Status
Not open for further replies.

Shikhar

Journeyman
Hi I have a IntelP4 2.4 Ghz 845chipset ASROCK Motherboard. Win xp pro and win 2000. 1GB + 256 MB DDR RAM. 160 GB + 20 GB HDDs. I have Win 2000 on C:\ and Win XP on G:\

Whenever I am surfing net (using Win XP) I have Zonealarm antivirus popping up and saying C:\Microsoft.pif is Quarantined (claiming it to be Trojan-Downloader.Win32.Agent.qpv) and another file named rm[1].exe in G:\Document and settings\Shikhar\Local Settings\Temporary Internet files\rm[1].exe is quarantined. This happens many times. Even after deleting the 2 files again it appears.

Searched for rm[1].exe in Registry but there is nothing in it.

All this started ever since I was looking for review of Harry Potter and the order of Phoenix game. I googled and got the review on pc.gamezone.com That is when this problem started.

Please help. Thanks in advance.
 

blueshift

Wise Old Crow
Check your startup entries and also in Registry.
It might be possible that there is still some file(undetected) somewhere that is called up everytime you boot.
Check Userinit and Shell entries in Registry.

Post your HijackThis log too.
 
OP
S

Shikhar

Journeyman
Posting the HijackThis log file

Logfile of HijackThis v1.99.1
Scan saved at 12:37:42 PM, on 6/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
G:\WINDOWS\system32\ZoneLabs\vsmon.exe
G:\WINDOWS\system32\spoolsv.exe
G:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
G:\Program Files\iolo\System Mechanic Professional 6\IoloSGCtrl.exe
G:\WINDOWS\system32\nvsvc32.exe
G:\WINDOWS\system32\slserv.exe
G:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
G:\Program Files\Nero\Nero 7\InCD\InCD.exe
G:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
G:\Program Files\HP\hpcoretech\hpcmpmgr.exe
G:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
G:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
G:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
G:\WINDOWS\system32\wuauclt.exe
G:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Sify Broadband\BBClient.exe
C:\Program Files\Sify Broadband\BBImpSec.exe
G:\Program Files\HijackThis\HijackThis.exe
G:\WINDOWS\system32\svchost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = *www.hotmail.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = *www.sify.com/?userid=3189&check=c6a1c5f5ddd4f559
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - g:\program files\google\googletoolbar1.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - g:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "G:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [InCD] G:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] G:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "G:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "G:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] G:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [SifyBB] C:\Program Files\Sify Broadband\BBImpSec.exe
O4 - HKCU\..\Run: [msnmsgr] "G:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{93046A72-7C38-41E4-911A-B9353B52EDB3}: NameServer = 202.144.115.4,202.144.66.6
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - G:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - G:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - G:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Capture Device Service - InterVideo Inc. - G:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - G:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - G:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - G:\Program Files\iolo\System Mechanic Professional 6\IoloSGCtrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - G:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - G:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - G:\WINDOWS\system32\ZoneLabs\vsmon.exe



Thanks in advance.
 
Status
Not open for further replies.
Top Bottom