Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
Hi, i found this two threats using ESET Smart security. (This are the files C:\Documents and Settings\All Users\Application Data\SecTaskMan\kavo0.dll.q_804EC01_q - a variant of Win32/Pacex.Gen virus - unable to clean
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kavo.exe.q_804CB98_q - Win32/Pacex.Gen virus - unable to clean)
These are the problems with my laptop
* I can't open other applications like YM and Winrar
* My system are too slow
Here are the logs
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:37:03 PM, on 7/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Boot mode: Normal
Deckard's System Scanner v20071014.68
Run by Kina on 2008-07-27 13:38:10
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
41: 2008-07-27 05:38:16 UTC - RP167 - Deckard's System Scanner Restore Point
40: 2008-07-27 04:05:29 UTC - RP166 - Installed AVG Free 8.0
39: 2008-07-27 04:04:49 UTC - RP165 - Removed AVG Free 8.0
38: 2008-07-26 23:01:45 UTC - RP164 - Installed AVG Free 8.0
37: 2008-07-26 17:33:02 UTC - RP163 - System Checkpoint
-- First Restore Point --
1: 2008-06-11 06:39:12 UTC - RP127 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 1.02 GiB (less than 15%) free.
-- HijackThis (run as Kina.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:39:09 PM, on 7/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Boot mode: Normal
Class GUID: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
Description: USB Human Interface Device
Device ID: USB\VID_05AC&PID_8240\5&11730951&0&2
Manufacturer: (Standard system devices)
Name: USB Human Interface Device
PNP Device ID: USB\VID_05AC&PID_8240\5&11730951&0&2
Service: HidUsb
You have a flash drive infection. Please download Flash_Disinfector by sUBs and save it to your desktop:
NOTE: In the event you already have Flash_Disinfector, this is a new version that I need you to download.
Plug in your USB flash drive.
Double-click Flash_Disinfector.exe to run it.
Follow any prompts that may appear.
Your desktop will vanish for a while, and then reappear. This is normal.
Wait until the program has finished scanning, then please exit the program. If you use more than 1 flash drive, run the tool with each plugged in.
Next, download ComboFix by sUBs from here, saving the file to your desktop.
Please disable realtime protection applications as they sometimes interfere with the tool. Check this link for your applicable programs.
Close all open programs and windows
Double click combofix.exe and follow the prompts.
It may reboot your computer and resume running when you logon. Wait for it to complete. When finished, it will open a log for you. Post that log in your next reply.
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Thanks for the help...
Here is the log file of ComboFix.
ComboFix 08-07-26.1 - Kina 2008-07-29 19:28:47.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1542 [GMT 8:00]
Running from: C:\Documents and Settings\Kina\My Documents\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-29 )))))))))))))))))))))))))))))))
.
ComboFix 08-07-26.1 - Kina 2008-07-28 22:02:01.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1532 [GMT 8:00]
Running from: C:\Documents and Settings\Kina\My Documents\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\Documents and Settings\Kina\Application Data\inst.exe
.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 )))))))))))))))))))))))))))))))
.
Close all other windows and programs. Now drag the CFScript.txt onto ComboFix.exe and drop it, using the left mouse button. Combofix should run and may reboot the computer when it's done. A log will open when it's complete. Post the contents of that log.
Please do not click on the ComboFix window while it is running a scan. This can cause it to stall.
Please note that I have instructed CFScript to collect some files for analysis. This means that when ComboFix finishes, you will be prompted to allow ComboFix to upload a zip file that was created on your desktop. The zip contains the aforementioned files. Please copy the path shown in the prompt and paste it into the box, then click Send.
Thanks!
Here is the new log file of Combofix and already submitted the files for analysis.
ComboFix 08-07-26.1 - Kina 2008-08-01 22:30:43.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1543 [GMT 8:00]
Running from: C:\Documents and Settings\Kina\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kina\My Documents\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-07-01 to 2008-08-01 )))))))))))))))))))))))))))))))
.
Thanks for the upload! Those files are all infected, and now there's another new one. Let's nuke 'em.
Please delete the ComboFix.exe file you currently have and download a fresh copy from here, saving it to your desktop. So you know, ComboFix has a new icon.
Once again, please disable any realtime protection applications. Highlight and copy the contents of the code box below and paste it into a blank notepad, then save it to your desktop as;
Filename: CFScript.txt
Save As Type: All Files (*.*)
Close all other windows and programs. Now drag the CFScript.txt onto ComboFix.exe and drop it, using the left mouse button. Combofix should run and may reboot the computer when it's done. A log will open when it's complete. Post the contents of that log and a fresh HijackThis log.
Please do not click on the ComboFix window while it is running a scan. This can cause it to stall.
Please note that I have instructed CFScript to collect some files. This means that when ComboFix finishes, you will be prompted to allow ComboFix to upload a zip file that was created on your desktop. The zip contains the aforementioned files. Please copy the path shown in the prompt and paste it into the box, then click Send. This will assist the author in adding the files for removal in future updates. Thanks!
I really appreciate your effort helping me with this problem.
Thanks a lot dude...
Here's the new log file of ComboFix and I already submitted the zip file for analysis.
ComboFix 08-08-01.05 - Kina 2008-08-03 9:40:33.4 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1521 [GMT 8:00]
Running from: C:\Documents and Settings\Kina\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kina\My Documents\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kavo.exe.q_804CB98_q
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kavo0.dll.q_804EC01_q
C:\lgnaqil.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\._32fsU30.exe
C:\2moh9y.exe
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kavo.exe.q_804CB98_q
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kavo0.dll.q_804EC01_q
C:\gd6.exe
C:\sdb.exe
C:\WINDOWS\system32\kvosoft.exe
C:\WINDOWS\system32\sool0.dll
C:\WINDOWS\system32\sool1.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-03 to 2008-08-03 )))))))))))))))))))))))))))))))
.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, August 04, 2008 4:52:17 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/08/2008
Kaspersky Anti-Virus database records: 1051288
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
G:\
Scan Statistics:
Total number of scanned objects: 76717
Number of viruses found: 14
Number of infected objects: 39
Number of suspicious objects: 0
Duration of the scan process: 00:50:18
Infected Object Name / Virus Name / Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\ulso0.dll Infected: not-a-virus:AdWare.Win32.BBT.gw skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{44F6870C-1F91-4F25-8CC9-4BB2EB3FCF8E}.bin Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\ESET\ESET Smart Security\Logs\virlog.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\ESET\ESET Smart Security\Logs\warnlog.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\ESET\ESET Smart Security\Logs\epfwlog.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\ESET\ESET Smart Security\Charon\CACHE.NDB Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD52EBD0A-916D-4CF6-90BE-5DE7716698A4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS637E3EFD-592F-4B06-9D27-3DD262DA3058.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEE9815E1-4889-494F-BE68-523B44071B1A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS73487139-99C0-4A0A-A011-3A7039E90EE7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6D2C2827-A71B-4810-BD0B-37C5086D6791.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0E5F0DCE-1FB5-4F7B-81F4-E14861A9F1FA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS94EAE5BD-DE13-4A46-B2BB-5A942DC28B6B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS90D1FB08-273C-4CE1-9C42-A4C3830DFADF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS92389C2E-CEC8-41CB-BFBB-B0EC08D45AD6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0F36D4B3-E4A5-4B39-A88A-7C081DDDB5F7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3B87001E-A7E2-4C0F-82A8-474910726781.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE523B122-557A-48B1-959A-73C46E8070B2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA1BC8AC5-54A1-45A9-9C2C-A59220CEBEFF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS92976E90-C3A4-4645-AECE-0F0E53215AF4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA57D828B-4544-427D-9B34-28222DDF8CC2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS31D1E41F-FCE0-497D-B053-29C58400FC43.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS044B7D86-DB6B-46FA-9322-42AD0EDC4CE4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS21F048F3-9E81-49B8-8080-C244DFCEBFFE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS97494C1A-C44F-4E7C-A5C8-308EDBA13778.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3D10ACBE-8283-4230-AFCB-95E61A5261CF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEF1AB4B3-AC61-473F-9FEC-DAC575D61AFE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4E8A3A4E-04EF-48C5-846A-E7F41094CAB5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1F8EBE79-B06F-4FD3-A76E-6484FA997B2F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS75489632-8EBD-49BF-90D8-48AE3B0F0838.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS163EC96D-26E5-4C90-8F63-CB9DDEA347A3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDEC9E49E-B2CF-4DDF-849C-884DE685E1B3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS86A120B5-1320-404A-95BC-FC22B744DF36.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1ED50C7F-14C6-4B6A-9C61-B948289EE596.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS17B61F8B-E46C-4AA2-8D10-DD9C08F90FC9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4BC57BBC-7D4C-4FEA-8FEE-DD302FF3F06F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS36F660AB-6370-4F70-821C-5C9EFCB5EA42.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDC78B304-DDEB-4CA9-8D70-384656DEB797.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2555C21D-3ED0-4CDB-A6B2-CF7092146327.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5104F9F2-CA47-460D-A764-44AE47C33A9C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFEAF44FD-8EA7-48F1-A412-2C11884D1B8E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS00E96126-F139-402B-A20D-38FEED23B497.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS47CD14E1-E156-47D1-8A1F-362659538889.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8EB79EF6-093A-47FB-956A-628135F7823C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS919F814E-FAD8-411F-9B43-9C4D29BA082A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS795CF69A-9D9F-460E-926B-6F39ED34FEA4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS150EDC71-D400-439C-BC6C-5B8ABA9006FC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE19751A3-7C2E-471D-B5C4-C4C73B96A445.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS17724020-BD6C-4890-9D62-8EA6954C5D68.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7B47C053-22AC-4612-8DD6-0A6E33AE670C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS602E93CB-BE06-4059-B7EC-C8AB227673A9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB6505D35-3E24-4CD9-9671-47F02A6C5DED.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA361F361-2BE2-44E1-9E4D-FF5C13847C6A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS72819AAC-7553-4933-B031-8B08EEC8F141.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB18E6702-8B9B-4D1B-8E28-E7B5367F0FAF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS03725442-1CBD-413C-A704-46BDF6DB6B5A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS41E2B459-2955-4B4E-A4BF-3E065A4DA7F2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4D3A3C79-533A-4CE3-8DF8-D3519854543A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5F5039C5-088C-44F9-AD8F-0463E8427CA9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEB876339-56E9-4F5D-8126-3B7C87E466FE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8A47AAA9-190A-46E9-B9B0-A7A7EFCE6E38.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6F1F7407-8CBE-4CE5-BCEC-448020B9E7A8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD44141B1-34A1-4B78-AA61-42ECF86C8AA5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDEC67BDF-9907-465D-999B-D1A4F4183CDD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS74DDF874-CFF1-406A-BB8D-00E9D9F595C6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS642435E4-414C-40D3-91EE-1DD84031293E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA12F1A07-2F27-4891-8E40-CBA0ECEEFB2B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3EFE7069-4234-4887-B55A-1E07943DA9DA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS625878EB-FEF3-4CF7-BF7D-65F08CFD839F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF752D015-0E54-4B53-96CF-92048DF14264.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCE934A4D-AFF8-4B70-A4B0-58EF65AEC204.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC223E7EC-CE67-432A-A638-0FB83D0F91B8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS221326E9-F957-4CD0-9D91-3F2BC02846A2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2441F6BA-3D52-49BD-BD86-C39052099750.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS06E8BF73-F46E-4AA7-9B77-430511A1C2A2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA14FA951-3EA7-422A-939C-30F40422234A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSABDDCD29-BDEA-47EE-BD21-1218A0E2EE94.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2CD72CC2-ADBE-410C-B922-A3CCBB4FF0CE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5F61314D-8146-41DB-BC70-D6E00F8C8618.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS48A10B1A-2396-43E8-8DA3-0972BC174D79.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA0A787AF-FCF6-46C7-87BE-10C634A4635D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF9EC9B0F-6072-4035-9A90-0724FC85FD46.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS17C289DA-5371-4791-9FBD-7A57C9DE22CE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS40213BAD-77A4-42D4-BEEE-A801259F2075.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDA28115F-2435-4128-B602-14D56E3D6C58.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS037DBCB7-A6C4-40EF-882A-F39DDCD603DF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS142FD4ED-0FBB-4028-A623-4BF8032E7AED.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2FA47F24-C416-4CD3-A243-BA3CBD0FD136.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8660D916-08F8-4FF4-B839-4113C0CB8984.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS46387ED3-04D9-44DD-880D-241214C9C42F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9D230E31-D317-4FA0-81A4-2499CC768CE5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS18B0F291-44D2-4FA2-B1B4-9714976B0746.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS97276326-46DC-43B3-A3CB-F3F5CC133B64.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBA13EB5D-F129-405E-B44B-EBFFCE78BC81.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5873FE4F-7DC3-41C4-8EE5-42EEEFF48D2C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Kina\NtUser.dat.LOG Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\History\History.IE5\MSHist012008080420080805\index.dat Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\History\History.IE5\MSHist012008072820080804\index.dat Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\temp\Perflib_Perfdata_ed4.dat Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\temp\fla173.tmp Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\temp\Perflib_Perfdata_874.dat Object is locked skipped
C:\Documents and Settings\Kina\Local Settings\temp\~DFF3AE.tmp Object is locked skipped
C:\Documents and Settings\Kina\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Kina\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\history.dat Object is locked skipped
C:\Documents and Settings\Kina\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\parent.lock Object is locked skipped
C:\Documents and Settings\Kina\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\cert8.db Object is locked skipped
C:\Documents and Settings\Kina\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\key3.db Object is locked skipped
C:\Documents and Settings\Kina\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Kina\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Kina\Application Data\Mozilla\Firefox\Profiles\vmbdzf0a.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Kina\Application Data\Webroot\Spy Sweeper\Logs\080804070231.ses Object is locked skipped
C:\Documents and Settings\Kina\NTUSER.DAT Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\client_Kina.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\network_Kina.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\billing_Kina.log Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP162\A0055809.inf Infected: Worm.Win32.AutoRun.eoa skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP162\A0055826.dll Infected: not-a-virus:AdWare.Win32.BBT.fx skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP162\A0055830.exe Infected: Trojan.Win32.Vaklik.cie skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP162\A0055843.DLL Infected: not-a-virus:AdWare.Win32.BBT.fx skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP162\A0055847.exe Infected: Trojan.Win32.Vaklik.cie skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP162\A0055857.DLL Infected: not-a-virus:AdWare.Win32.BBT.fx skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP162\A0055861.exe Infected: Trojan.Win32.Vaklik.cie skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP163\A0055977.exe Infected: Trojan.Win32.Vaklik.cie skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP164\A0055987.exe Infected: Trojan.Win32.Vaklik.cie skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP164\A0056017.DLL Infected: not-a-virus:AdWare.Win32.BBT.fx skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP166\A0056111.DLL Infected: not-a-virus:AdWare.Win32.BBT.fx skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP166\A0056114.exe Infected: Trojan.Win32.Vaklik.cie skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP166\A0056126.DLL Infected: not-a-virus:AdWare.Win32.BBT.fx skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP166\A0056133.exe Infected: Trojan.Win32.Vaklik.cie skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP166\A0056135.exe Infected: Trojan.Win32.Vaklik.cie skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP167\A0056138.exe Infected: Trojan.Win32.Vaklik.ciq skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP168\A0057126.DLL Infected: not-a-virus:AdWare.Win32.BBT.ga skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP168\A0057133.exe Infected: Trojan.Win32.Vaklik.ciq skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP168\A0057135.exe Infected: Trojan.Win32.Vaklik.ciq skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP169\A0057155.exe Infected: Trojan.Win32.Vaklik.cjl skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP171\A0057303.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP171\A0057309.exe Infected: Backdoor.Win32.Hupigon.dckd skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP171\A0058126.DLL Infected: not-a-virus:AdWare.Win32.BBT.gg skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP171\A0058133.exe Infected: Trojan.Win32.Vaklik.cjl skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP171\A0058134.exe Infected: Trojan.Win32.Vaklik.cjl skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP172\A0058143.exe Infected: Trojan.Win32.Vaklik.cnm skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP174\A0058230.exe Infected: Trojan.Win32.Vaklik.ciq skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP174\A0058231.exe Infected: Trojan.Win32.Vaklik.cjl skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP174\A0058232.exe Infected: Trojan.Win32.Vaklik.cnm skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP174\A0058233.EXE Infected: Trojan.Win32.Vaklik.cnm skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP174\A0058235.dll Infected: Trojan.Win32.Inject.epv skipped
C:\System Volume Information\_restore{E430164D-D535-4102-BDE1-2860C0A836B0}\RP175\change.log Object is locked skipped
C:\Photoshop\mIRC - English.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.63 skipped
C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
C:\QooBox\Quarantine\C\Documents and Settings\All Users\Application Data\SecTaskMan\kavo.exe.q_804CB98_q.vir Infected: Trojan-PSW.Win32.OnLineGames.aiof skipped
C:\QooBox\Quarantine\C\2moh9y.exe.vir Infected: Trojan.Win32.Vaklik.ciq skipped
C:\QooBox\Quarantine\C\gd6.exe.vir Infected: Trojan.Win32.Vaklik.cjl skipped
C:\QooBox\Quarantine\C\sdb.exe.vir Infected: Trojan.Win32.Vaklik.cnm skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\kvosoft.exe.vir Infected: Trojan.Win32.Vaklik.cnm skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\sool1.dll.vir Infected: Trojan.Win32.Inject.epv skipped
C:\$Persi0.sys Object is locked skipped
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:55:56 PM, on 8/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Boot mode: Normal
Should be the final run. Please delete the ComboFix.exe file you currently have and download a fresh copy from here, saving it to your desktop. The icon has been changed recently, so don't be alarmed if it's different that what you currently have.
Once again, please disable any realtime protection applications. Highlight and copy the contents of the code box below and paste it into a blank notepad, then save it to your desktop as;
Filename: CFScript.txt
Save As Type: All Files (*.*)
Close all other windows and programs. Now drag the CFScript.txt onto ComboFix.exe and drop it, using the left mouse button. Combofix should run and may reboot the computer when it's done. A log will open when it's complete. Post the contents of that log here.
Please do not click on the ComboFix window while it is running a scan. This can cause it to stall.
Please note that I have instructed CFScript to collect some files. This means that when ComboFix finishes, you will be prompted to allow ComboFix to upload a zip file that was created on your desktop. The zip contains the aforementioned files. Please copy the path shown in the prompt and paste it into the box, then click Send. This will assist the author in adding the files for removal in future updates. Thanks!
Thanks for the great help...
Here's the log file of ComboFix
ComboFix 08-08-04.01 - Kina 2008-08-05 12:51:43.5 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1519 [GMT 8:00]
Running from: C:\Documents and Settings\Kina\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kina\My Documents\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ulso0.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-05 to 2008-08-05 )))))))))))))))))))))))))))))))
.
Great! Lets clean up now. Click Start>Run and type ComboFix /u then hit Enter to uninstall ComboFix and remove the files it has quarantined. This action will also reset the System Restore points, removing the infected files there as well. The C:\Deckard's folder will also be removed. You can delete any logs that were created/saved too.
You can delete Flash_Disinfector.exe as well.
Download ATF Cleaner by Atribune and save it to your Desktop.
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch
Java Cache
Recycle bin
The rest are optional - if you want it to remove everything check "Select All".
Finally, click Empty Selected. When you get the "Done Cleaning" message, click OK.
Your computer is now clean! Geri has posted some very helpful information and recommendations regarding future protection in the following link.