Thank you very much for the help. I let the executable you provided execute and remove the items it found. I then let it reboot and ran Hijackthis 2 Mbam logs were generated, I'll post them in order of generation separated by ======================= HiJackThis log &&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&& Everything is running very smooth now. For transparency this netbook was acting as a proxy server and I let 1 not savvy enough user have access; my suspicion is data from a shady site passed through. I was running Avira at the time of the virus but now have Avast (free) installed. Kaspersky is on my main pc and I'd welcome any advice you might have on most appropriate (efficient) yet effective security for a netbook. Thanks for your help!!! Malwarebytes' Anti-Malware 1.44 Database version: 3730 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 2/12/2010 11:22:41 AM mbam-log-2010-02-12 (11-22-31).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 148884 Time elapsed: 56 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 2 Registry Keys Infected: 5 Registry Values Infected: 3 Registry Data Items Infected: 3 Folders Infected: 5 Files Infected: 76 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: c:\WINDOWS\system32\depopuho.dll (Trojan.Vundo.H) -> No action taken. c:\WINDOWS\system32\yozuyosa.dll (Trojan.Vundo.H) -> No action taken. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{05c75b6f-2dd5-4a50-8e46-da50ff129f35} (Trojan.Vundo.H) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{77dc0baa-3235-4ba9-8be8-aa9eb678fa02} (Rogue.ASCAntispyware) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77dc0baa-3235-4ba9-8be8-aa9eb678fa02} (Rogue.ASCAntispyware) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{77dc0baa-3235-4ba9-8be8-aa9eb678fa02} (Rogue.ASCAntispyware) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADBUPD (Trojan.Agent) -> No action taken. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mepapirol (Trojan.Vundo.H) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{05c75b6f-2dd5-4a50-8e46-da50ff129f35} (Trojan.Vundo.H) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\depomimeh (Trojan.Vundo.H) -> No action taken. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\yozuyosa.dll -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\yozuyosa.dll -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. Folders Infected: C:\Documents and Settings\home\Start Menu\Programs\Your PC Protector (Rogue.YourPCProtector) -> No action taken. C:\Program Files\Your PC Protector (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images (Rogue.YourPCProtector) -> No action taken. C:\Your PC Protector (Rogue.PcProtector) -> No action taken. Files Infected: C:\WINDOWS\system32\depopuho.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\dorizala.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\gidahumu.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\hukubuhu.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\kirasahi.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\leheziti.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\mikolobe.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\nadejafi.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\nadusajo.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\negokofi.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\rahobofo.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\ravebavi.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\vujigami.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\yiriyidi.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\yozuyosa.dll (Trojan.Vundo.H) -> No action taken. C:\Documents and Settings\home\Local Settings\Temporary Internet Files\Content.IE5\PGUNUWIW\default[1].htm (Trojan.Vundo.H) -> No action taken. C:\Documents and Settings\home\Local Settings\Temporary Internet Files\Content.IE5\PGUNUWIW\BHOQS2lloHLBnBRDWZrZET0rHr2JTFeCHNA7AVSoeBDlw1fNRByx_062EtP5j691QTn3QUoLnkJ NdQnU94Ifp_V4QU0FoK3fs8_bUcH9ZN2aL4UKoOidg_jhHzgEr4kd-RKyJ2NwwEk6bROkhGBursypRD5MTRA[1].htm (Trojan.Vundo.Gen) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libaccess_output_http_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libmemcpymmxext_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libcolorthres_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libdtssys_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libi422_i420_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libimage_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libmemcpy3dn_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libmemcpymmx_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libntservice_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libquicktime_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libsimple_channel_mixer_plugin.dll (Trojan.Exploit) -> No action taken. C:\Program Files\VideoLAN\VLC\plugins\libstream_out_es_plugin.dll (Trojan.Exploit) -> No action taken. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP103\A0021308.dll (Trojan.Vundo.Gen) -> No action taken. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP103\A0021356.dll (Trojan.Vundo.Gen) -> No action taken. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025534.dll (Trojan.Vundo.Gen) -> No action taken. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025539.dll (Trojan.Vundo.H) -> No action taken. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025540.dll (Trojan.Vundo.H) -> No action taken. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025541.dll (Trojan.Vundo.H) -> No action taken. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025550.dll (Trojan.FakeAlert) -> No action taken. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025597.dll (Trojan.Vundo.H) -> No action taken. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025598.dll (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\trz4.tmp (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\vulademu.dll.tmp (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\buyenayo.dll.tmp (Trojan.Vundo.H) -> No action taken. C:\WINDOWS\system32\hiwumeku.dll.tmp (Trojan.Vundo.H) -> No action taken. C:\Documents and Settings\home\Start Menu\Programs\Your PC Protector\Your PC Protector.lnk (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\wispex.html (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\i1.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\i2.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\i3.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\j1.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\j2.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\j3.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\jj1.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\jj2.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\jj3.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\l1.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\l2.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\l3.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\pix.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\t1.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\t2.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\Thumbs.db (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\up1.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\up2.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\w1.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\w11.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\w2.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\w3.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\w3.jpg (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\word.doc (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\wt1.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\wt2.gif (Rogue.YourPCProtector) -> No action taken. C:\Program Files\schtml\images\wt3.gif (Rogue.YourPCProtector) -> No action taken. C:\Your PC Protector\Your PC Protector.lnk (Rogue.PcProtector) -> No action taken. C:\Your PC Protector.lnk (Rogue.PcProtector) -> No action taken. C:\Program Files\nuar.old (Malware.Trace) -> No action taken. C:\Program Files\wp3.dat (Malware.Trace) -> No action taken. C:\Program Files\wp4.dat (Malware.Trace) -> No action taken. ====================================================================== Malwarebytes' Anti-Malware 1.44 Database version: 3730 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 2/12/2010 11:23:04 AM mbam-log-2010-02-12 (11-23-04).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 148884 Time elapsed: 56 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 2 Registry Keys Infected: 5 Registry Values Infected: 3 Registry Data Items Infected: 3 Folders Infected: 5 Files Infected: 76 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: c:\WINDOWS\system32\depopuho.dll (Trojan.Vundo.H) -> Delete on reboot. c:\WINDOWS\system32\yozuyosa.dll (Trojan.Vundo.H) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{05c75b6f-2dd5-4a50-8e46-da50ff129f35} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{77dc0baa-3235-4ba9-8be8-aa9eb678fa02} (Rogue.ASCAntispyware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77dc0baa-3235-4ba9-8be8-aa9eb678fa02} (Rogue.ASCAntispyware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{77dc0baa-3235-4ba9-8be8-aa9eb678fa02} (Rogue.ASCAntispyware) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADBUPD (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mepapirol (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{05c75b6f-2dd5-4a50-8e46-da50ff129f35} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\depomimeh (Trojan.Vundo.H) -> Delete on reboot. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\yozuyosa.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\yozuyosa.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Documents and Settings\home\Start Menu\Programs\Your PC Protector (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\Your PC Protector (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Your PC Protector (Rogue.PcProtector) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\depopuho.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\dorizala.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\gidahumu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hukubuhu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\kirasahi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\leheziti.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mikolobe.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\nadejafi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\nadusajo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\negokofi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\rahobofo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ravebavi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vujigami.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yiriyidi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yozuyosa.dll (Trojan.Vundo.H) -> Delete on reboot. C:\Documents and Settings\home\Local Settings\Temporary Internet Files\Content.IE5\PGUNUWIW\default[1].htm (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Local Settings\Temporary Internet Files\Content.IE5\PGUNUWIW\BHOQS2lloHLBnBRDWZrZET0rHr2JTFeCHNA7AVSoeBDlw1fNRByx_062EtP5j691QTn3QUoLnkJ NdQnU94Ifp_V4QU0FoK3fs8_bUcH9ZN2aL4UKoOidg_jhHzgEr4kd-RKyJ2NwwEk6bROkhGBursypRD5MTRA[1].htm (Trojan.Vundo.Gen) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libaccess_output_http_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libmemcpymmxext_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libcolorthres_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libdtssys_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libi422_i420_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libimage_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libmemcpy3dn_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libmemcpymmx_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libntservice_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libquicktime_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libsimple_channel_mixer_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\Program Files\VideoLAN\VLC\plugins\libstream_out_es_plugin.dll (Trojan.Exploit) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP103\A0021308.dll (Trojan.Vundo.Gen) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP103\A0021356.dll (Trojan.Vundo.Gen) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025534.dll (Trojan.Vundo.Gen) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025539.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025540.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025541.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025550.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025597.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP105\A0025598.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\trz4.tmp (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vulademu.dll.tmp (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\buyenayo.dll.tmp (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hiwumeku.dll.tmp (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Start Menu\Programs\Your PC Protector\Your PC Protector.lnk (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\wispex.html (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\i1.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\i2.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\i3.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\j1.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\j2.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\j3.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\jj1.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\jj2.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\jj3.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\l1.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\l2.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\l3.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\pix.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\t1.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\t2.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\Thumbs.db (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\up1.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\up2.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\w1.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\w11.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\w2.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\w3.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\w3.jpg (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\word.doc (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\wt1.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\wt2.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Program Files\schtml\images\wt3.gif (Rogue.YourPCProtector) -> Quarantined and deleted successfully. C:\Your PC Protector\Your PC Protector.lnk (Rogue.PcProtector) -> Quarantined and deleted successfully. C:\Your PC Protector.lnk (Rogue.PcProtector) -> Quarantined and deleted successfully. C:\Program Files\nuar.old (Malware.Trace) -> Quarantined and deleted successfully. C:\Program Files\wp3.dat (Malware.Trace) -> Quarantined and deleted successfully. C:\Program Files\wp4.dat (Malware.Trace) -> Quarantined and deleted successfully. &&&&&&&&&&&&&&&& Hijackthis log &&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&& Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:27:26 AM, on 2/12/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\Program Files\Palm, Inc\novacom\x86\novacomd.exe C:\Program Files\SpoonProxy\spserv.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\SpoonProxy\proxy.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Elantech\ETDCtrl.exe C:\Program Files\Elantech\ETDDect.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\EeePC\ACPI\AsTray.exe C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe C:\Program Files\EeePC\ACPI\AsEPCMon.exe C:\WINDOWS\system32\igfxext.exe C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe C:\Program Files\OpenSSH\bin\cygrunsrv.exe C:\Program Files\OpenSSH\usr\sbin\sshd.exe C:\Documents and Settings\home\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\home\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\home\My Documents\Downloads\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eeepc.asus.com/global R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing) O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing) O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe O4 - HKLM\..\Run: [ETDWareDetect] C:\Program Files\Elantech\ETDDect.exe O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: Shortcut to proxy.lnk = C:\Documents and Settings\home\proxy.bat O4 - Startup: SpoonProxy.lnk = C:\Program Files\SpoonProxy\proxy.exe O4 - Global Startup: SuperHybridEngine.lnk = ? O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1240285653753 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1240285575840 O20 - AppInit_DLLs: c:\windows\system32\nutuhunu.dll ,vahoremo.dll O21 - SSODL: muviwahur - {1f12919b-0b15-4ba3-8c8d-c850af005fc9} - c:\windows\system32\nutuhunu.dll (file missing) O22 - SharedTaskScheduler: kupuhivus - {1f12919b-0b15-4ba3-8c8d-c850af005fc9} - c:\windows\system32\nutuhunu.dll (file missing) O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe O23 - Service: Palm Novacom (NovacomD) - Unknown owner - C:\Program Files\Palm, Inc\novacom\x86\novacomd.exe O23 - Service: OpenSSH Server (OpenSSHd) - Unknown owner - C:\Program Files\OpenSSH\bin\cygrunsrv.exe O23 - Service: SpoonProxy (spserv) - Pi-Soft Consulting, LLC - C:\Program Files\SpoonProxy\spserv.exe -- End of file - 6569 bytes