Help - Search - Members - Calendar
Full Version: Infected Computer!
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
zenigame211
Hi there, someday ago, my friend clicked to an advert on a pop-up. After a while, her computer have pop-ups even shes off the internet. She said there are some unknown files in her C drive. something like luxor.exe, bleh.exe
anyway, i hope you can help her out. Here is her log file

Logfile of HijackThis v1.99.1
Scan saved at ¤W¤È 03:25:31, on 2005/10/17
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\WINDOWS\LTSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\NORMAN\nvc\BIN\ZLH.EXE
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\System32\winamp.exe
C:\WINDOWS\System32\firewall.exe
C:\WINDOWS\System32\explorer.exe
C:\WINDOWS\System32\wininit.exe
C:\NORMAN\nvc\BIN\NYMSE.EXE
C:\WINDOWS\System32\scvhost.exe
C:\WINDOWS\etb\pokapoka75.exe
C:\NORMAN\nvc\BIN\NJEEVES.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\scvhost.exe
C:\Program Files\Hijackthis\HijackThis.exe

O3 - Toolbar: ¦¬­µ¾÷(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [Winamp Agent] C:\WINDOWS\System32\winamp.exe
O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINDOWS\System32\firewall.exe
O4 - HKLM\..\Run: [Windows Explorer] C:\WINDOWS\System32\explorer.exe
O4 - HKLM\..\Run: [Microsoft Update 32] wininit.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
O4 - HKLM\..\Run: [System service75] C:\WINDOWS\etb\pokapoka75.exe
O4 - HKLM\..\RunServices: [Microsoft Update 32] wininit.exe
O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: ¶×¥X¦Ü Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: °Ñ¦Ò¸ê®Æ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.fujitsu-pc-asia.com
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\NORMAN\nvc\BIN\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\NVC\BIN\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\NORMAN\nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\NORMAN\nvc\BIN\NVCSCHED.EXE
Mosaic1
Download Pocket Killbox version 2.0.0.175
http://www.atribune.org/downloads/KillBox.exe

Run Killbox.exe by double clicking on it.

Select Delete on Reboot.
Copy this entire list of files to the clipboard.

(Highlight the list. Press CTRL + C)
C:\WINDOWS\System32\firewall.exe
C:\WINDOWS\System32\explorer.exe
C:\windows\system32\wininit.exe
C:\windows\system32\scvhost.exe

In the Killbox,
Go to the toolbar to File> Paste from clipboard. Click Paste from Clipboard.
All of the files you pasted in might not show up on the list in Killbox. That's normal. Some may not be present and so will not be listed. Go ahead to the next step.

Click the red icon with the white X at the upper right.
You will be prompted to restart. Say no and exit.
--------------------


You will be restarting into Safe mode. Here's help if you need it.

To use the F8 key to start Windows XP in Safe mode
Restart the computer.
Some computers have a progress bar that refers to the word BIOS. Others may not let you know what is happening.
As soon as the BIOS loads, begin tapping the F8 key on your keyboard. Do so until the Windows Advanced Options menu appears.
If you begin tapping the F8 key too soon, some computers display a
"keyboard error" message. If this happens, restart the computer and try again.
Using the arrow keys on the keyboard, select Safe mode and then press Enter.

------
Restart to Safe mode.
Go Directly to start >run
Type hijackthis
Press enter.
Select the following items andpress the fix checked button:

O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINDOWS\System32\firewall.exe
O4 - HKLM\..\Run: [Windows Explorer] C:\WINDOWS\System32\explorer.exe
O4 - HKLM\..\Run: [Microsoft Update 32] wininit.exe
O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
O4 - HKLM\..\RunServices: [Microsoft Update 32] wininit.exe
O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe
-------------------

Restart into regular windows.



Download LQfix.exe and Save it to your desktop.

http://users.pandora.be/bluepatchy/miekiem...tools/LQfix.exe
Doubleclick LQfix.exe and click install.

Leave the default settings. If you change them, the fix will fail.
You need an active internet connection so LQfix can connect.
Allow LQfix to connect to the internet if prompted by your firewall.
Make sure 'Launch LQfix' is checked. After clicking finish in the install, the fix will start.
Follow the prompts on the screen.
Your system will reboot afterwards.
Please be patient after reboot, because there is a script running in the background.
---------------



Go for a free online Virus scan here:

http://www.pandasoftware.com/activescan/

Allow it to clean

Panda will have the option to create a log afer the scan has finished.

Click the See Report button. Then click the save Report button. It will be saved under the name activescan.txt Do that and post that log into your next reply here.

----------------

Run hijackthis and post the new log.

Also Please download silentrunners.zip
http://www.silentrunners.org/Silent%20Runners.zip

Unzip to your desktop and double click on the VBS file.
If your get a message about a malicious script, please allow the script to run. It is a diagnostic tool.

The script will save a Notepad document to your Desktop.

Copy and paste the contents of that text file into your next reply.
zenigame211
Incident Status Location

Virus:W32/Gaobot.FVK.worm Disinfected C:\WINDOWS\system32\winamp.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\WINDOWS\system32\scvhost.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\WINDOWS\system32\bleh.exe
Virus:Trj/Dropper.HZ Disinfected C:\WINDOWS\system32\ctfmon.exe
Virus:Trj/Dropper.HZ Disinfected C:\WINDOWS\system32\ctfmon.exe.tmp
Adware:Adware/EliteBar No disinfected C:\WINDOWS\etb\pokapoka75.exe
Adware:Adware/EliteBar No disinfected C:\WINDOWS\etb\nt_hide75.dll
Adware:Adware/Exact.BargainBuddyNo disinfected C:\WINDOWS\etb\xml\images\virus.bmp
Adware:Adware/Exact.BargainBuddyNo disinfected C:\WINDOWS\etb\xml\images\dating.bmp
Adware:Adware/Exact.BargainBuddyNo disinfected C:\WINDOWS\etb\xml\images\-- Look for another playground --.bmp
Adware:Adware/EliteBar No disinfected C:\WINDOWS\etb\pokapoka76.exe
Adware:Adware/EliteBar No disinfected C:\WINDOWS\etb\nt_hide76.dll
Adware:Adware/IST.ISTBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\jfgudk.exe
Adware:adware/sahagent No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\sahagent.exe
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\1507824_692_380_720_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\3343178_1228_380_3540_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\196868_1416_2596_2704_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\262702_1676_2748_3844_76.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\262416_1676_2596_2712_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\721480_3056_112_2744_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\786992_2096_268_3864_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\196868_1416_2748_2852_76.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\262702_1676_2596_3680_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\262416_1676_2748_2856_76.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\262416_1676_1908_276_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\393492_1416_1908_1692_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\262702_1676_1908_4044_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\4915484_1104_276_264_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\10092772_2868_508_1444_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temp\8388926_4048_276_3784_75.41.tmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\RRRUSL9M\pokapoka66[1].exe
Virus:Trj/Downloader.FGR Disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\RRRUSL9M\uk_efp[1].exe
Adware:Adware/IST.ISTBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\RRRUSL9M\rmvbot[1].rar
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\RRRUSL9M\pokapoka73[1].exe
Adware:Adware/Exact.BargainBuddyNo disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\RRRUSL9M\dating[1].bmp
Virus:Trj/Downloader.FGR Disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\RRRUSL9M\uk_efp[2].exe
Dialer:Dialer.Gen No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\6HI523EP\China[1].exe
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\6HI523EP\silent_setup[1].exe
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\6HI523EP\silent_setup[2].exe
Adware:Adware/Exact.BargainBuddyNo disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\6HI523EP\-- Look for another playground --[1].bmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\6HI523EP\pokapoka76[1].exe
Adware:Adware/IST.ISTBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\OD63G5I7\istdownload[1].exe
Adware:Adware/Exact.BargainBuddyNo disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\0ZQ7IX67\virus[1].bmp
Virus:W32/Gaobot.FVK.worm Disinfected C:\Documents and Settings\daphne\®à­±\bleh.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\Documents and Settings\daphne\bleh.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\Program Files\Common Files\System\MSMAPI\1028\bleh.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\Program Files\Drag'n Drop CD\BinFiles\bleh.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000059.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000060.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000088.dll
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000092.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000099.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000100.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000104.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000105.DLL
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000109.exe
Virus:Trj/Dropper.HZ Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000117.EXE
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001954.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001955.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001959.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001960.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001964.DLL
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001965.DLL
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001970.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001978.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001979.DLL
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001980.exe
Virus:Trj/Dropper.HZ Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001991.EXE
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0002013.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0002014.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0002015.DLL
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0002016.dll
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP4\A0002024.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP4\A0002967.dll
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP4\A0002971.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP4\A0002972.exe
Adware:Adware/IST.ISTBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP4\A0002997.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP4\A0002999.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP5\A0003018.EXE
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP5\A0003028.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP5\A0003036.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP5\A0003039.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP5\A0003040.dll
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP5\A0003044.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP5\A0003045.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP10\A0004049.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP10\A0004051.exe
Virus:Trj/Dropper.HZ Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP10\A0004083.EXE
Virus:Trj/Lowzones.KX Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP10\A0004212.exe
Virus:Trj/Dropper.HZ Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP10\A0004515.EXE
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP10\A0004571.exe
Virus:Trj/Dropper.HZ Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP10\A0004572.EXE
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP11\A0005041.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP11\A0005049.exe
Virus:Bck/Poebot.CL Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP11\A0005050.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP11\A0005055.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP12\A0006055.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP12\A0006400.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP12\A0006401.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP13\A0007399.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP13\A0007400.exe
Virus:Trj/Dropper.HZ Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP13\A0007408.EXE
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP13\A0007443.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP15\A0009445.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP15\A0009448.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP15\A0010443.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP15\A0010444.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP15\A0011443.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP15\A0012443.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP15\A0012444.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP15\A0012448.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP15\A0012449.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP16\A0012458.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP16\A0012462.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP16\A0013458.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP16\A0013469.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP16\A0013470.exe
Virus:Trj/Dropper.HZ Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP16\A0013478.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP17\A0013495.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP17\A0013497.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP17\A0013511.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP17\A0013524.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP17\A0013526.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP19\A0015526.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP19\A0015530.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP19\A0015535.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP19\A0015536.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP20\A0016524.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP20\A0016531.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP20\A0016532.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP21\A0017524.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP21\A0017532.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP21\A0017538.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP21\A0017545.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP21\A0017546.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018538.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018549.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018552.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018558.exe
Virus:Trj/Dropper.KM Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018561.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018562.exe
Virus:W32/Gaobot.JWE.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018563.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018564.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018571.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018579.EXE
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018583.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018592.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018598.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018599.dll
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018600.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018608.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018609.EXE
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018610.EXE
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018611.exe
Virus:Trj/Dropper.HZ Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018612.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018614.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\!KillBox\scvhost.exe
Virus:W32/Gaobot.JWE.worm Disinfected C:\!KillBox\wininit.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\!KillBox\explorer.exe
Virus:Trj/Dropper.KM Disinfected C:\!KillBox\firewall.exe
Virus:Trj/Agent.AQF Disinfected C:\luxor.exe
zenigame211
Logfile of HijackThis v1.99.1
Scan saved at ¤W¤È 06:36:34, on 2005/10/22
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\NORMAN\nvc\BIN\NJEEVES.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\LTSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\NORMAN\nvc\BIN\ZLH.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\NORMAN\nvc\BIN\NYMSE.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\etb\pokapoka75.exe
C:\Program Files\Hijackthis\hijackthis.exe

O3 - Toolbar: ¦¬­µ¾÷(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
O4 - HKLM\..\Run: [System service75] C:\WINDOWS\etb\pokapoka75.exe
O4 - HKLM\..\Run: [System service76] C:\WINDOWS\\\etb\\pokapoka76.exe
O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: ¶×¥X¦Ü Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: °Ñ¦Ò¸ê®Æ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.fujitsu-pc-asia.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\NORMAN\nvc\BIN\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\NVC\BIN\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\NORMAN\nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\NORMAN\nvc\BIN\NVCSCHED.EXE
Mosaic1
We need to disable your Microsoft AntiSpyware Real-time Protection as it may interfere with the fixes that we need to make. It can be enabled when your clean. It in fact is not allowing use to remove startup entries.

Open Microsoft AntiSpyware.
Click on Tools, Settings.
In the left pane, click on Real-time Protection.
Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
_ _ _ _


Run hijakcthis and fix these entries.

O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe



If you didnt do this. Please do it now. OR if you did, repeat the procedure.

Download LQfix.exe and Save it to your desktop.

http://users.pandora.be/bluepatchy/miekiem...tools/LQfix.exe
Doubleclick LQfix.exe and click install.

Leave the default settings. If you change them, the fix will fail.
You need an active internet connection so LQfix can connect.
Allow LQfix to connect to the internet if prompted by your firewall.
Make sure 'Launch LQfix' is checked. After clicking finish in the install, the fix will start.
Follow the prompts on the screen.
Your system will reboot afterwards.
Please be patient after reboot, because there is a script running in the background.


--------

Empty your Temporary Internet Files and history in Internet Options. And clean out your
Temp folder.
Go to start>Run and type
%TEMP%
Press enter to open your temp folder.

Select all and delete all.

It's a good idea to do that regularly.
---------

Post a new hijckthis log.

I had also asked for a silent runners log. Please read my instructions again and post that log when you have finished too, please.


----
zenigame211
"Silent Runners.vbs", revision 41, http://www.silentrunners.org/
Operating System: Windows XP
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ctfmon.exe" = "C:\WINDOWS\System32\ctfmon.exe" [MS]
"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"IMJPMIG8.1" = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32" [MS]
"ATIModeChange" = "Ati2mdxx.exe" ["ATI Technologies, Inc."]
"AtiPTA" = "atiptaxx.exe" ["ATI Technologies, Inc."]
"LoadFujitsuQuickTouch" = "C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" ["FUJITSU LIMITED"]
"LoadBtnHnd" = "C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe" ["FUJITSU LIMITED"]
"IndicatorUtility" = "C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" ["FUJITSU LIMITED"]
"LTSMMSG" = "LTSMMSG.exe" ["Lucent Technologies"]
"Apoint" = "C:\Program Files\Apoint2K\Apoint.exe" ["Alps Electric Co., Ltd."]
"Drag'n Drop CD" = "C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp" [empty string]
"Norman ZANDA" = "C:\NORMAN\nvc\BIN\ZLH.EXE /LOAD /SPLASH" [null data]
"CJIMETIPSYNC" = "C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync" [MS]
"PHIMETIPSYNC" = "C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync" [MS]
"gcasServ" = ""C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"" [MS]
"Configuration Loader" = "scvhost.exe" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "**** CPL **" (unwritable string)
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{9EF34FF2-3396-4527-9D27-04C8C1C67806}" = "Microsoft AntiSpyware Service Hook"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft AntiSpyware\shellextension.dll" [MS]

HKLM\Software\Classes\PROTOCOLS\Filter\
INFECTION WARNING! text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
NVC\(Default) = "{D5507020-DB45-11d1-A5F0-00600872F78D}"
-> {CLSID}\InProcServer32\(Default) = "C:\NORMAN\nvc\BIN\NVCSE.DLL" ["Norman Data Defense Systems"]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
NVC\(Default) = "{D5507020-DB45-11d1-A5F0-00600872F78D}"
-> {CLSID}\InProcServer32\(Default) = "C:\NORMAN\nvc\BIN\NVCSE.DLL" ["Norman Data Defense Systems"]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
InventorMenu\(Default) = "{6FDE7A70-351B-11d6-988B-0010B57A8BB7}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Autodesk\Inventor 10\Bin\DT.dll" ["Autodesk, Inc."]
NVC\(Default) = "{D5507020-DB45-11d1-A5F0-00600872F78D}"
-> {CLSID}\InProcServer32\(Default) = "C:\NORMAN\nvc\BIN\NVCSE.DLL" ["Norman Data Defense Systems"]


Active Desktop and Wallpaper:
-----------------------------

Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\daphne\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\sstext3d.scr" [MS]


Startup items in "daphne" & "All Users" startup folders:
--------------------------------------------------------

C:\Documents and Settings\daphne\¡u¶}©l¡v¥\¯àªí\µ{¦¡¶°\±Ò°Ê
"Adobe Gamma" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]

C:\Documents and Settings\All Users\¡u¶}©l¡v¥\¯àªí\µ{¦¡¶°\±Ò°Ê
"Service Manager" -> shortcut to: "C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe /n" [MS]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 04, 07 - 18
%SystemRoot%\system32\rsvpsp.dll [MS], 05 - 06


Toolbars, Explorer Bars, Extensions:
------------------------------------

Explorer Bars

Dormant Explorer Bars in "View, Explorer Bar" menu

HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\ = "****(&R)" (unwritable string)
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
"ButtonText" = "°Ñ¦Ò¸ê®Æ"


Miscellaneous IE Hijack Points
------------------------------

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
: ÿþ[ V e r s i o n ]

: S i g n a t u r e = " $ C H I C A G O $ "

: A d v a n c e d I N F = 2 . 5 , " Y o u n e e d a n e w v e r s i o n o f a d v p a c k . d l l "

:

: [ R e s t o r e H o m e P a g e ]

: A d d R e g = R e s t o r e H o m e P a g e . r e g

:

: [ R e s t o r e B r o w s e r S e t t i n g s ]

: A d d R e g = R e s t o r e B r o w s e r S e t t i n g s . r e g

: D e l R e g = D e l e t e T e m p l a t e s . r e g , D e l e t e A u t o s e a r c h . r e g

:

: [ R e s t o r e H o m e P a g e . r e g ]

: H K C U , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n " , " S t a r t P a g e " , 0 , % S T A R T _ P A G E _ U R L %

:

: [ R e s t o r e B r o w s e r S e t t i n g s . r e g ]

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n " , " D e f a u l t _ P a g e _ U R L " , 0 , % S T A R T _ P A G E _ U R L %

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n " , " D e f a u l t _ S e a r c h _ U R L " , 0 , % S E A R C H _ P A G E _ U R L %

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n " , " S e a r c h P a g e " , 0 , % S E A R C H _ P A G E _ U R L %

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n \ U r l T e m p l a t e " , " 1 " , 0 , " w w w . % s . c o m "

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n \ U r l T e m p l a t e " , " 2 " , 0 , " w w w . % s . o r g "

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n \ U r l T e m p l a t e " , " 3 " , 0 , " w w w . % s . n e t "

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n \ U r l T e m p l a t e " , " 4 " , 0 , " w w w . % s . e d u "

: H K C U , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n " , " S e a r c h P a g e " , 0 , % S E A R C H _ P A G E _ U R L %

:

: ; N O T E ( a n d r e w g u ) i e 5 . 5 b # 1 0 8 2 5 9 - a u t o s e a r c h s e t t i n g s a r e n o t p r o p e r l y r e s e t

: H K C U , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ S e a r c h U r l " , " P r o v i d e r " , 0 , " "

:

: t m "

: t m "

: H K L M , " S o f t w a r e \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ I n t e r n e t S e t t i n g s \ S a f e S i t e s " , % S A F E S I T E _ V A L U E % , 0 , " h t t p : / / i e . s e a r c h . m s n . c o m / * "

:

: [ D e l e t e T e m p l a t e s . r e g ]

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n \ U r l T e m p l a t e " , " 5 "

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n \ U r l T e m p l a t e " , " 6 "

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n \ U r l T e m p l a t e " , " 7 "

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n \ U r l T e m p l a t e " , " 8 "

: H K L M , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n \ U r l T e m p l a t e " , " 9 "

:

: [ D e l e t e A u t o s e a r c h . r e g ]

: ; N O T E ( a n d r e w g u ) i e 5 . 5 b # 1 0 8 2 5 9 - a u t o s e a r c h s e t t i n g s a r e n o t p r o p e r l y r e s e t

: H K C U , " S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n " , " A u t o S e a r c h "

:

: [ S t r i n g s ]

: S T A R T _ P A G E _ U R L = h t t p : / / w w w . f u j i t s u - p c - a s i a . c o m

: S E A R C H _ P A G E _ U R L = " h t t p : / / w w w . m i c r o s o f t . c o m / i s a p i / r e d i r . d l l ? p r d = i e & a r = i e s e a r c h "

: S A F E S I T E _ V A L U E = " i e . s e a r c h . m s n . c o m "

:

: ; I M P O R T A N T N O T E :

: ; I E b r a n d i n g d l l ( i e d k c s 3 2 . d l l ) u s e s t h e f o l l o w i n g e n t r i e s t o r e s t o r e t h e d e f a u l t M S v a l u e s .

: ; I n t h e v a n i l l a v e r s i o n o f I E , t h e v a l u e s m u s t b e t h e s a m e a s t h e i r c o r r e s p o n d i n g n o n M S _ * v a l u e s .

: ; F o r e x a m p l e , S T A R T _ P A G E _ U R L a n d M S _ S T A R T _ P A G E _ U R L m u s t h a v e t h e s a m e U R L i n t h e I E v e r s i o n r e l e a s e d b y M S .

: M S _ S T A R T _ P A G E _ U R L = " h t t p : / / w w w . m i c r o s o f t . c o m / i s a p i / r e d i r . d l l ? p r d = i e & p v e r = 6 & a r = m s n h o m e "

:

Missing lines (compared with English-language version):
[Version]: 2 lines
[RestoreHomePage]: 1 line
[RestoreHomePage.reg]: 1 line
[RestoreBrowserSettings.reg]: 12 lines
[DeleteTemplates.reg]: 5 lines
[DeleteAutosearch.reg]: 1 line
[Strings]: 1 line
[RestoreBrowserSettings]: 2 lines
[Strings]: 3 lines


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\System32\Ati2evxx.exe" ["ATI Technologies Inc."]
MSSQL$INVENTORCONTENT, MSSQL$INVENTORCONTENT, "C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe -sINVENTORCONTENT" [MS]
Norman NJeeves, Norman NJeeves, "C:\NORMAN\nvc\BIN\NJEEVES.EXE" [null data]
Norman ZANDA, Norman ZANDA, "C:\Norman\NVC\BIN\Zanda.exe" [null data]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]


----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 19 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 17 seconds.
---------- (total run time: 64 seconds)
zenigame211
sorry about not posting the new hijack log cuz the computer is not with me now... i will post it on asap.!
Mosaic1
Try this.

Restart into Safe mode.

Run the Killbox.

Select Standard File kill

Paste in this path and then press the red button to delete.

C:\windows\system32\scvhost.exe




Restart the computer.


Run hijackthis again please and post the new log.
zenigame211
Logfile of HijackThis v1.99.1
Scan saved at ¤W¤È 06:43:05, on 2005/10/30
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\NORMAN\nvc\BIN\NJEEVES.EXE
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\WINDOWS\LTSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\WINDOWS\System32\conime.exe
C:\NORMAN\nvc\BIN\ZLH.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\scvhost.exe
C:\NORMAN\nvc\BIN\NYMSE.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Hijackthis\HijackThis.exe

O3 - Toolbar: ¦¬­µ¾÷(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: ¶×¥X¦Ü Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: °Ñ¦Ò¸ê®Æ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.fujitsu-pc-asia.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\NORMAN\nvc\BIN\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\NVC\BIN\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\NORMAN\nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\NORMAN\nvc\BIN\NVCSCHED.EXE
Mosaic1
We need to disable your Microsoft AntiSpyware Real-time Protection as it may interfere with the fixes that we need to make. It can be enabled when your clean.

Open Microsoft AntiSpyware.
Click on Tools, Settings.
In the left pane, click on Real-time Protection.
Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
_ _ _ _


*******Update your Anti Virus software.

--------------------


Download now and then run Cleanup while you are offline.

http://home.comcast.net/~sgould4567/softwa...p/download.html

Learn how to use Cleanup:
http://home.comcast.net/~sgould4567/softwa...up/running.html




If your anti virus can run in Safe mode, run a full system scan while in Safe mode and let it clean all.


At any rate, be sure to boot to safe mode.

Open the C:\windows\system32 folder and
Rename this file:
ctfmon.exe

Right click on ctfmon.exe and choose rename. Rename is as ctfmon.old




Run Hijackthis. Select the following items and press the fix checked button.

O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe



Run Killbox.exe by double clicking on it.

Select Replace on Reboot.

Select Use dummy.

Paste this path into the Full Path fo file to Delete box.
C:\WINDOWS\System32\scvhost.exe

Click the red icon with the white X at the upper right.

You will be prompted to restart. Say yes and exit.

-------------------

Once back into windows go back and get another Panda Scan. Allow it to clean. Save the log and post the results.

Post a new Hijackthis log.
----


Let's have you run McAffee's stinger.

Follow the directions and get the download on this page:
http://vil.nai.com/vil/stinger

Run Stinger.

Please create a log and post that.
Mosaic1
Another thing is that I see no Firewall running.

Zone Alarm offers a free firewall if you need one.

http://www.zonelabs.com/store/content/comp...reeDownload.jsp


And after she is clean, updating to SP2 is strongly recommended.
zenigame211
Incident Status Location

Virus:W32/Gaobot.FVK.worm Disinfected C:\WINDOWS\system32\scvhost.exe
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\RRRUSL9M\pokapoka66[1].exe
Adware:Adware/IST.ISTBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\RRRUSL9M\rmvbot[1].rar
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\RRRUSL9M\pokapoka73[1].exe
Adware:Adware/Exact.BargainBuddyNo disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\RRRUSL9M\dating[1].bmp
Dialer:Dialer.Gen No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\6HI523EP\China[1].exe
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\6HI523EP\silent_setup[1].exe
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\6HI523EP\silent_setup[2].exe
Adware:Adware/Exact.BargainBuddyNo disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\6HI523EP\-- Look for another playground --[1].bmp
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\6HI523EP\pokapoka76[1].exe
Adware:Adware/IST.ISTBar No disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\OD63G5I7\istdownload[1].exe
Adware:Adware/Exact.BargainBuddyNo disinfected C:\Documents and Settings\daphne\Local Settings\Temporary Internet Files\Content.IE5\0ZQ7IX67\virus[1].bmp
Virus:W32/Gaobot.FVK.worm Disinfected C:\Documents and Settings\daphne\bleh.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000059.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000060.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000088.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000099.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000100.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000104.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0000105.DLL
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001959.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001960.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001964.DLL
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001965.DLL
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001978.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0001979.DLL
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0002013.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0002014.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0002015.DLL
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP3\A0002016.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP4\A0002967.dll
Adware:Adware/IST.ISTBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP4\A0002997.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP5\A0003036.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP5\A0003039.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP5\A0003040.dll
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018598.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018599.dll
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018615.exe
Virus:W32/Gaobot.JWE.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018616.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018617.exe
Virus:Trj/Dropper.KM Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018618.exe
Virus:Trj/Agent.AQF Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018619.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018629.dll
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018638.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018655.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018657.exe
Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018658.dll
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018659.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018665.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018675.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018691.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018698.EXE
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018703.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018713.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018730.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018738.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018744.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018755.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018769.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018771.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018779.exe
Virus:W32/Gaobot.FVK.worm Disinfected C:\!KillBox\scvhost.exe
zenigame211
Logfile of HijackThis v1.99.1
Scan saved at 上午 12:10:07, on 2005/10/31
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\WINDOWS\LTSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\NORMAN\nvc\BIN\ZLH.EXE
C:\WINDOWS\System32\conime.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\System32\scvhost.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\NORMAN\nvc\BIN\NYMSE.EXE
C:\NORMAN\nvc\BIN\NJEEVES.EXE
C:\Program Files\Hijackthis\HijackThis.exe

O3 - Toolbar: 收音機(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: 匯出至 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: 參考資料 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.fujitsu-pc-asia.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\NORMAN\nvc\BIN\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\NVC\BIN\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\NORMAN\nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\NORMAN\nvc\BIN\NVCSCHED.EXE
zenigame211
Hey there, it seems that
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
is still inside my computer. I've disabled anti spyeware, and followed exactly what you told me to do.
I will post the stinger file soon.
Mosaic1
Go get a trial version of Trojan Hunter too. Update and run it in Safe mode if possible.


http://www.misec.net/

Run stinger again.




Do that while Offline. Disconnect the modem while cleaning. Did you update the Anti Virus definitions?
zenigame211
McAfee AVERT Stinger Version 2.5.8 built on Oct 5 2005

Copyright © 2005 Networks Associates Technology, Inc. All Rights Reserved.

Virus data file v1000 created on Oct 5 2005.

Ready to scan for 54 viruses, trojans and variants.



Scan initiated on Mon Oct 31 00:18:58 2005

C:\WINDOWS\system32\Ati2mdxx.exe

Found the W32/Polybot.dr virus !!!

C:\WINDOWS\system32\Ati2mdxx.exe has been deleted.

Number of clean files: 41775

Number of infected files: 1

Number of files deleted: 1



Scan initiated on Mon Oct 31 00:24:19 2005

C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP4\A0002981.EXE

Found the W32/Polybot.dr virus !!!

C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP4\A0002981.EXE has been deleted.

C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018808.exe

Found the W32/Polybot.dr virus !!!

C:\System Volume Information\_restore{43B33D7F-1FC9-4DD2-8F30-8501BB8002B0}\RP22\A0018808.exe has been deleted.

Number of clean files: 120388

Number of infected files: 2

Number of files deleted: 2
zenigame211
I am using Roman antivirus and I didn't choose it myself. It was installed inside the computer. When I tried to update, it says, the file is over 10000kb, therefore it cannot be continued. I dont know why thats the case though
Mosaic1
You need to have a decent Anti Virus and it has to be up to date!

You need to run a firewall and after the cleanup, Winodws must be updated to Service Pack2.


Did you Run Trojan Hunter?

If so then let's see what it found.


Search for *.tcf files. These are the files Trojan hunter found and renamed.

Let's do it auto.

Go to Start >Run and type cmd.exe
Press enter

Cpoy this command and right click in the command window. CLick paste on the menu.
cd \ & dir /s /a *.tcf >TH.txt & Start Notepad TH.txt

This is going to search to the files if there are any.

It will open a text file named TH.txt when it finishes.
Please post the contents of TH.txt

And is the nasty you saw still listed in your Hijackthis running processes?
Mosaic1
You had a very nasty infection and still may have. You have not returned to follow up. This one replaces good system files with copies of itself. It's hard if not impossible to clean and it compromises security and steals information.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.