|  | 
 
															
															
	
			
			
				| WinAntiVirusPro/SysProtect |  |  
					
					
				 
						| mayuenNewbie 
   | 22. April 2006 @ 20:04 |  Link to this message   |  
						| 
							
							As like other posts, whenever I'm online, I constantly get the popups about Blackworm virus and the need to download WinAntiVirusPRO and/or SysProtect. Hope you can help to get rid of it. Thanks. 
 
 this is my Hijack log -
 
 Logfile of HijackThis v1.99.1
 Scan saved at 04:51:26, on 23/04/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\system32\atiptaxx.exe
 C:\Program Files\Compaq\EAB\EabServr.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\PROGRA~1\NORTON~1\navapw32.exe
 C:\Program Files\Winamp\Winampa.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\WINDOWS\System32\Ati2evxx.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\Program Files\Norton AntiVirus\navapsvc.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\Windows NT\Accessories\wordpad.exe
 C:\Downloads\HijackThis_v1.99.1.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.compaq.com/2Q00CPT/0404/bF8.asp
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ??
 N3 - Netscape 7: user_pref("browser.startup.homepage", ""); (C:\Documents and Settings\Jan\Application Data\Mozilla\Profiles\default\wk7j1z0h.slt\prefs.js)
 N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Jan\Application Data\Mozilla\Profiles\default\wk7j1z0h.slt\prefs.js)
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program Files\FlashGet\jccatch.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O2 - BHO: DPCUpdater Object - {E321ACA5-B12F-4D2C-B786-23B0A559CB21} - C:\WINDOWS\system32\hgdef.dll
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
 O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
 O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
 O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
 O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
 O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
 O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [Gnetmous] C:\Program Files\KYE\Genius PowerScroll Mouse\gnetmous.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O8 - Extra context menu item: ¥þ³¡¨Ï¥Î FlashGet ¤U¸ü - C:\Program Files\FlashGet\jc_all.htm
 O8 - Extra context menu item: ¨Ï¥Î FlashGet ¤U¸ü - C:\Program Files\FlashGet\jc_link.htm
 O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
 O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
 O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple...
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/180262726b86b0a64e04/netzip/RdxIE601_...
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl...
 O16 - DPF: {8FF3B649-FBFE-4089-B7E5-29C3AE90D976} (DownloadCtlVOD Class) - http://www.akiho.net/xvd/XVDDownloaderVOD.cab
 O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
 O16 - DPF: {E1261DD0-C69A-11D4-8434-0010B559D5E9} (SignCtl Class) - http://luckydraw.hongkongpost.gov.hk/formsign.dll
 O20 - Winlogon Notify: hgdef - C:\WINDOWS\system32\hgdef.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Norton AntiVirus ?????? (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 |  
						| Advertisement   |   |  
						|  |  
						| Senior Member 
   | 22. April 2006 @ 20:19 |  Link to this message   |  
						| 
							
							Hi mayuen. You have a trojan.vundo infection...
 You don't have a firewall on your computer. Download and install one firewall.
 
 These are good (free) firewalls:
 ZoneAlarm --> http://www.zonelabs.com
 Kerio--> http://www.sunbelt-software.com/Kerio.cfm
 Outpost-> http://www.agnitum.com
 
 Have you uninstalled Norton Antivirus?
 
 Cleaning instructions:
 
 Download VundoFix.exe to your desktop -> http://www.atribune.org/ccount/click.php?id=4
 
 * Double-click VundoFix.exe to run it.
 * Put a check next to Run VundoFix as a task.
 * You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
 * When VundoFix re-opens, click the Scan for Vundo button.
 * Once it's done scanning, click the Remove Vundo button.
 * You will receive a prompt asking if you want to remove the files, click YES
 * Once you click yes, your desktop will go blank as it starts removing Vundo.
 * When completed, it will prompt that it will shutdown your computer, click OK.
 * Turn your computer back on
 
 Run HijackThis and fix these entries (if found): (Do a system scan only, check entries, close all other windows, press Fix checked)
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ??
 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/180262726b86b0a64e04/netzip/RdxIE601_...
 
 
 Post a new HijackThis log and the contents of C:\vundofix.txt
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 22. April 2006 @ 20:20 |  
						| mayuenNewbie 
   | 22. April 2006 @ 22:23 |  Link to this message   |  
						| 
							
							Hi JaPK, I followed the first three steps:
 Download VundoFix.exe to your desktop -> http://www.atribune.org/ccount/click.php?id=4
 
 * Double-click VundoFix.exe to run it.
 * Put a check next to Run VundoFix as a task.
 * You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
 * When VundoFix re-opens, click the Scan for Vundo button.
 
 But about 30 seconds after clicking OK, a window open but close immediately, then nothing appear. what should I do?
 |  
						| Senior Member 
   | 22. April 2006 @ 23:06 |  Link to this message   |  
						| 
							
							Ok, try to run vundofix from safe mode...
 Restart your computer to the safe mode -> http://www.pchell.com/support/safemode.shtml
 
 * Double-click VundoFix.exe to run it.
 * Put a check next to Run VundoFix as a task.
 * You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
 * When VundoFix re-opens, click the Scan for Vundo button.
 * Once it's done scanning, click the Remove Vundo button.
 * You will receive a prompt asking if you want to remove the files, click YES
 * Once you click yes, your desktop will go blank as it starts removing Vundo.
 * When completed, it will prompt that it will shutdown your computer, click OK.
 * Turn your computer back on
 
 Then run HijackThis and fix these entries (if found): (Do a system scan only, check entries, close all other windows, press Fix checked)
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ??
 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/180262726b86b0a64e04/netzip/RdxIE601_...
 
 Restart your computer normally.
 
 Post a new HijackThis log and the contents of C:\vundofix.txt
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 22. April 2006 @ 23:16 |  
						| mayuenNewbie 
   | 22. April 2006 @ 23:27 |  Link to this message   |  
						| 
							
							Hi, thank you for your reply. here are the new log for vundofix and hijackthis. is it clean now?
 i've already installed Keiro as firewall, AVG as antivirus, windows defender and spybot.
 
 
 
 VundoFix V4.2.71
 
 Checking Java version...
 
 Scan started at 07:36:44 23/04/2006
 
 Listing files found while scanning....
 
 C:\WINDOWS\system32\hgdef.dll
 C:\WINDOWS\system32\fedgh.ini
 C:\WINDOWS\system32\fedgh.bak1
 C:\WINDOWS\system32\fedgh.bak2
 
 C:\WINDOWS\system32\fedgh.bak1
 C:\WINDOWS\system32\fedgh.bak2
 C:\WINDOWS\system32\fedgh.ini
 C:\WINDOWS\system32\hgdef.dll
 Attempting to delete C:\WINDOWS\system32\hgdef.dll
 C:\WINDOWS\system32\hgdef.dll Has been deleted!
 
 Attempting to delete C:\WINDOWS\system32\fedgh.ini
 C:\WINDOWS\system32\fedgh.ini Has been deleted!
 
 Attempting to delete C:\WINDOWS\system32\fedgh.bak1
 C:\WINDOWS\system32\fedgh.bak1 Has been deleted!
 
 Attempting to delete C:\WINDOWS\system32\fedgh.bak2
 C:\WINDOWS\system32\fedgh.bak2 Has been deleted!
 
 Performing Repairs to the registry.
 Done!
 
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 09:40:24, on 23/04/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\system32\atiptaxx.exe
 C:\Program Files\Compaq\EAB\EabServr.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Winamp\Winampa.exe
 C:\WINDOWS\System32\Ati2evxx.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\MSN Messenger\msnmsgr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
 C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Downloads\HijackThis_v1.99.1.exe
 
 N3 - Netscape 7: user_pref("browser.startup.homepage", ""); (C:\Documents and Settings\Jan\Application Data\Mozilla\Profiles\default\wk7j1z0h.slt\prefs.js)
 N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Jan\Application Data\Mozilla\Profiles\default\wk7j1z0h.slt\prefs.js)
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program Files\FlashGet\jccatch.dll
 O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
 O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
 O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
 O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
 O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
 O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [Gnetmous] C:\Program Files\KYE\Genius PowerScroll Mouse\gnetmous.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
 O8 - Extra context menu item: 使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm
 O8 - Extra context menu item: 全部使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm
 O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
 O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl...
 O16 - DPF: {E1261DD0-C69A-11D4-8434-0010B559D5E9} (SignCtl Class) - http://luckydraw.hongkongpost.gov.hk/formsign.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
 This message has been edited since posting. Last time this message was edited on 23. April 2006 @ 00:43 |  
						| Senior Member 
   | 23. April 2006 @ 01:20 |  Link to this message   |  
						| 
							
							You're clean now =)
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| mayuenNewbie 
   | 23. April 2006 @ 01:40 |  Link to this message   |  
						| 
							
							thank you for your help!!!
							
						 |  
						| Senior Member 
   | 23. April 2006 @ 01:55 |  Link to this message   |  
						| 
							
							You're welcome =)
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| mayuenNewbie 
   | 3. May 2006 @ 11:20 |  Link to this message   |  
						| 
							
							winfix pop up again. I've run vundofix and hijackthis. it seems that nothing has been found. here are the logs. is it still clean now?
 VundoFix V4.2.71
 
 Checking Java version...
 
 Scan started at 20:13:17 03/05/2006
 
 Listing files found while scanning....
 
 
 No infected files were found.
 
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 20:26:50, on 03/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\Ati2evxx.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
 C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\atiptaxx.exe
 C:\Program Files\Compaq\EAB\EabServr.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Winamp\Winampa.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\WINDOWS\system32\CTFMON.EXE
 C:\Program Files\MSN Messenger\msnmsgr.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Downloads\HijackThis_v1.99.1.exe
 
 N3 - Netscape 7: user_pref("browser.startup.homepage", ""); (C:\Documents and Settings\Jan\Application Data\Mozilla\Profiles\default\wk7j1z0h.slt\prefs.js)
 N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Jan\Application Data\Mozilla\Profiles\default\wk7j1z0h.slt\prefs.js)
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program Files\FlashGet\jccatch.dll
 O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
 O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
 O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
 O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
 O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
 O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [Gnetmous] C:\Program Files\KYE\Genius PowerScroll Mouse\gnetmous.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
 O8 - Extra context menu item: 使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm
 O8 - Extra context menu item: 全部使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm
 O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
 O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl...
 O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
 O16 - DPF: {E1261DD0-C69A-11D4-8434-0010B559D5E9} (SignCtl Class) - http://luckydraw.hongkongpost.gov.hk/formsign.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
 This message has been edited since posting. Last time this message was edited on 3. May 2006 @ 11:30 |  
						| Senior Member 
   | 4. May 2006 @ 03:08 |  Link to this message   |  
						| 
							
							Hi again mayuen. 
 Download Blacklight and save it to your desktop http://www.f-secure.com/blacklight/try.shtml
 
 Doubleclick blbeta.exe, accept agreement, click > Scan, then > Next
 
 You'll see a list what have been found. There will appear a log in desktop named fsbl.xxxxxxx.log (xxxxxxx will be random numbers ).
 
 Don't choose Rename if something was found!
 
 Post the following logs to here:
 -> fresh HijackThis log
 -> contents from fsbl.xxxx.log (blacklight log from your desktop).
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| mayuenNewbie 
   | 4. May 2006 @ 06:50 |  Link to this message   |  
						| 
							
							thank your for reply. The "winfix" did not pop up again in the last 3 hours in fact. 
 
 the blacklight said "Scan completed. No hidden items were found."
 
 05/04/06 15:32:05 [Info]: BlackLight Engine 1.0.36 initialized
 05/04/06 15:32:05 [Info]: OS: 5.1 build 2600 (Service Pack 2)
 05/04/06 15:32:05 [Note]: 7019 4
 05/04/06 15:32:05 [Note]: 7005 0
 05/04/06 15:32:16 [Note]: 7006 0
 05/04/06 15:32:16 [Note]: 7011 148
 05/04/06 15:32:16 [Note]: 7026 0
 05/04/06 15:32:16 [Note]: 7026 0
 05/04/06 15:32:30 [Note]: FSRAW library version 1.7.1015
 05/04/06 15:39:00 [Note]: 2000 1006
 05/04/06 15:39:00 [Note]: 2000 1006
 05/04/06 15:42:09 [Note]: 7007 0
 
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 15:43:58, on 04/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\atiptaxx.exe
 C:\Program Files\Compaq\EAB\EabServr.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\Program Files\Winamp\winampa.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\MSN Messenger\msnmsgr.exe
 C:\WINDOWS\System32\Ati2evxx.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
 C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Downloads\HijackThis_v1.99.1.exe
 
 N3 - Netscape 7: user_pref("browser.startup.homepage", ""); (C:\Documents and Settings\Jan\Application Data\Mozilla\Profiles\default\wk7j1z0h.slt\prefs.js)
 N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Jan\Application Data\Mozilla\Profiles\default\wk7j1z0h.slt\prefs.js)
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program Files\FlashGet\jccatch.dll
 O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
 O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
 O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
 O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
 O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [Gnetmous] C:\Program Files\KYE\Genius PowerScroll Mouse\gnetmous.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
 O8 - Extra context menu item: ¥þ³¡¨Ï¥Î FlashGet ¤U¸ü - C:\Program Files\FlashGet\jc_all.htm
 O8 - Extra context menu item: ¨Ï¥Î FlashGet ¤U¸ü - C:\Program Files\FlashGet\jc_link.htm
 O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
 O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl...
 O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
 O16 - DPF: {E1261DD0-C69A-11D4-8434-0010B559D5E9} (SignCtl Class) - http://luckydraw.hongkongpost.gov.hk/formsign.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
 This message has been edited since posting. Last time this message was edited on 4. May 2006 @ 06:55 |  
						| Advertisement   |   |  
						| 
 |  
						| Senior Member 
   | 4. May 2006 @ 09:51 |  Link to this message   |  
						| 
							
							Ok your logs are clean :) Let me know if those popups come back....
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  |