Hijack this log and internet trouble

  1. #1
    darkstar` is offline Newbie

    Hijack this log and internet trouble

    My internet has been spiking and inconsistent lately, and my ISP says it's due to spyware or a virus, I heard you guys were amazing so I'm going to post my log here

    Logfile of HijackThis v1.99.1
    Scan saved at 12:06:18 AM, on 8/3/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb1 0.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE
    C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
    C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\program files\valve\steam\steam.exe
    C:\Program Files\Creative\SBAudigy4\Entertainment Center\RcMan.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Common Files\AOL\1136262802\ee\aolsoftware.exe
    C:\Program Files\Ventrilo\Ventrilo.exe
    C:\Program Files\Xfire\Xfire.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.078\Hijac kThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.insightbb.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.insightbb.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [SAUpdate] C:\Program Files\Insight\BBClient\Programs\SAUpdate.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb1 0.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [SAClient] C:\Program Files\Insight\BBClient\Programs\RegCon.exe /admincheck
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
    O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [RemoteCenter] "C:\Program Files\Creative\SBAudigy4\Entertainment Center\RcMan.exe"
    O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - AutorunsDisabled - (no file)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15012/CTSUEng.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab30149.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...38&clcid=0x409
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st20040510.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by21fd.bay21.hotmail.msn.com/...s/MsnPUpld.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab30149.cab
    O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
    O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploa...loadClient.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab30149.cab
    O16 - DPF: {D3A7982E-915D-4589-8ECE-249F70D0C941} (Launch Control) - http://aaotracker.4players.de/LaunchGame.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15012/CTPID.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
    O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: Ethernet Service (EthernetService) - Unknown owner - ethernet.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe


  2. #2
    Neal is offline Dedicated Member
    Welcome,



    Create a folder such as C:\HJT or C:\Program Files\HJT and move HJT.exe into the newly created folder so we can have avaiable backups in case you fix the wrong thing or I make a mistake. Very important.



    To clean your temp folder, recycle bin, etc..please download this free tool:

    CCleaner

    Don't install any Toolbars, or other programs, should it ask you!Just uncheck the option of installing the Yahoo toolbar.
    It will put a shortcut on your Desktop.

    Before first use:
    Select Options then Advanced.
    UNCHECK "Only delete files in Windows Temp folder older than 48 hours"

    Click on CCleaner to start it. Then click "Run Cleaner", just use the windows tab up front by default.


    Then Reboot (Exit)





    Download and install
    Ewido anti-spyware
    4.0
    (uninstall any previous version first).
    • Click the Download BUTTON. On the next page click the
      Download now BUTTON.
    • Save and then install (Run) from the save location.
    • Open/Run ewido anti-spyware
    • Wait a few moments and Ewido should Auto update itself (note date of last
      update). If it doesn't update, click the update ICON at top of
      screen:

    • Click on the Update now LINK at the top of the window
      • Click on the Start update button
      • Wait for the update to download and install
  3. This is very important to get the LATEST
    updates

  4. Click on the Status ICON
    • Under "Your computers Security"
      Click change status on Resident shield to inactive
      (ONLY consider activation of that feature once you are
      clean)
  5. Click on the Scanner ICON at the top of the window
  6. Click on the Settings tab then select Recommended Actions
    and choose Quarantine




  7. Close ALL open Windows / Programs / Folders. Please start
    Ewido, and run a full scan:
    • Click on the default Status ICON and select
      the Scan now LINK.

      OR

    • Click on the Scanner ICON . Select the Scan
      TAB.

      • Select Complete System Scan. Ewido will now begin to scan your
        system.

    • If Ewido finds anything it will list them in the Preview WINDOW:
      • Make sure that Set all elements to: shows
        Quarantine, if not click on the link and choose
        Quarantine from the popup menu.
      • Select Apply all actions at the bottom of the window (and the
        items found will be quarantined - and recoverable, if any items are needed
        back).

    • When the scan has completed, click on the Save Scan Report button
      and save the scan to your Desktop where it can be easily found.
    • Copy and paste the EWIDO scan results into your next
      post.
    • Close Ewido.


    Go here BitDefender and run an online scan with BitDefender (you will need to use Internet Explorer for this scan). When the ActiveX Control has loaded, click on "Click here to scan" and grab a coffee.

    When BitDefender completes the scan, select the "Detected Problems" tab. Click on "Click here to export scan". Save the file as an HTML to your Desktop. Then click on the saved file and allow it to open with your browser. Go to Edit - Select All then copy/paste that log back here. Post back and let us know what it found (post the log).

    And post a new HJT log also..

  • #3
    darkstar` is offline Newbie
    alrighty here is everything

    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 7:30:54 PM 8/3/2006

    + Scan result:



    C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
    C:\WINDOWS\NDNuninstall4_85.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\Common.Buttons -> Adware.WebSearch : Cleaned with backup (quarantined).
    :mozilla.14:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\kqa0ue8u.default\coo kies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\msupdate.exe -> Trojan.VB.vv : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\19 2Pac Videos.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\2 Vibez - Just 4 You (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\7-Zip 4.18.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\ACDSee Standard 8.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\AIR - Premiers Symptomes.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\APSW Budget Planner 3.0.1.35.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Ace DVD Audio Extractor 1.2.26.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Ace DVD Backup 1.2.32.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Active MediaMagnet 4.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Adobe After Effects 6.5 Tutorials.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Adobe Photoshop 9 CS2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Adobe Photoshop CS2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Advanced Maillist Verify 4.25.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Advent Rising (Xbox).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\AirStrike II Gulf Thunder 2.52.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Alias PortfolioWall 2.2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\All About My Dog.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\All Project 7 apps and theme packs.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\AnyDVD 5.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\AnyDVD 5.2.6.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Ashampoo Burning Studio 5.0.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Ashampoo Photo Commander 3.02.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Attachment Reminder 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Avant Browser 10.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\BackRex Mail Backup 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Big Fish Games Atlantis.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Blade 3 Trinity.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Bogart 5.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\CHM2HTML Pilot 1.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Catch Me If You Can (2002).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\ChrisTV 4.60 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Civilization 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\CloneCD 5.2.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Cyberlink PowerCinema 4.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\DVD Audio Extractor 3.3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\DVDIdle Pro 5.9.3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Dangerous Google - Searching for Secrets.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Desktop Writer 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Diablo 2 ExpansionLord of Destruction.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Diet Tracker 3.0 PalmOS.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Dragon Reloaded.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Drome Racers.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\DynAdvance Notifier 1.1.51.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\EZ Extract Resource 1.85.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\EditPad Pro 5.4.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\EditPro 1.57.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Effective Site Studio Home 2004.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Effective Site Studio Photo 2004.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Effective Site Studio Pro 2004.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\FIFA 2005 SoundTracks.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Fantastic 4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Fantastipo The Movie.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\FileRecoveryAngel 1.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\FinePrint 5.41 Enterprise.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\FlexPde Professional 3D.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\FlightCheck Professional 5.60 for Mac.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\FlightCheck Professional 5.60 for Win.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Forgotten Mailbox Password 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Four Brothers (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\FreeFile 1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\GFI MailSecurity for ExchangeSMTP 9.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\HTML Search and Replace 1.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\HotDog Professional 7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Insane 4x4 Offroad Racing.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\International Cricket Captain 2005 1.05.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Invision Community Blog 1.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Iolo Search and Recover 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Jay-Z - The Argyle Album (The Black Albu.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\K-Lite Mega Codec Pack 1.29.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Kay Cee - Unsolved Mysteries.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Kelis - Tasty.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Kill Bill Vol. 2 (2004).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Macro Mania 10.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Maxthon 1.2.3 Combo.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Metal Gear Acid (PSP).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Mexican Motor Mafia.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Microsoft Office Pro 2003.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Microsoft Windows XP Tools 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Motion Studio 3.0.921.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\MySQL 5 Certification Study Guide Book.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Mysterious Skin.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Nero 6.6.0.16 Enterprise.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Nero Burning ROM 6.6.0.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Nero CD-DVD Speed 3.80.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\NextUp Talker 0.050.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Norton Antivirus 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Opera 8.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Out of Sight (1998).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\PSPWare 2.0.0.206.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Panda Platinum Internet Security 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Passware Kit 7.3 Enterprise.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Password Manager XP 2.0.281.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Photokorn.Gallery 1.542.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Power Phone Book Enterprise 1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Remote Administrator 2.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Resident Evil 2The Apocalypse.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Road Rush 1.7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\RoboGEO 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Rouge Skin For vBulletin 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\SPAMfighter Standard 3.5.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Scorched3D 38.1b.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Screen Movie Recorder 1.25.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\South Park Episodes.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Super DVD Creator 8.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Super Utilities Pro 5.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\The Afternoon Of A Torturer.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\The Italian Job.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\The Lord of the RingFellowship the Ring.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\The Lord of the Rings The Two Towers.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\The Passion Of The Christ OST.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Tomb Raider 5 Chronicles.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Torrent David Banner - Play (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\UltraEdit-32 11.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Usaf 2003.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Virtual CD 7.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Virtual Railroad 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\VisNetic MailFlow 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Visual SQL-Designer 3.99.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Wamasoft AutoTyping Pro 1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\War of the Worlds (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\WebGrab! 3.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Wild Wild West (1999).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Winamp 5.1 Surround Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Winferno PC Confidential 2005.2.212.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\Zoner Barcode Studio 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\eBook Imperial Ends.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\eBook Joel McNamara. GPS For Dummies.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Documents and Settings\Owner\Complete\mp3cue 5.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
    C:\Program Files\winupdates\winupdates.exe -> Worm.VB.an : Cleaned with backup (quarantined).


    ::Report end

    BitDefender Online Scanner



    Scan report generated at: Thu, Aug 03, 2006 - 21:37:44





    Scan path: A:\;C:\;D:\;E:\;







    Statistics

    Time
    02:02:00

    Files
    579575

    Folders
    6584

    Boot Sectors
    2

    Archives
    3334

    Packed Files
    50462




    Results

    Identified Viruses
    4

    Infected Files
    4

    Suspect Files
    0

    Warnings
    0

    Disinfected
    0

    Deleted Files
    4




    Engines Info

    Virus Definitions
    426627

    Engine build
    AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38)

    Scan plugins
    13

    Archive plugins
    39

    Unpack plugins
    5

    E-mail plugins
    6

    System plugins
    1




    Scan Settings

    First Action
    Disinfect

    Second Action
    Delete

    Heuristics
    Yes

    Enable Warnings
    Yes

    Scanned Extensions
    *;

    Exclude Extensions


    Scan Emails
    Yes

    Scan Archives
    Yes

    Scan Packed
    Yes

    Scan Files
    Yes

    Scan Boot
    Yes




    Scanned File
    Status

    C:\Program Files\Logitech\Resource Center\installers\wildtangent\blastrb2.exe=>(NSIS o)=>zlib_nsis0018
    Infected with: Trojan.Exploit.Html.Codebaseexec.CC

    C:\Program Files\Logitech\Resource Center\installers\wildtangent\blastrb2.exe=>(NSIS o)=>zlib_nsis0018
    Disinfection failed

    C:\Program Files\Logitech\Resource Center\installers\wildtangent\blastrb2.exe=>(NSIS o)=>zlib_nsis0018
    Deleted

    C:\Program Files\Logitech\Resource Center\installers\wildtangent\blastrb2.exe=>(NSIS o)
    Update failed

    C:\Turner's Stuff\52504.exe=>wise0019
    Infected with: Trojan.Dloader.HK

    C:\Turner's Stuff\52504.exe=>wise0019
    Disinfection failed

    C:\Turner's Stuff\52504.exe=>wise0019
    Deleted

    C:\Turner's Stuff\52504.exe
    Update failed

    C:\Turner's Stuff\52504.exe=>wise0020
    Infected with: Dropped:Application.Adware.NewDotNet.A

    C:\Turner's Stuff\52504.exe=>wise0020
    Disinfection failed

    C:\Turner's Stuff\52504.exe=>wise0020
    Deleted

    C:\Turner's Stuff\52504.exe
    Update failed

    C:\Turner's Stuff\52504.exe=>wise0022
    Infected with: Trojan.Muldrop.A

    C:\Turner's Stuff\52504.exe=>wise0022
    Disinfection failed

    C:\Turner's Stuff\52504.exe=>wise0022
    Deleted

    C:\Turner's Stuff\52504.exe
    Update failed


    Logfile of HijackThis v1.99.1
    Scan saved at 2:30:56 AM, on 8/4/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb1 0.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE
    C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
    C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\program files\valve\steam\steam.exe
    C:\Program Files\Creative\SBAudigy4\Entertainment Center\RcMan.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\AOL\1136262802\ee\aolsoftware.exe
    c:\program files\common files\aol\1136262802\ee\aim6.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.insightbb.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.insightbb.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [SAUpdate] C:\Program Files\Insight\BBClient\Programs\SAUpdate.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb1 0.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [SAClient] C:\Program Files\Insight\BBClient\Programs\RegCon.exe /admincheck
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
    O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [RemoteCenter] "C:\Program Files\Creative\SBAudigy4\Entertainment Center\RcMan.exe"
    O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - AutorunsDisabled - (no file)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15012/CTSUEng.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab30149.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...38&clcid=0x409
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st20040510.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by21fd.bay21.hotmail.msn.com/...s/MsnPUpld.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab30149.cab
    O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
    O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploa...loadClient.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab30149.cab
    O16 - DPF: {D3A7982E-915D-4589-8ECE-249F70D0C941} (Launch Control) - http://aaotracker.4players.de/LaunchGame.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15012/CTPID.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: Ethernet Service (EthernetService) - Unknown owner - ethernet.exe (file missing)
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

  • #4
    Neal is offline Dedicated Member
    Hi, nice job.


    From add/remove program remove:if present

    viewpoint
    viewpoint manager
    viewpoint media player



    Reboot after removal


    Run hijackthis and click on scan button and put a check next to this:

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe


    Nothing open but hijackthis and click on fix checked.


    Now reboot into safe mode by tapping your F8 key upon restart and safe mode screen appears, select safe mode and press enter.


    Navigate to these files or folders using Windows Explorer (OR Start -> Search) and delete (if present):



    DELETE FOLDERS

    C:\Program Files\Viewpoint


    Reboot and post a new hijackthis log please. How is your computer behaving now?

  • #5
    darkstar` is offline Newbie
    here is the new HJT log

    Logfile of HijackThis v1.99.1
    Scan saved at 3:20:31 PM, on 8/4/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb1 0.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE
    C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
    C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\program files\valve\steam\steam.exe
    C:\Program Files\Creative\SBAudigy4\Entertainment Center\RcMan.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\HJT\HijackThis.exe
    C:\WINDOWS\System32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.insightbb.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.insightbb.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [SAUpdate] C:\Program Files\Insight\BBClient\Programs\SAUpdate.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb1 0.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [SAClient] C:\Program Files\Insight\BBClient\Programs\RegCon.exe /admincheck
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
    O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [RemoteCenter] "C:\Program Files\Creative\SBAudigy4\Entertainment Center\RcMan.exe"
    O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - AutorunsDisabled - (no file)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15012/CTSUEng.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab30149.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...38&clcid=0x409
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st20040510.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by21fd.bay21.hotmail.msn.com/...s/MsnPUpld.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab30149.cab
    O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
    O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploa...loadClient.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab30149.cab
    O16 - DPF: {D3A7982E-915D-4589-8ECE-249F70D0C941} (Launch Control) - http://aaotracker.4players.de/LaunchGame.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15012/CTPID.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: Ethernet Service (EthernetService) - Unknown owner - ethernet.exe (file missing)
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    I couldn't find a trace of Viewpoint in safe mode afte adding/removing the program from the control panel and my internet seems to be fine for now, no sudden ping spikes or anything like that as of yet, I'll post if the problem continues

  • #6
    Neal is offline Dedicated Member
    Save 20% on AVG Internet Security 2012 Suite!
    Good news,


    Your sunjava is way out of date and is a security issue as is:


    * Go to Start > Control Panel double-click on the Software icon > add/remove programs.
    * Search in the list for all previous installed versions of Java. (J2SE Runtime Environment.... )

    It should have next icon next to it:
    Select it and click Remove.
    * Then Download and install the newest version from here:
    Sun Java


    Your log is clean.

  • + Reply to Thread

    Similar Threads