.1412838 C:\Documents and Settings\Gareth\Local Settings\Temp\winvsnet.tmp Malware: Trojan.Zlob.49617 C:\Documents and Settings\Gareth\Local Settings\Temporary Internet Files\Content.IE5\0DLOF2A2\setup_lib_srl.exe C:\Documents and Settings\Gareth\Local Settings\Temporary Internet Files\Content.IE5\3USG04HR\setup_lib_srl.exe ----[ Cookies Still Infected ]------------ Malware: Cookie.Advertising <System>=>C:\Documents and Settings\Gareth\Cookies\gareth@advertising.txt ----[ Registry Entries Still Infected ]------------ Malware: Gen:Trojan.Heur.544453 <System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B61EBBC4-DF04-467F-8D4B-F8379881953C}=>C:\WINDOWS\SYSTEM32\XXYARJGD.DLL ___________________________________________________________ Results after ROUND 1 ___________________________________________________________ Scan started: Sunday, February 08, 2009 18:38:57 Scan duration: 0 days, 00 hours, 01 minutes, 18 seconds Infections solved: 1 Infections left: 7 Viruses left: 5 ----[ Cookies Solved ]------------ Malware: Cookie.Advertising Status: Deleted <System>=>C:\Documents and Settings\Gareth\Cookies\gareth@advertising.txt ----[ Files Still Infected ]------------ Malware: Gen:Trojan.Heur.544453 Status: Disinfect Failed C:\WINDOWS\system32\xxyARjgD.dll Malware: MemScan:Trojan.FakeAV.CH Status: Disinfect Failed C:\Documents and Settings\Gareth\Local Settings\Temp\winsinstall.exe Malware: Trojan.Generic.1338256 Status: Disinfect Failed C:\Documents and Settings\Gareth\Local Settings\Temp\snapsnet.tmp Malware: Trojan.Generic.1412838 Status: Disinfect Failed C:\Documents and Settings\Gareth\Local Settings\Temp\winvsnet.tmp Malware: Trojan.Zlob.49617 Status: Disinfect Failed C:\Documents and Settings\Gareth\Local Settings\Temporary Internet Files\Content.IE5\0DLOF2A2\setup_lib_srl.exe C:\Documents and Settings\Gareth\Local Settings\Temporary Internet Files\Content.IE5\3USG04HR\setup_lib_srl.exe ----[ Registry Entries Still Infected ]------------ Malware: Gen:Trojan.Heur.544453 Status: Deletion Failed <System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B61EBBC4-DF04-467F-8D4B-F8379881953C}=>C:\WINDOWS\SYSTEM32\XXYARJGD.DLL ___________________________________________________________ Results after ROUND 2 ___________________________________________________________ Scan started: Sunday, February 08, 2009 18:40:29 Scan duration: 0 days, 00 hours, 00 minutes, 41 seconds Infections solved: 5 Infections left: 2 Viruses left: 1 ----[ Files Solved ]------------ Malware: MemScan:Trojan.FakeAV.CH Status: Moved To Quarantine C:\Documents and Settings\Gareth\Local Settings\Temp\winsinstall.exe Malware: Trojan.Generic.1338256 Status: Moved To Quarantine C:\Documents and Settings\Gareth\Local Settings\Temp\snapsnet.tmp Malware: Trojan.Generic.1412838 Status: Moved To Quarantine C:\Documents and Settings\Gareth\Local Settings\Temp\winvsnet.tmp Malware: Trojan.Zlob.49617 Status: Moved To Quarantine C:\Documents and Settings\Gareth\Local Settings\Temporary Internet Files\Content.IE5\0DLOF2A2\setup_lib_srl.exe C:\Documents and Settings\Gareth\Local Settings\Temporary Internet Files\Content.IE5\3USG04HR\setup_lib_srl.exe ----[ Files Still Infected ]------------ Malware: Gen:Trojan.Heur.544453 Status: Failed moving to quarantine C:\WINDOWS\system32\xxyARjgD.dll ----[ Registry Entries Still Infected ]------------ Malware: Gen:Trojan.Heur.544453 Status: Deletion Failed <System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B61EBBC4-DF04-467F-8D4B-F8379881953C}=>C:\WINDOWS\SYSTEM32\XXYARJGD.DLL Here is the one from after the restart: ___________________________________________________________ BullGuard Scan Report Scan Profile: "~Resuming Profile - My Computer" ___________________________________________________________ ----[ System Info ]------------ OS Version: Microsoft Windows XP Professional - Service Pack 3 (Build 2600) [2 * x86 CPUs] Physical memory: 2048 MB System up-time: 0 days, 00 hours, 01 minutes, 29 seconds BullGuard up-time: 0 days, 00 hours, 00 minutes, 36 seconds TopLayer Version: 8, 5, 0, 17 FileSpy5 Version: N/A BdFileSpy Version: 3.14.0.64 built by: WinDDK BsFileScan Version: 8, 5, 0, 70 Reconn Version: 1.1.0.5 built by: WinDDK MailProxy Version: 8, 5, 0, 20 AntiVirus Version: 8, 5, 0, 48 ----[ Scan Parameters ]------------ Folders to scan: None Excluded folders: None Files to scan: C:\WINDOWS\system32\xxyARjgD.dll Scan type: [o] Scan all files [ ] Scan program files only [ ] Scan custom extensions: [ ] Exclude user extensions: [X] Scan boot sectors [X] Scan packed files [X] Scan archives [ ] Scan emails [ ] Scan running processes [ ] Scan registry [ ] Scan IE cookies [X] Enable heuristic detection [ ] Scan default action ___________________________________________________________ Scan Statistics ___________________________________________________________ Scan started: Sunday, February 08, 2009 18:44:54 Scan duration: 0 days, 00 hours, 00 minutes, 03 seconds Completion status: Successful Total files scanned: 2 Total files skipped: 0 Identified viruses: 1 Scan speed: 0.67 files/sec ___________________________________________________________ Infected Files ___________________________________________________________ ----[ Infected Files ]------------ Malware: Gen:Trojan.Heur.544453 C:\WINDOWS\system32\xxyARjgD.dll ___________________________________________________________ Results after ROUND 0 ___________________________________________________________ Scan started: Sunday, February 08, 2009 18:44:51 Scan duration: 0 days, 00 hours, 00 minutes, 03 seconds Infections solved: 0 Infections left: 1 Viruses left: 1 ----[ Files Still Infected ]------------ Malware: Gen:Trojan.Heur.544453 C:\WINDOWS\system32\xxyARjgD.dll ___________________________________________________________ Results after ROUND 1 ___________________________________________________________ Scan started: Sunday, February 08, 2009 18:45:01 Scan duration: 0 days, 00 hours, 00 minutes, 01 seconds Infections solved: 0 Infections left: 1 Viruses left: 1 ----[ Files Still Infected ]------------ Malware: Gen:Trojan.Heur.544453 Status: Disinfect Failed C:\WINDOWS\system32\xxyARjgD.dll ___________________________________________________________ Results after ROUND 2 ___________________________________________________________ Scan started: Sunday, February 08, 2009 18:45:07 Scan duration: 0 days, 00 hours, 00 minutes, 03 seconds Infections solved: 0 Infections left: 1 Viruses left: 1 ----[ Files Still Infected ]------------ Malware: Gen:Trojan.Heur.544453 Status: Failed moving to quarantine C:\WINDOWS\system32\xxyARjgD.dll ___________________________________________________________ Results after ROUND 3 ___________________________________________________________ Scan started: Sunday, February 08, 2009 18:45:16 Scan duration: 0 days, 00 hours, 00 minutes, 08 seconds Infections solved: 0 Infections left: 1 Viruses left: 1 ----[ Files Still Infected ]------------ Malware: Gen:Trojan.Heur.544453 Status: Deletion Failed C:\WINDOWS\system32\xxyARjgD.dllPost Edited (norsenoddy) : 08-02-2009 19:02:42 GMT
Back to Top
norsenoddy New Member Date Joined Feb 2009 Total Posts : 7 Posted 2-8-2009 8:21 (GMT +1) Hi, another update: I received a response from bullguard to my scan log, and was advised to restart in safe mode and manually delete the file mentioned above (xxyARjgD.dll). I tried this but was told I did not have permission to delete it, even though I had turned off 'read only' on the files properties, and was logged on as administrator Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 17983 Posted 2-9-2009 7:25 (GMT +1) You can´t delete the mentioned file, as it is part of a (vundo) infection. We need to use special fix tools ->
Once installed, run CCleaner click the Windows tab Select the following: Internet Explorer: Temp Internet History Recently Typed URLs Delete Index.dat files System: Empty Recycle Bin Temporary Files Memory Dumps Chkdsk File Fragments Old Prefetch Data Next: click Options click the Settings tab Uncheck: "Only delete files older than 48 hrs.", click Ok Then click Run Cleaner (bottom right) then Exit
Reboot
Please download Malwarebytes' Anti-Malware:
Or here:
to your desktop .
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch
Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Please connect all your external hard drive/flash drive before running Malwarebyte
Once the program has loaded, select Perform full scan , then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location.
NB : If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
to download HJTinstall.exe
Save HJTinstall.exe to your desktop. Double click on the HJTinstall.exe icon on your desktop.
By default it will install to C:\Program Files\Trend Micro\Hijack This.
Click I accept
Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
Click Save to save the log file and then the log will open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT have Hijack This fix anything yet.
Most of what it finds will be harmless or even required.
Post hijackthis log along with Malwarebytes' Anti-Malware log
Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.
Post Edited (Touch) : 09-02-2009 06:29:09 GMT
Back to Top
norsenoddy New Member Date Joined Feb 2009 Total Posts : 7 Posted 2-9-2009 7:48 (GMT +1) Ok, got all that :) Here's the hijack this log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:41:37, on 09/02/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\nvsvc32.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\DAP\DAP.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: (no name) - {40BF0BA1-43DD-4B31-9C55-0B51FDBCB5C0} - C:\WINDOWS\system32\xxyvtqQJ.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe" -boot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe" O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: *.amaena.com O15 - Trusted Zone: *.antispyexpert.com O15 - Trusted Zone: *.avsystemcare.com O15 - Trusted Zone: *.imagesrvr.com O15 - Trusted Zone: *.onerateld.com O15 - Trusted Zone: *.safetydownload.com O15 - Trusted Zone: *.spyguardpro.com O15 - Trusted Zone: *.storageguardsoft.com O15 - Trusted Zone: *.trustedantivirus.com O15 - Trusted Zone: *.virusremover2008.com O15 - Trusted Zone: *.virusschlacht.com O15 - Trusted Zone: *.amaena.com (HKLM) O15 - Trusted Zone: *.antispyexpert.com (HKLM) O15 - Trusted Zone: *.avsystemcare.com (HKLM) O15 - Trusted Zone: *.imageservr.com (HKLM) O15 - Trusted Zone: *.imagesrvr.com (HKLM) O15 - Trusted Zone: *.onerateld.com (HKLM) O15 - Trusted Zone: *.safetydownload.com (HKLM) O15 - Trusted Zone: *.spyguardpro.com (HKLM) O15 - Trusted Zone: *.storageguardsoft.com (HKLM) O15 - Trusted Zone: *.trustedantivirus.com (HKLM) O15 - Trusted Zone: *.virusremover2008.com (HKLM) O15 - Trusted Zone: *.virusschlacht.com (HKLM) O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: avgrsstx.dll C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O20 - Winlogon Notify: qoMeEULc - qoMeEULc.dll (file missing) O20 - Winlogon Notify: ssqQhigH - ssqQhigH.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe O23 - Service: BGRaSvc - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\support\bgrasvc.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 9384 bytes And here's the malware log Malwarebytes' Anti-Malware 1.33 Database version: 1740 Windows 5.1.2600 Service Pack 3 09/02/2009 18:13:15 mbam-log-2009-02-09 (18-13-15).txt Scan type: Full Scan (C:\|F:\|) Objects scanned: 253604 Time elapsed: 2 hour(s), 10 minute(s), 23 second(s) Memory Processes Infected: 0 Memory Modules Infected: 2 Registry Keys Infected: 21 Registry Values Infected: 4 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 18 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\gtqaxcav.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\xxyARjgD.dll (Trojan.Vundo.H) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomedvss (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7ff603c4-0582-4fb2-b505-3dc4af58e1a5} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{7ff603c4-0582-4fb2-b505-3dc4af58e1a5} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7ff603c4-0582-4fb2-b505-3dc4af58e1a5} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\{5222008a-dd62-49c7-a735-7bd18ecc7350} (Rogue.VirusRemover) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\{5222008a-dd62-49c7-a735-7bd18ecc7350} (Rogue.VirusRemover) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\prunnet (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\virusremover2008 (Rogue.VirusRemove) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\virusremover2008 (Rogue.VirusRemove) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\287eed9b (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prunnet (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prunnet (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\xxyarjgd -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\xxyarjgd -> Delete on reboot. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\qoMeDvss.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\xxyARjgD.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\DgjRAyxx.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\DgjRAyxx.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\gtqaxcav.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\vacxaqtg.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\smgjyxpu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\upxyjgms.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\prunnet.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Gareth\Local Settings\Temporary Internet Files\Content.IE5\G44YRGXZ\upd105320 (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ljJYpmLf.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Gareth\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusRemover2008.lnk (Rogue.VirusRemove) -> Quarantined and deleted successfully. C:\WINDOWS\system32\senekakdeqmmne.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\senekanootjwke.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\senekappralwjy.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\senekarjahverc.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\senekaunfhiota.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\senekampppuwtu.sys (Trojan.Agent) -> Delete on reboot. Thanks for your help so far! Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 17983 Posted 2-9-2009 8:03 (GMT +1) According to the (removed) infections in malwarebyte log´s, I´ll need to see a combofix log.
But first -it looks like you have two antivirus programs running - Bullguard and AVG8 .
" Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and will typically cause your computer to crash, and will provide less protection . Not more ."
Remove/uninstall from "add/remove programs" in controlpanel:
One of Your antivirus programs.
Then ->
Please download Combofix:
And save to the desktop.
Close all other browser windows.
Note : combofix is detected by some antivirus programs as a "RiskTool" /infection; it is not a virus. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
If necessary, temporarily disable/shutdown your anti-virus.
Please connect all your external hard drive/flash drive before running Combofix, if you have any
Double-click on the combofix icon found on your desktop.
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.
When finished, it will produce a logfile located at C:\combofix.txt.
Post the contents of that log in your next reply.
Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.
Post Edited (Touch) : 09-02-2009 19:15:08 GMT
Back to Top
norsenoddy New Member Date Joined Feb 2009 Total Posts : 7 Posted Yesterday 5:57 (GMT +1) Hi, sorry this has taken me so long, my computer had to be taken to the shop for unrelated hardware problems... I tried running combofix, but even when I close bullguard, and have uninstalled avg, it insists that they are still 'active' and that running combofix may damage the computer. It still tried to do it anyway, I had to quickly hit the reset button. I'm a little torn on what to do - i right clicked the bullguard icon in the system tray and told it to close, and avg is uninstalled, so i'm confused as to what combofix wants from me. Sorry to be such a bother! Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 17983 Posted Today 7:04 (GMT +1) Ok. Let´s try this scanner ->
Please download OTViewIt by OldTimer to your desktop.
Double click on the OTViewIt.exe icon on your desktop. If you are using Windows Vista, right click the icon and select Run as Administrator .
Check the Scan All Users checkbox and leave Use Whitelist checked. Set the File Age to 30 days.
Click on the Run Scan button. Two reports that are located in the same location as OTViewIt will open.
OTViewIt.txt <-- Will be opened Extra.txt <-- Will be minimized
Copy and Paste the logs into your next reply.
Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.
Back to Top
Forum Information Currently it is Sunday, February 12, 2012 3:24 AM (GMT +1) There are a total of 82.635 posts in 18.630 threads. In the last 3 days there were 0 new threads and 5 reply posts. View Active Threads Who's Online This forum has 33728 registered members. Please welcome our newest member, uma shankar . 18 Guest(s), 0 Registered Member(s) are currently online. Details 5 Latest Threads