Well first off my computer is acting a little buggy which is unusual. I made sure that my antivirus software was up to date and ran a Virus and Spyware Scan to find nothing (utilities I'm using on my computer). Went online to BitDefender's website and did an online virus-scan their to reveal a virus that my antivirus program did not pick up (imagine that). The virus's name is tvgyiy.exe - Backdoor.Rbot.XJH. Which I've searched and searched I can't find anything on it. I have tried to locate the virus myself by doing a search with the Windows search engine and whatever I do it won't find this particular file. Then I did a search in the system32 directory where this virus resides I still can't find it there. I enabled show hidden folders or files and turned on file extensions with no once again. I ran silent runners and posting my log here for hopefully somebody can help me out.
--------------------------
----------
----------
----------
----------
----------
----------
----------
------
"Silent Runners.vbs", revision 52,
http://www.silentrunners.org/Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
--------------------------
-------
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run\ {++}
"ctfmon.exe" = "C:\WINDOWS\system32\ctfmo
n.exe" [MS]
"Yahoo! Pager" = ""C:\PROGRA~1\Yahoo!\MESSE
N~1\YAHOOM
~1.EXE" -quiet" ["Yahoo! Inc."]
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run\ {++}
"BitDefender Antiphishing Helper" = ""C:\Program Files\BitDefender\BitDefen
der 2008\IEShow.exe"" ["BitDefender"]
"BDAgent" = ""C:\Program Files\BitDefender\BitDefen
der 2008\bdagent.exe"" ["BitDefender S.R.L."]
"ISUSScheduler" = ""C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe" -start" ["InstallShield Software Corporation"]
"ISUSPM Startup" = "c:\PROGRA~1\COMMON~1\INST
AL~1\UPDAT
E~1\isuspm
.exe -startup" ["InstallShield Software Corporation"]
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Explorer\
Browser Helper Objects\
{02478D38-C3F9-4efb-9B51-7
695ECA0567
0}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = "&Yahoo! Toolbar Helper"
\InProcServer32\(Default) = "C:\PROGRA~1\Yahoo!\Compan
ion\Instal
ls\cpn\yt.
dll" ["Yahoo! Inc."]
{5BAB4B5B-68BC-4B02-94D6-2
FC0DE4A789
7}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = "Yahoo! IE Services Button"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Common\yiesrv
c.dll" ["Yahoo! Inc."]
{761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = "SSVHelper Class"
\InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll" ["Sun Microsystems, Inc."]
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-
00a0c9068f
f3}" = "Display Panning CPL Extension"
-> {HKLM...CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-
00AA0030EB
C8}" = "HyperTerminal Icon Ext"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\system32\htico
ns.dll" ["Hilgraeve, Inc."]
"{B41DB860-8EE4-11D2-9906-
E49FADC173
CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{280CFDE1-1354-4431-92F3-
03073BA593
FB}" = "TotalConverter Context Menu Shell Extension"
-> {HKLM...CLSID} = "TotalConverter Context Menu Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\TotalAudioConverter\
axTotalCon
verter.dll
" [empty string]
"{e57ce731-33e8-4c51-8354-
bb4de9d215
d1}" = "Universal Plug and Play Devices"
-> {HKLM...CLSID} = "Universal Plug and Play Devices"
\InProcServer32\(Default) = "C:\WINDOWS\system32\upnpu
i.dll" [MS]
"{00020D75-0000-0000-C000-
0000000000
46}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {HKLM...CLSID} = "Microsoft Office Outlook"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFI
CE11\MLSHE
XT.DLL" [MS]
"{0006F045-0000-0000-C000-
0000000000
46}" = "Microsoft Office Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Outlook File Icon Extension"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFI
CE11\OLKFS
TUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-
0050048385
97}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
" [MS]
"{993BE281-6695-4BA5-8A2A-
7AACBFAAB6
9E}" = "Microsoft Office Metadata Handler"
-> {HKLM...CLSID} = "Microsoft Office Metadata Handler"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICR
OS~1\OFFIC
E12\msoshe
xt.dll" [MS]
"{C41662BB-1FA0-4CE0-8DC5-
9B7F8279FF
97}" = "Microsoft Office Thumbnail Handler"
-> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICR
OS~1\OFFIC
E12\msoshe
xt.dll" [MS]
"{5464D816-CF16-4784-B9F3-
75C0DB52B4
99}" = "Yahoo! Mail"
-> {HKLM...CLSID} = "Yahoo! Mail Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Common\YMMAPI
.dll" ["Yahoo! Inc."]
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\ShellServ
iceObjectD
elayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-
94D524869D
B5}"
-> {HKLM...CLSID} = "WPDShServiceObj Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\WPDSh
ServiceObj
.dll" [MS]
HKLM\Software\Microsoft\Wi
ndows NT\CurrentVersion\Winlogon
\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
HKLM\Software\Classes\PROT
OCOLS\Filt
er\
<<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-
00B0D022E9
45}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.D
LL" [MS]
HKLM\Software\Classes\*\sh
ellex\Cont
extMenuHan
dlers\
MagicISO\(Default) = "{DB85C504-C730-49DD-BEC1-
7B39C6103B
7A}"
-> {HKLM...CLSID} = "MShellExtMenu Class"
\InProcServer32\(Default) = "C:\Program Files\MagicISO\misosh.dll"
["MagicISO, Inc."]
TotalConverter\(Default) = "{280CFDE1-1354-4431-92F3-
03073BA593
FB}"
-> {HKLM...CLSID} = "TotalConverter Context Menu Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\TotalAudioConverter\
axTotalCon
verter.dll
" [empty string]
WinExpert\(Default) = "{19741013-C829-11D1-8233-
0020AF3E97
A9}"
-> {HKLM...CLSID} = "Context Menu Shell Extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32\conte
xt.dll" ["SuperLogix"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-
E49FADC173
CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
Yahoo! Mail\(Default) = "{5464D816-CF16-4784-B9F3-
75C0DB52B4
99}"
-> {HKLM...CLSID} = "Yahoo! Mail Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Common\YMMAPI
.dll" ["Yahoo! Inc."]
HKLM\Software\Classes\Dire
ctory\shel
lex\Contex
tMenuHandl
ers\
MagicISO\(Default) = "{DB85C504-C730-49DD-BEC1-
7B39C6103B
7A}"
-> {HKLM...CLSID} = "MShellExtMenu Class"
\InProcServer32\(Default) = "C:\Program Files\MagicISO\misosh.dll"
["MagicISO, Inc."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-
E49FADC173
CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
HKLM\Software\Classes\Fold
er\shellex
\ContextMe
nuHandlers
\
MagicISO\(Default) = "{DB85C504-C730-49DD-BEC1-
7B39C6103B
7A}"
-> {HKLM...CLSID} = "MShellExtMenu Class"
\InProcServer32\(Default) = "C:\Program Files\MagicISO\misosh.dll"
["MagicISO, Inc."]
WinExpert\(Default) = "{19741013-C829-11D1-8233-
0020AF3E97
A9}"
-> {HKLM...CLSID} = "Context Menu Shell Extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32\conte
xt.dll" ["SuperLogix"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-
E49FADC173
CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
Group Policies {GPedit.msc branch and setting}:
--------------------------
----------
----------
-
Note: detected settings may not have any effect.
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Policies\
Explorer\
"ClearRecentDocsOnExit" = (REG_DWORD) hex:0x00000001
{unrecognized setting}
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Policies\
System\
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}
Active Desktop and Wallpaper:
--------------------------
---
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Explorer\
ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\In
ternet Explorer\Desktop\General\
"Wallpaper" = "%APPDATA%\Microsoft\Inter
net Explorer\Internet Explorer Wallpaper.bmp"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\David\Application
Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp"
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\system32\ss3df
o.scr" [MS]
Startup items in "David" & "All Users" startup folders:
--------------------------
----------
----------
---------
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Wireless Connection Manager" -> shortcut to: "C:\Program Files\D-Link\D-Link RangeBooster N DWA-542\wirelesscm.exe" [" "]
Enabled Scheduled Tasks:
------------------------
"1-Click Maintenance" -> launches: "C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe /schedulestart" [file not found]
Winsock2 Service Provider DLLs:
--------------------------
-----
Namespace Service Providers
HKLM\System\CurrentControl
Set\Servic
es\Winsock
2\Paramete
rs\NameSpa
ce_Catalog
5\Catalog_
Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\msw
sock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\win
rnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\msw
sock.dll" [MS]
000000000004\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll"
["Apple Computer, Inc."]
Transport Service Providers
HKLM\System\CurrentControl
Set\Servic
es\Winsock
2\Paramete
rs\Protoco
l_Catalog9
\Catalog_E
ntries\ {++}
0000000000##\PackedCatalog
Item (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\msws
ock.dll [MS], 01 - 03, 06 - 17
%SystemRoot%\system32\rsvp
sp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
--------------------------
----------
Toolbars
HKCU\Software\Microsoft\In
ternet Explorer\Toolbar\WebBrowse
r\
"{EF99BD32-C1FB-11D2-892F-
0090271D4F
88}"
-> {HKLM...CLSID} = "Yahoo! Toolbar"
\InProcServer32\(Default) = "C:\PROGRA~1\Yahoo!\Compan
ion\Instal
ls\cpn\yt.
dll" ["Yahoo! Inc."]
HKLM\Software\Microsoft\In
ternet Explorer\Toolbar\
"{381FFDE8-2394-4F90-B10D-
FC6124A40F
8C}" = "IEToolbar"
-> {HKLM...CLSID} = "BitDefender Toolbar"
\InProcServer32\(Default) = "C:\Program Files\BitDefender\BitDefen
der 2008\IEToolbar.dll" ["Bitdefender"]
"{EF99BD32-C1FB-11D2-892F-
0090271D4F
88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
\InProcServer32\(Default) = "C:\PROGRA~1\Yahoo!\Compan
ion\Instal
ls\cpn\yt.
dll" ["Yahoo! Inc."]
Explorer Bars
HKLM\Software\Microsoft\In
ternet Explorer\Explorer Bars\
HKLM\Software\Classes\CLSI
D\{FF059E3
1-CC5A-4E2
E-BF3B-96E
929D65503}
\(Default)
= "&Research"
Implemented Categories\{00021493-0000-
0000-C000-
0000000000
46}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFI
CE11\REFIE
BAR.DLL" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\In
ternet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0016-0000-0003-
ABCDEFFEDC
BC}"
-> {HKCU...CLSID} = "Java Plug-in 1.6.0_03"
\InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll" ["Sun Microsystems, Inc."]
-> {HKLM...CLSID} = "Java Plug-in 1.6.0_03"
\InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_03\bin
\npjpi160_
03.dll" ["Sun Microsystems, Inc."]
{5BAB4B5B-68BC-4B02-94D6-2
FC0DE4A789
7}\
"ButtonText" = "Yahoo! Services"
"CLSIDExtension" = "{5BAB4B5B-68BC-4B02-94D6-
2FC0DE4A78
97}"
-> {HKLM...CLSID} = "Yahoo! IE Services Button"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Common\yiesrv
c.dll" ["Yahoo! Inc."]
{85D1F590-48F4-11D9-9669-0
800200C9A6
6}\
"MenuText" = "Uninstall BitDefender Online Scanner v8"
"Exec" = "%windir%\bdoscandel.exe" [null data]
{92780B25-18CC-41C8-B9BE-3
C9C571A826
3}\
"ButtonText" = "Research"
{E2E2DD38-D088-4134-82B7-F
2BA3849658
3}\
"MenuText" = "@xpsp3res.dll,-20001"
"Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]
{FB5F1910-F110-11D2-BB9E-0
0C04F79568
3}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe
" [MS]
Miscellaneous IE Hijack Points
--------------------------
----
HKCU\Software\Microsoft\In
ternet Explorer\URLSearchHooks\
<<H>> "{EF99BD32-C1FB-11D2-892F-
0090271D4F
88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
\InProcServer32\(Default) = "C:\PROGRA~1\Yahoo!\Compan
ion\Instal
ls\cpn\yt.
dll" ["Yahoo! Inc."]
Running Services (Display Name, Service Name, Path {Service DLL}):
--------------------------
----------
----------
----------
----------
Atheros Configuration Service, ACS, "C:\Program Files\D-Link\D-Link RangeBooster N DWA-542\acs.exe" ["Atheros"]
Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2e
vxx.exe" ["ATI Technologies Inc."]
BitDefender Communicator, XCOMM, ""C:\Program Files\Common Files\BitDefender\BitDefen
der Communicator\xcommsvr.exe"
/service" ["Softwin"]
BitDefender Desktop Update Service, LIVESRV, ""C:\Program Files\Common Files\BitDefender\BitDefen
der Update Service\livesrv.exe" /service" ["BitDefender S.R.L."]
BitDefender Threat Scanner, scan, "C:\WINDOWS\System32\svcho
st.exe -kbdx" {"C:\Program Files\Common Files\BitDefender\BitDefen
der Threat Scanner\scan.dll" ["BitDefender"]}
BitDefender Virus Shield, VSSERV, ""C:\Program Files\BitDefender\BitDefen
der 2008\vsserv.exe" /service" ["BitDefender S.R.L."]
Diskeeper, Diskeeper, ""C:\Program Files\Diskeeper Corporation\Diskeeper\DkSe
rvice.exe"
" ["Diskeeper Corporation"]
LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBC
ES.EXE" ["Lexmark International, Inc."]
Print Monitors:
---------------
HKLM\System\CurrentControl
Set\Contro
l\Print\Mo
nitors\
Dell Network Port\Driver = "LEXLMPM.DLL" ["Lexmark International, Inc."]
Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]
---------- (launch time: 2007-10-16 18:04:59)
<<!>>: Suspicious data at a malware launch point.
<<H>>: Suspicious data at a browser hijack point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 30 seconds.
---------- (total run time: 73 seconds)