How can I remove the malware "rkg.exe", "vpp.exe", etc (MBR root virus?) (zlob trojan?) from my XP-SP3 computer and router?
I am running Windows XP, SP3 (and IE8) with all updates current, through a 2wire Gateway router. I use Avast free anti-virus, Avast v 6.0.1.1367 updated to definitions v 120104-1.
SYMPTOMS:
After clicking a link on a wiki.com article about functions, several (fake) security warning windows popped up similar to Windows Defender warnings. BUT, Avast anti-virus will not run, executable programs will not run, cmd.exe window will not start, etc. IE8 reroutes all internet requests to malware sites, which will continue downloading malware unless I stop. The USB port is blocked by the virus (even with the rkg.exe process ended), so I cannot find it using explorer, load programs on it, or run programs from it. In Task Manager, a file unknown to me was running: "rkg.exe", which I killed, this closed the fake security windows.
PRELIMINARY INVESTIGATIONS:
The file C:\Documents and Settings\Owner\Local Settings\Application Data\rkg.exe is malware. In that directory, I also found vpp.exe, and 4 other strange executable files. The cmd prompt works only in safe mode, so I renamed them xxx-rkg.exe, etc.
Later I also found C:\Documents and Settings\Owner\My Documents\T5B7d14N.exe, and other randomly named files in that directory: 75724.exe, 53037Ro.exe, 11RP81TV.exe, T1TqAmgb.exe.
The file C:\Documents and Settings\Owner\My Documents\3CANh.exe is also suspicious.
Rebooting, F8 to "last known good configuration" will not work.
I was able to reboot in safe mode and run DDS.exe, the files are included. DDS.exe was already present on my computer, but would not run in normal mode.
The dds.txt ==File Associations== section shows the problem with executable files, .exe=Uiq, not the normal exefile. To obtain the dds.txt and attach.txt files, I had to remove the hard drive and connect it to a working computer via Kingwin's "EZ-CONNECT".
I cannot download MBAM or GMER. If I downloaded MBAM-setup.exe to a working computer, could I "install" it on the infected disk, then transfer the disk back to the infected computer and run it? GMER, I believe, can be done this way, but can MBAM?
I also already had OTL and autorunsc.exe loaded on my computer, and was able to run them in safe mode. The OTL and autorunsc output is available, and I found them useful. I can either paste or attach them if desired.
Per website instructions, I have not attempted any registry edits or used any registry repair programs, even though I am comfortable with regedit.exe. I have included attach.txt.
When I get the computer cleaned up, how do I clean up the 2wire 2701HB-G router?
Is powering it down and restarting sufficient?
DDS.TXT **********************************************************************
DDS.TXT **********************************************************************
.
DDS (Ver_2011-08-26.01) - FAT32x86 MINIMAL
Internet Explorer: 8.0.6001.18702
Run by Owner at 17:35:03 on 2012-01-06
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.250 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
C:\Program Files\IrfanView\i_view32.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [PPWebCap] c:\progra~1\scansoft\paperp~1\PPWebCap.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{9617A521-4884-4BC2-A15B-D7692C593190} : DhcpNameServer = 192.168.1.254
Notify: ComPlusSetup - c:\windows\system32\catsrvut.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nlem32nt;NLEM32NT;c:\windows\system32\drivers\nlem32nt.sys [2009-10-16 69656]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-12 435032]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-15 314456]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-15 20568]
S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-15 44768]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-2-24 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-2-24 8456]
.
=============== File Associations ===============
.
.exe=Uiq
.
=============== Created Last 30 ================
.
2016-02-24 20:28:50 -------- d-----w- c:\program files\InCtrl5
2016-02-24 15:15:27 -------- d-----w- c:\documents and settings\owner\local settings\application data\Help
2016-02-22 19:40:27 -------- d-----w- c:\windows\system32\wbem\AutoRecover
2016-02-22 19:40:20 -------- d-s---w- c:\windows\system32\Microsoft
2016-02-22 19:32:50 -------- d-----w- c:\windows\ServicePackFiles
2016-02-22 19:31:28 2897920 ------w- c:\windows\system32\xpsp2res.dll
2016-02-22 19:30:30 -------- d-----w- c:\windows\system32\ReinstallBackups
2016-02-22 19:30:11 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2016-02-22 19:28:18 -------- d-----w- c:\windows\EHome
2016-02-17 19:26:11 -------- d-sh--w- c:\documents and settings\owner\UserData
2016-02-17 01:27:20 -------- d-sh--w- C:\Recycled
2016-02-17 01:18:59 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2016-02-17 01:16:43 40960 ----a-w- c:\windows\system32\dllcache\trialoc.dll
2016-02-17 01:16:43 40960 ----a-w- c:\program files\internet explorer\connection wizard\trialoc.dll
2016-02-17 01:16:42 73728 ----a-w- c:\windows\system32\dllcache\icwtutor.exe
2016-02-17 01:16:42 73728 ----a-w- c:\program files\internet explorer\connection wizard\icwtutor.exe
2016-02-17 01:16:42 61440 ----a-w- c:\windows\system32\dllcache\icwres.dll
2016-02-17 01:16:42 61440 ----a-w- c:\program files\internet explorer\connection wizard\icwres.dll
2016-02-17 01:16:42 61440 ----a-w- c:\program files\internet explorer\connection wizard\icwconn.dll
2016-02-17 01:16:42 49152 ----a-w- c:\program files\internet explorer\connection wizard\icwutil.dll
2016-02-17 01:16:42 24576 ----a-w- c:\program files\internet explorer\connection wizard\icwrmind.exe
2016-02-17 01:16:42 172032 ----a-w- c:\program files\internet explorer\connection wizard\icwhelp.dll
2016-02-17 01:01:17 24661 ----a-w- c:\windows\system32\spxcoins.dll
2016-02-17 01:01:17 24661 ----a-w- c:\windows\system32\dllcache\spxcoins.dll
2016-02-17 01:01:17 13312 ----a-w- c:\windows\system32\irclass.dll
2016-02-17 01:01:17 13312 ----a-w- c:\windows\system32\dllcache\irclass.dll
2016-02-17 00:50:29 -------- d-----w- c:\windows\system32\xircom
2016-02-17 00:50:29 -------- d-----w- c:\windows\system32\wbem\snmp
2016-02-17 00:50:03 100864 ----a-w- c:\windows\system32\migicons.exe
2016-02-17 00:47:51 45568 ----a-w- c:\windows\system32\safrslv.dll
2016-02-17 00:46:56 -------- d-----w- c:\windows\Registration
2016-02-17 00:45:59 73216 ----a-w- c:\windows\system32\dllcache\avwav.dll
2016-02-17 00:44:35 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2016-02-17 00:44:29 52864 ----a-w- c:\windows\system32\drivers\DMusic.sys
2016-02-17 00:44:23 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2016-02-17 00:44:08 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2016-02-17 00:43:56 907456 ----a-w- c:\windows\system32\drivers\HCF_MSFT.sys
2016-02-17 00:43:52 731648 ----a-w- c:\windows\system32\drivers\nv4.sys
2016-02-17 00:43:52 1738496 ----a-w- c:\windows\system32\nv4.dll
2016-02-17 00:43:49 117760 ----a-w- c:\windows\system32\drivers\e100b325.sys
2016-02-17 00:43:37 96256 ----a-w- c:\windows\system32\drivers\ac97intc.sys
2016-02-17 00:43:37 4096 ----a-w- c:\windows\system32\ksuser.dll
2016-02-17 00:43:37 129536 ----a-w- c:\windows\system32\ksproxy.ax
2016-02-17 00:41:45 -------- d-----w- C:\Documents and Settings
2016-02-17 00:36:29 -------- d-----w- c:\windows\MDMUPGLG
2016-02-17 00:25:36 -------- d-s---w- c:\windows\Downloaded Program Files
2016-02-17 00:25:00 -------- d--h--w- c:\windows\PIF
2016-02-17 00:24:56 -------- d-----w- c:\windows\All Users
2012-01-06 18:59:04 -------- d-sh--w- C:\FOUND.000
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-vpp.exe
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-pxh.exe
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-akh.exe
2012-01-04 18:52:59 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-rkg.exe
2012-01-04 18:52:59 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-geh.exe
2012-01-04 17:48:10 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-gfd.exe
.
==================== Find3M ====================
.
2011-11-28 18:01:26 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 17:53:54 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20:52 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:52 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:24:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33:08 2192768 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:04 2069376 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 ------w- c:\windows\system32\encdec.dll
2011-10-10 14:22:42 692736 ----a-w- c:\windows\system32\inetcomm.dll
.
============= FINISH: 17:35:42.15 ===============
end DDS.TXT **********************************************************************
ATTACH.TXT $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
ATTACH.TXT $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
.
DDS (Ver_2011-08-26.01) - FAT32x86 MINIMAL
Internet Explorer: 8.0.6001.18702
Run by Owner at 17:35:03 on 2012-01-06
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.250 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
C:\Program Files\IrfanView\i_view32.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [PPWebCap] c:\progra~1\scansoft\paperp~1\PPWebCap.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{9617A521-4884-4BC2-A15B-D7692C593190} : DhcpNameServer = 192.168.1.254
Notify: ComPlusSetup - c:\windows\system32\catsrvut.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nlem32nt;NLEM32NT;c:\windows\system32\drivers\nlem32nt.sys [2009-10-16 69656]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-12 435032]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-15 314456]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-15 20568]
S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-15 44768]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-2-24 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-2-24 8456]
.
=============== File Associations ===============
.
.exe=Uiq
.
=============== Created Last 30 ================
.
2016-02-24 20:28:50 -------- d-----w- c:\program files\InCtrl5
2016-02-24 15:15:27 -------- d-----w- c:\documents and settings\owner\local settings\application data\Help
2016-02-22 19:40:27 -------- d-----w- c:\windows\system32\wbem\AutoRecover
2016-02-22 19:40:20 -------- d-s---w- c:\windows\system32\Microsoft
2016-02-22 19:32:50 -------- d-----w- c:\windows\ServicePackFiles
2016-02-22 19:31:28 2897920 ------w- c:\windows\system32\xpsp2res.dll
2016-02-22 19:30:30 -------- d-----w- c:\windows\system32\ReinstallBackups
2016-02-22 19:30:11 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2016-02-22 19:28:18 -------- d-----w- c:\windows\EHome
2016-02-17 19:26:11 -------- d-sh--w- c:\documents and settings\owner\UserData
2016-02-17 01:27:20 -------- d-sh--w- C:\Recycled
2016-02-17 01:18:59 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2016-02-17 01:16:43 40960 ----a-w- c:\windows\system32\dllcache\trialoc.dll
2016-02-17 01:16:43 40960 ----a-w- c:\program files\internet explorer\connection wizard\trialoc.dll
2016-02-17 01:16:42 73728 ----a-w- c:\windows\system32\dllcache\icwtutor.exe
2016-02-17 01:16:42 73728 ----a-w- c:\program files\internet explorer\connection wizard\icwtutor.exe
2016-02-17 01:16:42 61440 ----a-w- c:\windows\system32\dllcache\icwres.dll
2016-02-17 01:16:42 61440 ----a-w- c:\program files\internet explorer\connection wizard\icwres.dll
2016-02-17 01:16:42 61440 ----a-w- c:\program files\internet explorer\connection wizard\icwconn.dll
2016-02-17 01:16:42 49152 ----a-w- c:\program files\internet explorer\connection wizard\icwutil.dll
2016-02-17 01:16:42 24576 ----a-w- c:\program files\internet explorer\connection wizard\icwrmind.exe
2016-02-17 01:16:42 172032 ----a-w- c:\program files\internet explorer\connection wizard\icwhelp.dll
2016-02-17 01:01:17 24661 ----a-w- c:\windows\system32\spxcoins.dll
2016-02-17 01:01:17 24661 ----a-w- c:\windows\system32\dllcache\spxcoins.dll
2016-02-17 01:01:17 13312 ----a-w- c:\windows\system32\irclass.dll
2016-02-17 01:01:17 13312 ----a-w- c:\windows\system32\dllcache\irclass.dll
2016-02-17 00:50:29 -------- d-----w- c:\windows\system32\xircom
2016-02-17 00:50:29 -------- d-----w- c:\windows\system32\wbem\snmp
2016-02-17 00:50:03 100864 ----a-w- c:\windows\system32\migicons.exe
2016-02-17 00:47:51 45568 ----a-w- c:\windows\system32\safrslv.dll
2016-02-17 00:46:56 -------- d-----w- c:\windows\Registration
2016-02-17 00:45:59 73216 ----a-w- c:\windows\system32\dllcache\avwav.dll
2016-02-17 00:44:35 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2016-02-17 00:44:29 52864 ----a-w- c:\windows\system32\drivers\DMusic.sys
2016-02-17 00:44:23 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2016-02-17 00:44:08 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2016-02-17 00:43:56 907456 ----a-w- c:\windows\system32\drivers\HCF_MSFT.sys
2016-02-17 00:43:52 731648 ----a-w- c:\windows\system32\drivers\nv4.sys
2016-02-17 00:43:52 1738496 ----a-w- c:\windows\system32\nv4.dll
2016-02-17 00:43:49 117760 ----a-w- c:\windows\system32\drivers\e100b325.sys
2016-02-17 00:43:37 96256 ----a-w- c:\windows\system32\drivers\ac97intc.sys
2016-02-17 00:43:37 4096 ----a-w- c:\windows\system32\ksuser.dll
2016-02-17 00:43:37 129536 ----a-w- c:\windows\system32\ksproxy.ax
2016-02-17 00:41:45 -------- d-----w- C:\Documents and Settings
2016-02-17 00:36:29 -------- d-----w- c:\windows\MDMUPGLG
2016-02-17 00:25:36 -------- d-s---w- c:\windows\Downloaded Program Files
2016-02-17 00:25:00 -------- d--h--w- c:\windows\PIF
2016-02-17 00:24:56 -------- d-----w- c:\windows\All Users
2012-01-06 18:59:04 -------- d-sh--w- C:\FOUND.000
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-vpp.exe
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-pxh.exe
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-akh.exe
2012-01-04 18:52:59 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-rkg.exe
2012-01-04 18:52:59 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-geh.exe
2012-01-04 17:48:10 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-gfd.exe
.
==================== Find3M ====================
.
2011-11-28 18:01:26 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 17:53:54 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20:52 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:52 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:24:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33:08 2192768 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:04 2069376 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 ------w- c:\windows\system32\encdec.dll
2011-10-10 14:22:42 692736 ----a-w- c:\windows\system32\inetcomm.dll
.
============= FINISH: 17:35:42.15 ===============
end ATTACH.TXT $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
zlob-virus-summary-120106.txt
I am running Windows XP, SP3 (and IE8) with all updates current, through a 2wire Gateway router. I use Avast free anti-virus, Avast v 6.0.1.1367 updated to definitions v 120104-1.
SYMPTOMS:
After clicking a link on a wiki.com article about functions, several (fake) security warning windows popped up similar to Windows Defender warnings. BUT, Avast anti-virus will not run, executable programs will not run, cmd.exe window will not start, etc. IE8 reroutes all internet requests to malware sites, which will continue downloading malware unless I stop. The USB port is blocked by the virus (even with the rkg.exe process ended), so I cannot find it using explorer, load programs on it, or run programs from it. In Task Manager, a file unknown to me was running: "rkg.exe", which I killed, this closed the fake security windows.
PRELIMINARY INVESTIGATIONS:
The file C:\Documents and Settings\Owner\Local Settings\Application Data\rkg.exe is malware. In that directory, I also found vpp.exe, and 4 other strange executable files. The cmd prompt works only in safe mode, so I renamed them xxx-rkg.exe, etc.
Later I also found C:\Documents and Settings\Owner\My Documents\T5B7d14N.exe, and other randomly named files in that directory: 75724.exe, 53037Ro.exe, 11RP81TV.exe, T1TqAmgb.exe.
The file C:\Documents and Settings\Owner\My Documents\3CANh.exe is also suspicious.
Rebooting, F8 to "last known good configuration" will not work.
I was able to reboot in safe mode and run DDS.exe, the files are included. DDS.exe was already present on my computer, but would not run in normal mode.
The dds.txt ==File Associations== section shows the problem with executable files, .exe=Uiq, not the normal exefile. To obtain the dds.txt and attach.txt files, I had to remove the hard drive and connect it to a working computer via Kingwin's "EZ-CONNECT".
I cannot download MBAM or GMER. If I downloaded MBAM-setup.exe to a working computer, could I "install" it on the infected disk, then transfer the disk back to the infected computer and run it? GMER, I believe, can be done this way, but can MBAM?
I also already had OTL and autorunsc.exe loaded on my computer, and was able to run them in safe mode. The OTL and autorunsc output is available, and I found them useful. I can either paste or attach them if desired.
Per website instructions, I have not attempted any registry edits or used any registry repair programs, even though I am comfortable with regedit.exe. I have included attach.txt.
When I get the computer cleaned up, how do I clean up the 2wire 2701HB-G router?
Is powering it down and restarting sufficient?
DDS.TXT **********************************************************************
DDS.TXT **********************************************************************
.
DDS (Ver_2011-08-26.01) - FAT32x86 MINIMAL
Internet Explorer: 8.0.6001.18702
Run by Owner at 17:35:03 on 2012-01-06
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.250 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
C:\Program Files\IrfanView\i_view32.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [PPWebCap] c:\progra~1\scansoft\paperp~1\PPWebCap.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{9617A521-4884-4BC2-A15B-D7692C593190} : DhcpNameServer = 192.168.1.254
Notify: ComPlusSetup - c:\windows\system32\catsrvut.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nlem32nt;NLEM32NT;c:\windows\system32\drivers\nlem32nt.sys [2009-10-16 69656]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-12 435032]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-15 314456]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-15 20568]
S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-15 44768]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-2-24 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-2-24 8456]
.
=============== File Associations ===============
.
.exe=Uiq
.
=============== Created Last 30 ================
.
2016-02-24 20:28:50 -------- d-----w- c:\program files\InCtrl5
2016-02-24 15:15:27 -------- d-----w- c:\documents and settings\owner\local settings\application data\Help
2016-02-22 19:40:27 -------- d-----w- c:\windows\system32\wbem\AutoRecover
2016-02-22 19:40:20 -------- d-s---w- c:\windows\system32\Microsoft
2016-02-22 19:32:50 -------- d-----w- c:\windows\ServicePackFiles
2016-02-22 19:31:28 2897920 ------w- c:\windows\system32\xpsp2res.dll
2016-02-22 19:30:30 -------- d-----w- c:\windows\system32\ReinstallBackups
2016-02-22 19:30:11 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2016-02-22 19:28:18 -------- d-----w- c:\windows\EHome
2016-02-17 19:26:11 -------- d-sh--w- c:\documents and settings\owner\UserData
2016-02-17 01:27:20 -------- d-sh--w- C:\Recycled
2016-02-17 01:18:59 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2016-02-17 01:16:43 40960 ----a-w- c:\windows\system32\dllcache\trialoc.dll
2016-02-17 01:16:43 40960 ----a-w- c:\program files\internet explorer\connection wizard\trialoc.dll
2016-02-17 01:16:42 73728 ----a-w- c:\windows\system32\dllcache\icwtutor.exe
2016-02-17 01:16:42 73728 ----a-w- c:\program files\internet explorer\connection wizard\icwtutor.exe
2016-02-17 01:16:42 61440 ----a-w- c:\windows\system32\dllcache\icwres.dll
2016-02-17 01:16:42 61440 ----a-w- c:\program files\internet explorer\connection wizard\icwres.dll
2016-02-17 01:16:42 61440 ----a-w- c:\program files\internet explorer\connection wizard\icwconn.dll
2016-02-17 01:16:42 49152 ----a-w- c:\program files\internet explorer\connection wizard\icwutil.dll
2016-02-17 01:16:42 24576 ----a-w- c:\program files\internet explorer\connection wizard\icwrmind.exe
2016-02-17 01:16:42 172032 ----a-w- c:\program files\internet explorer\connection wizard\icwhelp.dll
2016-02-17 01:01:17 24661 ----a-w- c:\windows\system32\spxcoins.dll
2016-02-17 01:01:17 24661 ----a-w- c:\windows\system32\dllcache\spxcoins.dll
2016-02-17 01:01:17 13312 ----a-w- c:\windows\system32\irclass.dll
2016-02-17 01:01:17 13312 ----a-w- c:\windows\system32\dllcache\irclass.dll
2016-02-17 00:50:29 -------- d-----w- c:\windows\system32\xircom
2016-02-17 00:50:29 -------- d-----w- c:\windows\system32\wbem\snmp
2016-02-17 00:50:03 100864 ----a-w- c:\windows\system32\migicons.exe
2016-02-17 00:47:51 45568 ----a-w- c:\windows\system32\safrslv.dll
2016-02-17 00:46:56 -------- d-----w- c:\windows\Registration
2016-02-17 00:45:59 73216 ----a-w- c:\windows\system32\dllcache\avwav.dll
2016-02-17 00:44:35 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2016-02-17 00:44:29 52864 ----a-w- c:\windows\system32\drivers\DMusic.sys
2016-02-17 00:44:23 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2016-02-17 00:44:08 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2016-02-17 00:43:56 907456 ----a-w- c:\windows\system32\drivers\HCF_MSFT.sys
2016-02-17 00:43:52 731648 ----a-w- c:\windows\system32\drivers\nv4.sys
2016-02-17 00:43:52 1738496 ----a-w- c:\windows\system32\nv4.dll
2016-02-17 00:43:49 117760 ----a-w- c:\windows\system32\drivers\e100b325.sys
2016-02-17 00:43:37 96256 ----a-w- c:\windows\system32\drivers\ac97intc.sys
2016-02-17 00:43:37 4096 ----a-w- c:\windows\system32\ksuser.dll
2016-02-17 00:43:37 129536 ----a-w- c:\windows\system32\ksproxy.ax
2016-02-17 00:41:45 -------- d-----w- C:\Documents and Settings
2016-02-17 00:36:29 -------- d-----w- c:\windows\MDMUPGLG
2016-02-17 00:25:36 -------- d-s---w- c:\windows\Downloaded Program Files
2016-02-17 00:25:00 -------- d--h--w- c:\windows\PIF
2016-02-17 00:24:56 -------- d-----w- c:\windows\All Users
2012-01-06 18:59:04 -------- d-sh--w- C:\FOUND.000
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-vpp.exe
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-pxh.exe
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-akh.exe
2012-01-04 18:52:59 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-rkg.exe
2012-01-04 18:52:59 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-geh.exe
2012-01-04 17:48:10 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-gfd.exe
.
==================== Find3M ====================
.
2011-11-28 18:01:26 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 17:53:54 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20:52 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:52 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:24:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33:08 2192768 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:04 2069376 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 ------w- c:\windows\system32\encdec.dll
2011-10-10 14:22:42 692736 ----a-w- c:\windows\system32\inetcomm.dll
.
============= FINISH: 17:35:42.15 ===============
end DDS.TXT **********************************************************************
ATTACH.TXT $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
ATTACH.TXT $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
.
DDS (Ver_2011-08-26.01) - FAT32x86 MINIMAL
Internet Explorer: 8.0.6001.18702
Run by Owner at 17:35:03 on 2012-01-06
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.250 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
C:\Program Files\IrfanView\i_view32.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [PPWebCap] c:\progra~1\scansoft\paperp~1\PPWebCap.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{9617A521-4884-4BC2-A15B-D7692C593190} : DhcpNameServer = 192.168.1.254
Notify: ComPlusSetup - c:\windows\system32\catsrvut.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nlem32nt;NLEM32NT;c:\windows\system32\drivers\nlem32nt.sys [2009-10-16 69656]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-12 435032]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-15 314456]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-15 20568]
S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-15 44768]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-2-24 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-2-24 8456]
.
=============== File Associations ===============
.
.exe=Uiq
.
=============== Created Last 30 ================
.
2016-02-24 20:28:50 -------- d-----w- c:\program files\InCtrl5
2016-02-24 15:15:27 -------- d-----w- c:\documents and settings\owner\local settings\application data\Help
2016-02-22 19:40:27 -------- d-----w- c:\windows\system32\wbem\AutoRecover
2016-02-22 19:40:20 -------- d-s---w- c:\windows\system32\Microsoft
2016-02-22 19:32:50 -------- d-----w- c:\windows\ServicePackFiles
2016-02-22 19:31:28 2897920 ------w- c:\windows\system32\xpsp2res.dll
2016-02-22 19:30:30 -------- d-----w- c:\windows\system32\ReinstallBackups
2016-02-22 19:30:11 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2016-02-22 19:28:18 -------- d-----w- c:\windows\EHome
2016-02-17 19:26:11 -------- d-sh--w- c:\documents and settings\owner\UserData
2016-02-17 01:27:20 -------- d-sh--w- C:\Recycled
2016-02-17 01:18:59 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2016-02-17 01:16:43 40960 ----a-w- c:\windows\system32\dllcache\trialoc.dll
2016-02-17 01:16:43 40960 ----a-w- c:\program files\internet explorer\connection wizard\trialoc.dll
2016-02-17 01:16:42 73728 ----a-w- c:\windows\system32\dllcache\icwtutor.exe
2016-02-17 01:16:42 73728 ----a-w- c:\program files\internet explorer\connection wizard\icwtutor.exe
2016-02-17 01:16:42 61440 ----a-w- c:\windows\system32\dllcache\icwres.dll
2016-02-17 01:16:42 61440 ----a-w- c:\program files\internet explorer\connection wizard\icwres.dll
2016-02-17 01:16:42 61440 ----a-w- c:\program files\internet explorer\connection wizard\icwconn.dll
2016-02-17 01:16:42 49152 ----a-w- c:\program files\internet explorer\connection wizard\icwutil.dll
2016-02-17 01:16:42 24576 ----a-w- c:\program files\internet explorer\connection wizard\icwrmind.exe
2016-02-17 01:16:42 172032 ----a-w- c:\program files\internet explorer\connection wizard\icwhelp.dll
2016-02-17 01:01:17 24661 ----a-w- c:\windows\system32\spxcoins.dll
2016-02-17 01:01:17 24661 ----a-w- c:\windows\system32\dllcache\spxcoins.dll
2016-02-17 01:01:17 13312 ----a-w- c:\windows\system32\irclass.dll
2016-02-17 01:01:17 13312 ----a-w- c:\windows\system32\dllcache\irclass.dll
2016-02-17 00:50:29 -------- d-----w- c:\windows\system32\xircom
2016-02-17 00:50:29 -------- d-----w- c:\windows\system32\wbem\snmp
2016-02-17 00:50:03 100864 ----a-w- c:\windows\system32\migicons.exe
2016-02-17 00:47:51 45568 ----a-w- c:\windows\system32\safrslv.dll
2016-02-17 00:46:56 -------- d-----w- c:\windows\Registration
2016-02-17 00:45:59 73216 ----a-w- c:\windows\system32\dllcache\avwav.dll
2016-02-17 00:44:35 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2016-02-17 00:44:29 52864 ----a-w- c:\windows\system32\drivers\DMusic.sys
2016-02-17 00:44:23 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2016-02-17 00:44:08 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2016-02-17 00:43:56 907456 ----a-w- c:\windows\system32\drivers\HCF_MSFT.sys
2016-02-17 00:43:52 731648 ----a-w- c:\windows\system32\drivers\nv4.sys
2016-02-17 00:43:52 1738496 ----a-w- c:\windows\system32\nv4.dll
2016-02-17 00:43:49 117760 ----a-w- c:\windows\system32\drivers\e100b325.sys
2016-02-17 00:43:37 96256 ----a-w- c:\windows\system32\drivers\ac97intc.sys
2016-02-17 00:43:37 4096 ----a-w- c:\windows\system32\ksuser.dll
2016-02-17 00:43:37 129536 ----a-w- c:\windows\system32\ksproxy.ax
2016-02-17 00:41:45 -------- d-----w- C:\Documents and Settings
2016-02-17 00:36:29 -------- d-----w- c:\windows\MDMUPGLG
2016-02-17 00:25:36 -------- d-s---w- c:\windows\Downloaded Program Files
2016-02-17 00:25:00 -------- d--h--w- c:\windows\PIF
2016-02-17 00:24:56 -------- d-----w- c:\windows\All Users
2012-01-06 18:59:04 -------- d-sh--w- C:\FOUND.000
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-vpp.exe
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-pxh.exe
2012-01-04 18:53:00 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-akh.exe
2012-01-04 18:52:59 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-rkg.exe
2012-01-04 18:52:59 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-geh.exe
2012-01-04 17:48:10 275456 ----a-w- c:\documents and settings\owner\local settings\application data\xxx-gfd.exe
.
==================== Find3M ====================
.
2011-11-28 18:01:26 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 17:53:54 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20:52 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:52 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:24:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33:08 2192768 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:04 2069376 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 ------w- c:\windows\system32\encdec.dll
2011-10-10 14:22:42 692736 ----a-w- c:\windows\system32\inetcomm.dll
.
============= FINISH: 17:35:42.15 ===============
end ATTACH.TXT $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
zlob-virus-summary-120106.txt