Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
hi my clients system are infected with below type of virus and eset no32 antivirus keep qurantaine all the time ..
C:\WINNT\System32\x
it's very hard to remove i have tried many things to delete it but again it comes after few mints or after few hours
here i have put my eset log file and hijack log too please need expert look tq
2/19/2009 12:42:04 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 12:41:53 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 12:37:46 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 12:37:36 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 12:31:45 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 12:31:35 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 11:54:13 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 11:54:02 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\internet explorer\iexplore.exe.
2/19/2009 11:52:13 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 11:52:02 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 11:45:45 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 11:08:15 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 11:05:56 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 11:00:05 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
2/19/2009 10:59:19 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Q359VMDZ\xjvsbeko[1].bmp a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 10:59:18 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 10:59:17 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\81IFOX2F\xjvsbeko[1].jpg a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 10:59:16 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 10:59:15 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Q359VMDZ\xjvsbeko[1].gif a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 3:13:50 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 3:10:03 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 3:06:04 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 2:30:16 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 2:26:29 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 2:23:17 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 1:46:51 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 1:43:13 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 1:40:27 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 1:35:40 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:40 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\41D66ADK\scop[1].png a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:39 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:39 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Q359VMDZ\scop[1].png a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:38 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:38 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\41D66ADK\scop[1].png a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:37 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:37 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Q359VMDZ\scop[1].bmp a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:36 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:36 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\41D66ADK\scop[1].bmp a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:35 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:35 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Q359VMDZ\scop[1].png a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:34 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:35:34 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\41D66ADK\scop[1].bmp a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 1:03:26 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 12:57:35 AM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/19/2009 12:57:06 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:56 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\M06WCV25\xjlb[1].gif a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:56 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:45 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\41D66ADK\xjlb[1].bmp a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:44 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:34 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\M06WCV25\xjlb[1].bmp a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:33 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:23 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\41D66ADK\xjlb[1].png a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:22 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:12 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\M06WCV25\xjlb[1].jpg a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:12 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:01 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\41D66ADK\xjlb[1].gif a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:56:01 AM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/19/2009 12:55:57 AM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\M06WCV25\xjlb[1].png a variant of Win32/Conficker.X worm cleaned by deleting (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/18/2009 11:11:52 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/18/2009 10:51:30 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/18/2009 10:51:30 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\cafeagent.exe.
2/18/2009 10:31:59 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe.
2/18/2009 10:31:59 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\cafeagent.exe.
2/18/2009 10:26:36 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/18/2009 10:26:36 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\cafeagent.exe.
2/18/2009 10:06:50 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/18/2009 9:42:30 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\cafeagent.exe.
2/18/2009 9:41:02 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\internet explorer\iexplore.exe.
2/18/2009 9:29:40 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
2/18/2009 9:29:40 PM Real-time file system protection file C:\WINNT\System32\olkfzwf.due a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
2/18/2009 9:18:35 PM Real-time file system protection file C:\WINNT\system32\olkfzwf.dll a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\services.exe.
2/18/2009 9:18:34 PM Real-time file system protection file C:\WINNT\System32\x a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
2/18/2009 9:18:34 PM Real-time file system protection file C:\WINNT\system32\olkfzwf.dll a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINNT\system32\services.exe.
2/18/2009 9:18:32 PM Real-time file system protection file C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\81IFOX2F\gcisrt[1].bmp a variant of Win32/Conficker.X worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINNT\system32\services.exe.
hijack log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:56:06 PM, on 2/19/2009
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
okey i here is my DDS log report and as i m using this windows 2000 machine and same this kind of virus also have been infected my windows xp machine..
hopefully by cleaning this system i will ask help for other windows xp machine..
DDS (Ver_09-02-01.01) - FAT32x86
Run by PC8 at 20:16:22.64 on Thu 02/19/2009
Internet Explorer: 6.0.2800.1106
Microsoft Windows 2000 Professional 5.0.2195.0.1252.1.1033.18.128.5 [GMT -8:00]
--------------------------------------------------------------------
Please Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
(Click on this link to see a list of programs that should be disabled.) http://www.bleepingcomputer.com/forums/topic114351.html
Double click on Combo-Fix.exe & follow the prompts.
** Please Note:
At times ComboFix may appear to stall, please be patient.
When finished, it will produce a report for you.
Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
Please only run the tool once, ty.
You may need several replies to post the requested logs, otherwise they might get cut off.
ComboFix 09-02-21.01 - PC8 02/24/2009 14:17:41.11 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.0.1252.1.1033.18.128.45 [GMT -8:00]
Running from: c:\documents and settings\ZR81\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-01-24 to 2009-02-24 )))))))))))))))))))))))))))))))
.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:24:52 PM, on 2/24/2009
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Print this topic or save to notepad, it will make it easier for you to follow the instructions and complete all of the necessary steps as we will need to close all windows that are open later in the fix.
C:\qoobox\ComboFix-quarantined-files.txt
Try to locate the above file and post it in your next reply.
Please locate the ComboFix icon on your desktop
Right click and select delete.....I want you to have an updated version.
Open HijackThis, Click Do a system scan only, checkmark these. Then close all other windows and browsers except HijackThis and press fix checked.
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ZR81/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
Next:Please disable all onboard security programs (all running with back ground protection) as it may hinder the scanner from working. This includes Antivirus, Firewall, and any Spyware scanners that run in the background.
Click on this link Here to see a list of programs that should be disabled.
The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the CODE box below:
Save this as "CFScript.txt" including quotes and change the "Save as type" to "All Files" and place it on your desktop.
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe. ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply. CAUTION:Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
NEXT**
I'd like for you to run this next online scan to check for remnants or anything that might be hidden.
The below scan can take up to an hour or longer, please be patient.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.
Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
Click on the Accept button and install any components it needs.
The program will install and then begin downloading the latest definition
files.
After the files have been downloaded on the left side of the page in the Scan section select My Computer.
This will start the program and scan your system.
The scan will take a while, so be patient and let it run. (At times it may appear to stall)
* Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
* Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
* Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in
your reply.
(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
Or use Firefox with IE-Tab plugin https://addons.mozilla.org/en-US/firefox/addon/1419
In your next reply post:
C:\qoobox\ComboFix-quarantined-files.txt
ComboFix.txt
Kaspersky log
New HJT log taken after the above scans have run
You may need several replies to post the requested logs, otherwise they might get cut off.
okey i follow your instruction and below are log files sorry i can't run kasperskyonline virus scan it's show can' found page and even i tried other i tried other online virus scan but same problem happen but i can browser other website
ComboFix 09-02-24.02 - PC8 02/25/2009 0:41:26.12 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.0.1252.1.1033.18.128.49 [GMT -8:00]
Running from: c:\documents and settings\ZR81\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\ZR81\Desktop\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-01-25 to 2009-02-25 )))))))))))))))))))))))))))))))
.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:44:07 AM, on 2/25/2009
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
thanx juliet if you can settle my problem today or tmrw because from friday to monday i will on the leave..
when i run the gmer.exe i recieve follownig error
c:\winnt\system32\config\system: the proces cannot acesss the file because it is being used by another process.
then press okey so i click on it.
then i do uncheck option u mentioned to me.
sections
IAt/EATS
files except c drive.
show all
when i run the scan i receive same above error that files in used..
after finish scan here is log file
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-02-26 14:23:42
Windows 5.0.2195
NEXT** Next:Please disable all onboard security programs (all running with back ground protection) as it may hinder the scanner from working. This includes Antivirus, Firewall, and any Spyware scanners that run in the background.
Click on this link Here to see a list of programs that should be disabled.
The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the CODE box below:
Save this as "CFScript.txt" including quotes and change the "Save as type" to "All Files" and place it on your desktop.
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe. ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply. CAUTION:Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine
NEXT**
A couple of things we can try to get GMER to run.
Copy (Ctrl +C) and paste (Ctrl +V) the text in the code box below to Notepad.
Code:
@echo off
Copy /y gmer.exe ark.exe
Start ark.exe
Save it into the gmer folder as File name: ark.cmd
Save as type: All Files
Once done, double click ark.cmd to run it.
This should start GMER, follow the steps I have outlined earlier to save a log file, then post me the contents in your next reply.
~~~~~~~~~~~~~~
If the above does not work
okey juliet sorry i was on leaves for fews days and i am back and i think the virus still infected the machine because i just check qurantaine files in eset32 antivirus same virus files detected okey
okey here is combofix log by running with script
ComboFix 09-03-02.03 - PC8 03/03/2009 23:42:33.13 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.0.1252.1.1033.18.128.84 [GMT -8:00]
Running from: c:\documents and settings\ZR81\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\ZR81\Desktop\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
by creating file ark.cmd into gmer folder and doesn't work and same error msg is appearing even i download the new Download SGmer.com and place it next to Gmer.exe http://techsupportforum.com/sectools/sUBs/sGmer.com
but same problems remaining tq
Next:Please disable all onboard security programs (all running with back ground protection) as it may hinder the scanner from working. This includes Antivirus, Firewall, and any Spyware scanners that run in the background.
Click on this link Here to see a list of programs that should be disabled.
The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
Save this as "CFScript.txt" including quotes and change the "Save as type" to "All Files" and place it on your desktop.
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe. ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply. CAUTION:Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location.
* You can also access the log by doing the following:
o Click on the Malwarebytes' Anti-Malware icon to launch the program.
o Click on the Logs tab.
o Click on the log at the bottom of those listed to highlight it.
o Click Open.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
In your next reply post: ComboFix.txt
Malwarebytes' Anti-Malware log
New HJT log
You may need several replies to post the requested logs, otherwise they might get cut off.
here is following requested logs ComboFix 09-03-02.03 - PC8 03/04/2009 1:51:34.14 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.0.1252.1.1033.18.128.83 [GMT -8:00]
Running from: c:\documents and settings\ZR81\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\ZR81\Desktop\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
c:\winnt\system32\Drivers\vdmzmzi2.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{85e06077-c824-43d0-a8dc-5efb17bc348a} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8109fd3d-d891-4f80-8339-50a4913ace6f} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{5937cd7f-1c0b-41e1-9075-60ebdf3c7d34} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove d\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\inte rnet antivirus pro_is1 (Rogue.InternetAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWe bSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\ZR81\Application Data\Desktopicon\eBayShortcuts.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MSN Messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\ZR81\Local Settings\Application Data\Microsoft\Windows\pguard.ini (Rogue.InternetAntivirus) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:51:18 AM, on 3/4/2009
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal