Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

2901.

Solve : I’m using a BT home hub and when surfing the web it seems to frequently crash?

Answer»

I'm using a BT home hub and when surfing the WEB it seems to frequently crash a lot and I have to unplug it at the mains and restart it to get back on the web (did not have this problem with my old voyager modem) I have found out that If I go in the settings and DISABLE the HUBS built-in firewall everything is OK can any one tell me if I need to RUN a software firewall as well as the hardware firewall and if I'm compromising my security by turning it off.. -PS I'm using zone alarm Any help will be welcome Anna

Obviously the firewall shouldn't be MAKING the modem crash, so it might be worth checking whether any firmware updates are available. A firmware update will upgrade the software in the modem.
If you got the modem from an ISP you should check with them.

You aren't compromising your security by disabling the hardware firewall though when you have a software firewall in place. But there's nothing wrong in having both a hardware and software firewall between you and the big bad web.

2902.

Solve : AppInit_DLLs?

Answer»

Alright, just SCANNED with AVG Antispyware in normal mode. There's this very stubborn file on my system that doesn't delete when I delete it. AVG Anti-spyware identified it as Not-A-Virus.Adware.BHO. Here's the LOG.

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at:4:51:22 PM 2/02/2008

+ Scan result:



C:\Documents and Settings\John\Local Settings\Temp\{17480E83-7BAD-4E32-86EB-EC919C66535B}\_extra\objects\cmdline.dll -> Not-A-Virus.Adware.BHO : Ignored.
C:\Documents and Settings\\Local Settings\Temp\{4DD377A2-607A-4D53-AA1E-A67911D8A3E4}\_extra\objects\cmdline.dll -> Not-A-Virus.Adware.BHO : Ignored.


::Report end

2903.

Solve : Win.2k Pro popups.?

Answer»

Win.2k Pro SP4 - AVG Free, Zone Alarm Free, SpywareBlaster - Adaware SE Pro, CCLEANER, SpyBot s&d.

Ever since a clean INSTALL have been getting the attached popups at random intervals. Have scanned and nothing found by any maintenance program including online scanners. Msconfig>Startup shown nothing abnormal.

Apart from the annoying popups the system is running well.

Any ideas what is causing the popups please?

[file cleanup - saving space - attachment deleted by admin]Download, and run Shoot Messenger: HTTP://www.grc.com/stm/shootthemessenger.htmThank you Broni, I found the answer by disabling Messenger in Services, took me a while to think of Googling for Messenger Services, should have known better

Sure THING.

2904.

Solve : MSN virus and general cleanup?

Answer»

My friend fell for the stupid MSN virus that sends itself to people and he had some viruses a few months ago. I ran through Broni's usual instructions, here are the logs.

ESET:

# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=Unknown
# vers_standard_module=2829 (20080128)
# vers_arch_module=1.063 (20080117)
# vers_adv_heur_module=1.060 (20070601)
# EOSSerial=a383a53b196cb94f92cb2eca6ec83c6c
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-01-29 12:39:11
# local_time=2008-01-28 07:39:11 (-0500, Eastern Standard Time)
# country="Canada"
# osver=5.1.2600 NT Service Pack 2
# scanned=407599
# found=0
# scan_time=4425


SUPERantispyware:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/29/2008 at 00:35 AM

Application Version : 3.9.1008

Core Rules Database Version : 3389
Trace Rules Database Version: 1383

Scan type : Complete Scan
Total Scan Time : 04:40:42

Memory items scanned : 175
Memory threats detected : 0
Registry items scanned : 7122
Registry threats detected : 0
File items scanned : 171523
File threats detected : 44

Adware.Tracking Cookie
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][2].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][2].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][2].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][2].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][2].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][2].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][1].txt
C:\Documents and Settings\Dmitri Shatrov\Cookies\dmitri [emailprotected][2].txt

Trojan.Security Toolbar
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url
C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url

Trace.Known Threat Sources
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\S5IJ4X6N\Chriss%20Angel%20Gets%20Hit%20By%20A%20Car_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\01234567\Crazy%20scateboard%20dude_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\4DYJCDEF\Chris%20Angel%20does%20aWood%20Chipper%20Illusion_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\05YZO16V\Chris%20Angel%20Can%20Fly_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\4DYJCDEF\Chris%20Angel%20predicts%20the%20future_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\05YZO16V\VG_zango_300x250_11[1].gif
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\4DYJCDEF\Bungee%20Jumping_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\05YZO16V\Break%20Dancing_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\4DYJCDEF\Bungee%20Jumping%20in%20Africa_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\01234567\30%20Second%20Rubik's%20Cube_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\S5IJ4X6N\Cyril%20Card%20Through%20Glass_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\01234567\Chris%20Angel%20Levitation_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\S5IJ4X6N\Chriss%20Angel%20Knives%20Stunt_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\05YZO16V\7%20Year%20Old%20Pool%20Shark_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\05YZO16V\Chris%20Angel%20walks%20through%20glass%20window%20without%20breaking%20it!_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\01234567\Chicken%20Dance_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\01234567\Cool%20DJ%20Battle_size_large[1].jpg
C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temporary Internet Files\Content.IE5\4DYJCDEF\JS_zango_300x250_3[1].gif
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:29:25 PM, on 30/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Diskeeper\DkService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\FSScrCtl.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Comodo\Firewall\cpf.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = *Blocked Russian URL*
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Microsoft Update Machine] zxpbkt.exe
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\RunServices: [Microsoft Update Machine] zxpbkt.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Microsoft Update Machine] zxpbkt.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O8 - Extra context menu ITEM: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{63C17329-8E16-4ECC-9DCA-C0DEB8F9917D}: NameServer = 64.71.255.198
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 7572 bytesOpen Hijackthis and select Do a system scan only.

Place a check MARK next to the following entries:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Important: Close all windows except for Hijackthis and then click Fix checked.

Exit Hijackthis.

----------

Download SDFix.exe and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following:

  • RESTART your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard).
  • Finally add the contents of the Report.txt in your next post.
----------

Next run a new Hijackthis scan and post that log also.

----------

Is ROGERS CABLE COMMUNICATIONS INC your ISP?


Next post please add
SDFix log
New Hijackthis log
Rogers is his ISP. Here are the logs:

SDFix:


SDFix: Version 1.134

Run by Dmitri Shatrov on 30/01/2008 at 09:47 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\WINDOWS\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\Documents and Settings\Dmitri Shatrov\Local Settings\Temp\utt41C.tmp.exe - Deleted





Removing Temp Files...

ADS Check:




Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-30 21:53:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:cb,43,30,8f,d7,2a,36,f4,0e,5c,b2,53,3f,23,cd,e6,6a,77,d6,bd,ee,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,6a,f4,a0,f0,b3,7d,3e,76,be,a4,da,30,9a,ce,3f,a0,4c,..
"khjeh"=hex:af,8e,ab,4d,0a,20,f8,bf,31,5c,f0,d4,c3,e0,0a,03,97,dc,3d,f2,af,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:f9,84,82,50,07,10,12,5a,b1,c5,70,fd,72,4b,76,af,da,87,15,aa,57,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:a7,87,79,1f,d1,0f,09,70,1e,df,5f,73,d4,af,14,38,05,83,65,62,64,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:7e,9c,cf,3c,1e,5c,b8,dd,34,ea,21,84,c5,17,da,1f,5f,39,a2,e2,8e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:cb,43,30,8f,d7,2a,36,f4,0e,5c,b2,53,3f,23,cd,e6,6a,77,d6,bd,ee,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,6a,f4,a0,f0,b3,7d,3e,76,be,a4,da,30,9a,ce,3f,a0,4c,..
"khjeh"=hex:af,8e,ab,4d,0a,20,f8,bf,31,5c,f0,d4,c3,e0,0a,03,97,dc,3d,f2,af,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:f9,84,82,50,07,10,12,5a,b1,c5,70,fd,72,4b,76,af,da,87,15,aa,57,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:a7,87,79,1f,d1,0f,09,70,1e,df,5f,73,d4,af,14,38,05,83,65,62,64,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:7e,9c,cf,3c,1e,5c,b8,dd,34,ea,21,84,c5,17,da,1f,5f,39,a2,e2,8e,..

scanning hidden registry entries ...

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ \4C\4A\4A\4>\0041\48\4B\4 ]
"Order"=hex:08,00,00,00,02,00,00,00,68,01,00,00,01,00,00,00,02,00,00,00,b6,..

scanning hidden files ...


scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 2


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:зTorrent"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"="C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"C:\\Program Files\\Call of Duty 2\\CoD2MP_s.exe"="C:\\Program Files\\Call of Duty 2\\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\\WINDOWS\\system32\\zxpbkt.exe"="C:\\WINDOWS\\system32\\zxpbkt.exe:*:Enabled:zxpbkt"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Nero\\Nero8\\Nero ShowTime\\ShowTime.exe"="C:\\Program Files\\Nero\\Nero8\\Nero ShowTime\\ShowTime.exe:*:Enabled:Nero ShowTime"
"C:\\Program Files\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)"
"C:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"="C:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe:*:Enabled:Company of Heroes - Opposing Fronts"
"C:\\WINDOWS\\system32\\dpnsvr.exe"="C:\\WINDOWS\\system32\\dpnsvr.exe:*:Disabled:Microsoft DirectPlay8 Server"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:
---------------

File Backups: - C:\WINDOWS\SDFix\backups\backups.zip

Files with Hidden Attributes:

Thu 10 Jan 2008 2,516 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sun 9 Dec 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT4.tmp"
Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT2.tmp"
Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BIT6.tmp"
Wed 23 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\585dc2612ebcefc90e7dee4c276ee95e\BIT3.tmp"
Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b69c46c5109d0f8b0dee9fab84906813\BIT5.tmp"
Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BIT7.tmp"
Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fa6c916bb150f8a929e7a4ffdfbc120f\BIT3.tmp"

Finished!


HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:02:46 PM, on 30/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Diskeeper\DkService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\FSScrCtl.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = *Blocked Russian URL*
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{63C17329-8E16-4ECC-9DCA-C0DEB8F9917D}: NameServer = 64.71.255.198
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 7173 bytes
The Hijackthis log looks fine. How is the computer now?Its good. Use OTMoveIt2 to remove SDFix and it's related files. Leaving them on the computer will likely result in your antivirus identifying the quarantine as a virus.

Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop.

1. Double click OTMoveIt2.exe to launch it.
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
5. Once complete exit out of OTMoveIt2

This is a good time to clear your infected system restore points and establish a new clean restore point:
  • Go to Start > All Programs > Accessories > System Tools > System Restore
  • Select Create a restore point, and click Next.
  • Next, go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Next to System Restore click Clean up...
This will remove all restore points except the new one you just created.

Here are some great tools to help you keep from getting infected again.

Spybot Search & Destroy - A safe and effective spyware scanner.
* Official Spybot Tutorial
* Spybot FAQ

AVG Anti-Spyware Free EDITION - Very reliable with a high detection rate.
* AVG Anti-Spyware User Manual

SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* SpywareBlaster Tutorial

Comodo BOClean - Stops trojans and many more malicious attacks.

Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
* Click here for a list of free firewalls.
* Why would I consider a third party firewall?

UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
* Help with Windows updates

Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

Let us know if anything else comes up.Thanks, did all that.Glad it worked.

Safe surfing.........
2905.

Solve : AVI files problem?

Answer»

Hi BRONI,

I did what "neljan" suggested (Post 59) and it seems to have sorted out my AVI problem - not sure how. Going to download a couple of AVI files, to see how I get on.

I would like to thank you for all your time and trouble.

Belvin Hi neljan,

Went through your posting and suggested DOWNLOADS. Seems to have sorted out my AVI problem. Not sure which programme sorted it, as I did the lot before checking.

I'd like to thank you though.

BelvinAnytime Blevin, I'm very HAPPY for you!

May I also say how pleasent it was talking to you, you were more than WORTHY of my time!

All the best...Way to go, guys!!! What a team a Broni?

I didn't do anything....LOL

2906.

Solve : Msn Virus HELP?

Answer»

My msn automatically sends files to everyone online

like: Me says: heyyy are you on this picture??
Me says: (file name)

I fell for it and now im a carrier

Help Please!
Hickjack THIS LOG part 1


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:51:45 PM, on 30/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\DISC\DiscGui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\vVX6000.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\sbmsp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\RTHDCPL.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\BITCOMET\BitComet.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
Hijackthis log PART 2

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: The ensfolr - {A037112F-183D-4E98-8CEA-1A0D93BA9F48} - C:\WINDOWS\ensfolr.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [HPHUPD08] "c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe"
O4 - HKLM\..\Run: [DISCover] "C:\Program Files\DISC\DISCover.exe"
O4 - HKLM\..\Run: [DiscUpdateManager] "C:\Program Files\DISC\DiscUpdateMgr.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] "c:\Program Files\Norton Internet Security\UrlLstCk.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [sbmsp] C:\WINDOWS\system32\sbmsp.exe
O4 - HKLM\..\Run: [jndx] C:\WINDOWS\system32\jndx.exe
O4 - HKLM\..\RunServices: [sbmsp] C:\WINDOWS\system32\sbmsp.exe
O4 - HKLM\..\RunServices: [jndx] C:\WINDOWS\system32\jndx.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /BACKGROUND
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /TRAY
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
HickJackthis log part 3

O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Print Spooler Service (mvzu2yo3k) - Unknown owner - C:\WINDOWS\system32\jndx.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe1. Run free ESET Online Scanner at: http://www.eset.com/onlinescan/
Note: This Scanner is for Internet Explorer Only
1. You will notice that the "Start" button is grayed out. Place a check mark at "Yes, I accept the Terms of use". The "Start" button will become visible. Click on it.
2. If it wants to install an ActiveX component allow it
3. You will be asked to install an ActiveX, click the "Install" button (Note: If you have a Firewall install you may have to approve the installation)
4. Once ActiveX control is installed click on the "Start" button to initialize the scanner
5. After initialization is complete uncheck\untick "Remove found threats"
6. Check\tick "Scan unwanted applications"
7. Click the "Scan" button
8. Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt
Post ESET's log.

2. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

Print these instructions out.

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four CORNERS of your screen

* Open SUPERAntiSpyware.
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were DETECTED. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply with a new HijackThis log.
* Click Close to exit the program.
Post SUPERAntiSpyware log.

3. Post new HijackThis log.[/B]k all the logs
help

[file cleanup - saving space - attachment deleted by admin]*** Go Start>Control Panel>Add\Remove, and uninstall SpyNoMore - worthless.

*** Disable TeaTimer, since it'll interfere with the cleaning process:
* Right click Spybot's TeaTimer System Tray Icon > click Exit Spybot-S&D Resident.
o TeaTimer closes.

*** Disable Windows Defender, as it'll interfere with cleaning process:
* Open Windows Defender
* Click Tools
* Click General Settings
* Scroll down to Real Time Protection Options
* Uncheck Turn on Real Time Protection
* After you uncheck this, click on the Save button
* Close Windows Defender


1. Print this post out, since you won't have an access to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actuall program will be removed):

- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
- *O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
- *O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
- *O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
- *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
- *O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
- *O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
(I recommend, you unistall Adobe Acrobat Reader, which is enormous hog, and install FoxIt Reader (http://www.foxitsoftware.com/pdf/rd_intro.php), which is much smaller, and faster.)
- O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
- O4 - HKLM\..\Run: [jndx] C:\WINDOWS\system32\jndx.exe
- *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
- *O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
- O4 - HKLM\..\RunServices: [jndx] C:\WINDOWS\system32\jndx.exe (2nd occurrence)
- *O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
- *O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
- *O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
- *O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
- *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
- *O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
- *O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
- O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
- O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
- O15 - Trusted Zone: http://*.trymedia.com (HKLM) (If you did not add these pages to your trusted pages, they should be fixed)
- O23 - Service: Print Spooler Service (mvzu2yo3k) - Unknown owner - C:\WINDOWS\system32\jndx.exe (file missing)

4. Click on "Fix checked" button.

5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

7. Delete following files/folders (if present):

- SpyNoMore folder from C:\Program Files
- jndx.exe file from C:\WINDOWS\system32

8. Turn off System Restore:

- Windows XP:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore".
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
- Windows Vista:
1. Click Start.
2. Right-click the Computer icon, and then click Properties.
3. Click on System Protection under the Tasks column on the left side
4. Click on Continue on the "User Account Control" window that pops up
5. Under the System Protection tab, find Available Disks
6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
8. Click OK

9. Restart in Normal Mode.

10. Turn System Restore on.

11. Post new HijackThis log.new hijackthis log
thanks for the help

[file cleanup - saving space - attachment deleted by admin]It looks MUCH better. We're almost there....

If you uninstalled Adobe Acrobat Reader, as I suggested, open HJT one more time, checkmark this:
- O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
Click "Fix checked".
Close HJT.

Go Start>Run, type in:
regedit
Click OK.
Registry Editor will open.
Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions folder
In the above folder, you'll see (left pane) alphanumeric subfolders.
Find:
{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}
Right click on it, click Delete

Go Start>Run, type in:
services.msc
Click OK.
Services window will open.
Find:
Print Spooler Service
If it's listed as Running, right click on it, click Stop
Right click again, click Properties, and under Startup type, select Disable from drop-down menu.

Go Start>Run, type in:
sc delete mvzu2yo3k (<----watch for "spaces")
Click OK.

Restart computer.
Post new HJT log.new log

[file cleanup - saving space - attachment deleted by admin]The log is clean

1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
2. Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

How is your computer doing?

2907.

Solve : blue rectangular window in entre of screen?

Answer»

Can anyone help me with this problem? A blue rectangular window has appeared in the centre of my screen. It is about 4 inches (10 cm) wide by 3.5 inches TALL. It floats on top of everything else, blocking out text beneath it. It has commands in it for screen settings: brightness, contrast, horizont position, vertical position, ETC. I cannot find any way of removing it or accessing it. It just seemed to appear for no apparent reason.
It appears at STARTUP during the bootup process, before Windows loads.
I have loaded an updated driver for the display

Operating SYSTEM: Windows XP SP2, 1.7GB, 40GB hard disk
Screen: Neovo LCD 19inch
RAM: 512

This sounds like the controls for your monitor.
The monitor should have buttons that let you move through the controls and some way of closing it. There's usually arrow or +/- buttons and an ok/MENU button.

Thanks deerpark
It definitely seems to be the monitor menu. The control buttons on the front of the monitor are inactive - must be something wrong with them. They don't respond when they are pushedIt sounds like a defective monitor to be honest.
If you can, connect it to another computer just to rule out the possibility of it being a defect in the computer that's causing this.

2908.

Solve : AVG Trojan Generic9.AVLZ?

Answer»

Quote

see HJT log
Where?....LOL

Quote
What was it? Is Generic9 an actual malicious infection?
I believe, it was false positive.

Quote
I know one of you folks made a comment somewhere to their disatisfaction with Tea Timer before.
Personally, I don't use it.

Quote
As soon as I am re-employed, I OWE you guy's--no bull I'll do it.
Ahhhh...free beer I tried to 'modify' and add the log. Here it is.

[file cleanup - saving SPACE - attachment deleted by ADMIN]It looks good
You may remove COUPLE of unnecessary startups. Open HJT, and checkmark these:
- O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
- O4 - HKCU\..\Run: [SUPERANTISPYWARE] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Click "Fix checked".

Run CCleaner, afterwards.
2909.

Solve : Trojan.packed.nsanti still here?

Answer»

Hi!

I'm still getting notifications from Symantec about Trojan.Packed.NsAnti that look like this:

Scan type: Auto-Protect Scan
Event: Security Risk Found!
Risk: Trojan.Packed.NsAnti
File: C:\Users\kittymaroon\AppData\Local\Temp\DWH1167.tmp
Location: Quarantine
Computer: KITTYMAROON-PC
User: Victoria Chao
Action taken: Quarantine succeeded : Access denied
Date found: Monday, April 27, 2009 4:09:22 PM

My symantec antivirus should be up-to-date (Version: 6/1/2009 rev. 3). SOMETIMES I'll go a few days without getting any virus WARNINGS--other days, I'll get over 50 in a half hour.

If it's at all helpful, I have a Dell Inspiron 1420 running Windows Vista. I have SP1 installed on it. I've also attached my logs, THOUGH I'd be happy to post them as WELL. Thanks so much for your help--I look forward to your reply!


[attachment deleted by admin]Download DDS by sUBs and save it to your desktop. Alternate DDS download link

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.

2910.

Solve : Trojan horse agent 2.JCS discovered today?

Answer»

I was so grateful to find this site, and have followed all the steps and CREATED the logs, which I will try to attach. Any help you can give me would be very much appreciated.

I have Windows XP and run AVG 3 times a week. The scan on 5/31/09 was fine, but today (6/2/09) I found three files infected with Trojan Horse Agent 2.JCS. AVG would not remove them because "the moved object is bigger than the archive size limit". All three infected files are in old computer files from my previous computer (copied to this one's hard drive) and are in My Pictures/Sample Pictures. I am sure I don't need those files, so could I just delete them? Would that solve the problem? I wasn't sure, so I didn't do anything.

Following your steps, I removed Viewpoint Manager (remove only) and Viewpoint Media Player. I ran the CCleaner, the superantispyware, and mbam. I had a very old Java, which I updated.

I had not been updating Windows, and the day before I found the infection I went through the process of getting SP3 and also downloaded 2 or 3 optional updates. I wondered if that had anything to do with getting the Trojan Horse.

I am going to attach the mbam log and hijink log.

Superantispyware is at

http://www.filedropper.com/superantispywarescanlog-06-02-2009-19-03-08

THANKS so much! I have to go to bed, but I will check back in the morning.

Alta Price
Bettendorf, Iowa




[attachment DELETED by admin]Interesting! Concerned that the Trojan might be spreading (I don't even know if they spread), I scanned my computer this morning and it didn't find any infection.

Does that mean the steps I followed yesterday took care of it?

Maybe I am done?

Thanks!

AltaHi again.

I read on the other thread that this trojan is a false positive.

I did try to do the hijack this self help thing last night, and there were 2 things that came up it said I should correct. However, I have no idea how to correct those things, so if you wouldn't mind looking at that for me I would really appreciate it!

No hurry, though. I am not sure if I have "bumped" my thread by posting REPLIES. I didn't understand that part of your directions, and apologize if I am not following them. Even if it puts me to the end of the line, I suspect my problems aren't as severe as others anyway.

Thanks again.

Alta Re: trojan hoarse agent2.jcs
Posted by: sevcikp - AVG Team (IP Logged)
Date: June 1, 2009 09:53PM

Hello,

no need to sent the file to AVG Tech. We can confirm, that this detection really is false alarm. Update fixing this false is currently being prepared and should be released soon.Everything looks OK.

You can have HijackThis fix this:

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

Realtek AC97 Audio - Event Monitor. "Sypware" file USED surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers

Use the Secunia Software Inspector to check for out of date software.

  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
2911.

Solve : Help needed with infection......please!?

Answer»

Before answering your question about how my computer is running now (it seems to be fine), I ran a complete scan of the whole computer with my AVG 8.5 and learned that AVG just this MORNING found and successfully moved to the virus vault 11 infections and a bunch of tracking cookies. See list below.

I have just changed my IE settings to block all cookies and accept only those I have allowed by exception. Maybe that will take care of the tracking cookie problem but is there something I can do prevent picking up these infections? AVG says everything is up to date and working.

I will wait for your response before doing anything else and I've not yet followed your last instruction to uninstall ComboFix. Let me know if you STILL want me to do that uninstall right now.

Thanks alot, I appreciate it. wildbjk.

INFECTIONS:

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP16\A0001001.sys";"Trojan horse Pakes.DPC";"Moved to Virus Vault"

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP16\A0001002.dll";"Trojan horse Rootkit-Pakes.A";"Moved to Virus Vault"

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP16\A0001003.dll";"Trojan horse Generic13.ATOC";"Moved to Virus Vault"

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP16\A0001004.dll";"Trojan horse Generic13.ATOB";"Moved to Virus Vault"

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP16\A0001026.dll";"Trojan horse Agent2.IBE";"Moved to Virus Vault"

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP16\A0001027.dll";"Trojan horse Agent2.IBE";"Moved to Virus Vault"

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP16\A0001029.exe";"Trojan horse SHeur2.AGJH";"Moved to Virus Vault"

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP16\A0001030.exe";"Trojan horse Agent2.IBG";"Moved to Virus Vault"

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP16\A0001031.exe";"Trojan horse Small.BKI";"Moved to Virus Vault"

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP17\A0001228.exe";"Trojan horse Small.BKI";"Moved to Virus Vault"

"C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP17\A0001229.dll";"Trojan horse Downloader.Generic8.AOLC";"Moved to Virus Vault"

TRACKING COOKIES:

"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\ad.yieldmanager.com.539b0606";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\ad.yieldmanager.com.557bf2b0";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\advertising.com.1820df7a";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\advertising.com.203aa218";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\advertising.com.1dfa2206";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\advertising.com.525a5fb9";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\advertising.com.b624fa46";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\advertising.com.f62113d5";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt";"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\atdmt.com.7247c262";"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\atdmt.com.b3e33b5f";"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\bs.serving-sys.com.5bf1f00f";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt";"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt:\doubleclick.net.bf396750";"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt";"Found Tracking cookie.2o7";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt:\msnportal.112.2o7.net.7225be6f";"Found Tracking cookie.2o7";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt";"Found Tracking cookie.Questionmarket";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\questionmarket.com.3eb5a9f1";"Found Tracking cookie.Questionmarket";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\questionmarket.com.4dd5e426";"Found Tracking cookie.Questionmarket";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt:\serving-sys.com.255d6f2f";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt:\serving-sys.com.4b416ef8";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt:\serving-sys.com.606c3d3b";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt:\serving-sys.com.400f83f";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt:\serving-sys.com.6a1cf9e8";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][1].txt:\serving-sys.com.c9034af6";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt";"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\tacoda.net.27341d57";"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\tacoda.net.4366831a";"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\tacoda.net.5935e89";"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\tacoda.net.c4fe2ebb";"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\tacoda.net.ed9c50d1";"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt";"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\trafficmp.com.a00e30b4";"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt";"Found Tracking cookie.Tribalfusion";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\tribalfusion.com.dcc03271";"Found Tracking cookie.Tribalfusion";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt";"Found Tracking cookie.Zedo";"Moved to Virus Vault"
"C:\Documents and Settings\Jim\Cookies\[emailprotected][2].txt:\zedo.com.27f1639b";"Found Tracking cookie.Zedo";"Moved to Virus Vault"
Nothing found by AVG is actually a threat.

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.

  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly CREATED clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also STOP certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Evilfantasy,

Sorry about the long delay in my reply but I just wanted to be sure my system was running properly before getting back to you. Good news! Everything seems to be fine with no SIGNS of infection........fantastic! I appreciate all your suggestions for keeping my system safe in the future.


Thank you very much for all your help and staying with it until the effort was successful. I can't begin to tell you how much I appreciate what you've done. Thank you, thank you, thank you!!!!!

Regards,
wildbjk
2912.

Solve : Virus Warnings?

Answer»

Hi,
I am getting multiple virus warnings from McAfee. They all refer to different infected files, so I have listed a couple below:

C:\SYSTEM VOLUME INFORMATION\_RESTORE{5B4B794D-8560-419A-B57D-EB3E8743B493}\RP166\A0045805.EXE
W32/Trats

C:\SYSTEM VOLUME INFORMATION\_RESTORE{5B4B794D-8560-419A-B57D-EB3E8743B493}\RP166\A0045811.EXE\A0045811.EXE
Downloader-AWM.gen

I have attached the requested scan logs - any help would be appreciated.

Thanks

Nick


[file cleanup - saving space - attachment deleted by admin]Thanks for following the guide before posting. It looks LIKE it got rid of alot. There is still some cleaning to do.

Open HJT and select Do a system scan only and then place a check mark next to:


O2 - BHO: (no name) - {5C3F6257-3E00-45C2-88D5-CB0F3A17BF0E} - (no file)O2 - BHO: (no name) - {5C3F6257-3E00-45C2-88D5-CB0F3A17BF0E} - (no file)
O2 - BHO: (no name) - {6F87F145-DC2D-4766-AF03-3A3B96FFAD98} - (no file)
O20 - Winlogon Notify: agvfqnaa - agvfqnaa.dll (file missing)
O20 - Winlogon Notify: efcyyyy - efcyyyy.dll (file missing)
O20 - Winlogon Notify: winaqc32 - winaqc32.dll (file missing)


Close all windows except for Hijackthis and click Fix checked.

EXIT Hijackthis.

----------

Download Vundofix.exe to your desktop.

  • Double-click VundoFix.exe to run it.
  • Put a check next to Run VundoFix as a task.
  • You will receive a message saying vundofix will close and re-open in a MINUTE or less. Click OK
  • When VundoFix re-opens, click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

Please let Vundo finish, sometimes it can take multiple passes

----------

Do you know what this is? HQ.AUTOCAB.COM

----------

Next post please add
Vundofix log
NEW Hijackthis log
Thanks for your help - the PC appears to be running OK now, and all the virus warning messages have stopped.

I have attached the 2 new log files.

hq.autocab.com is the domain that the PC was on.

[file cleanup - saving space - attachment deleted by admin]Quote
hq.autocab.com is the domain that the PC was on.
You say was on? If it is no longer on the domain then you can have HJT fix those four O17 entries also. If it is needed then don't fix them.

Open HJT and select Do a system scan only and then place a check mark next to:

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)

Close all windows except for Hijackthis and click Fix checked.

Exit Hijackthis.

----------

Download and install CleanUp!

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
  • Click Options...
  • Make sure the arrow is set to Standard CleanUp!
  • Uncheck the following: (if checked)
    • Delete Newsgroup cache
    • Delete Newsgroup Subscriptions
  • Click OK
Click the CleanUp! button to start the program. Reboot/logoff when prompted.

Note: CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp! If you have a 64 bit Operating System do NOT run Cleanup and let me know as we will use another utility

----------

Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop.

1. Double click OTMoveIt2.exe to launch it.
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
  • When finished exit out of OTMoveIt2
.

UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
* Help with Windows updates

Learn more about how to PROTECT yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

Let us know if anything else comes up.
Almost forgot something.


Toggle System Restore to clear infected restore points

1. Turn off System Restore
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
2. Restart your computer

3. Turn ON System Restore
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore.
  • Click Apply, and then click OK.
Thanks for all your help, it seems to have done the job.

NickGlad it worked.

Safe surfing..............
2913.

Solve : Need Anti virus for WIndows XP with 128 Mb of RAM?

Answer»

I have WIndows XP service pack 2 and need anti-virus. My microprocessor(Celeron) has 996 Hz and I have 128 MB of RAM and I have 2.72 GB of FREE space. I previously had Norton Internet Security. I have a free cd of Norton ANti-virus, but it says I have to have 256 MB of Ram. If I had Norton Internet Security 2007 and I believe it requires 256MB of RAM too, then can I use my cd of Norton ANti-Virus? If not, any recommendations?Honestly Norton will slow down your computer and there are much better free alternatives.

Antivirus Click here
Suggested options are EITHER Avast, AVG or Avira.

Firewall Click here
Suggestions are Comodo, Sunbelt or Zone Alarm. (zone alarm can be heavy on resources so keep that in mind)

Note: If you choose Comodo it must be run in Advanced Mode to provide full protection. Basic mode is strongly NOT suggested.Straight to AVG's site is: http://free.grisoft.com


From here, http://free.grisoft.com/doc/download-free-anti-virus/us/frt/0
I see:

Minimum system requirements

* CPU Intel 486 133 MHz
* 30 MB free hard drive space (for installation)
* 32 MB RAM



RAM is pretty inexpensive these days...if you add another 512Mg. you, XP and your machine will be alot happier.Quote

RAM is pretty inexpensive these days...if you add another 512Mg
Not, that patio is any Norton SUPPORTER. He's far from it. Go with evil's advice.Due to conditions i'd rather not discuss i can no longer comment on Norton's until after it has been successfully un-installed...
2914.

Solve : Virus make all folders invisible?

Answer»

My flash was infected by virus that create each folder with .exe EXTENSION, and make all folders hidden.

After cleaning with antivirus (kaspersky 6), all folders are still disappeared. But when i create those folders again, it show the message folder are ALREADY exists. So, i try to tick "show hidden files and folders" in explorer but folders still invisible.

Is there anyway to make them visible?

Thanks.It sounds like there is still something that wasn't removed.

Download HijackThis.exe

* Double-click on the installer you just downloaded.
* Click on the Install BUTTON to install.
* It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
* Please do not change the default install location.
* Upon install, HijackThis should open for you.

* Next click on the Do a system scan and save a log file button.
* HijackThis will scan and then a log will open in notepad.
* Copy and then paste the log in your next reply.Urgently using it, I have formatted it. Sorry and Thanks for ur help. QUOTE from: khmerguy on February 01, 2008, 02:41:03 AM

Urgently using it, I have formatted it. Sorry and Thanks for ur help.

The flash drive more than likely infected your machine as well...i'd follow EF's suggestions.
2915.

Solve : Trojan Horse Agent 2JCS cannot be removed--please help!?

Answer»

I did all t his. Should I keep going? What's next?

Thanks

Dr. d'EliaLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30:13 PM, on 6/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\XpertVision\TBPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
E:\OpwareSE4.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
E:\reza\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\All USERS\Application Data\Skype\Plugins\Plugins\9E0D937F462E4362A83B254A9F8AB3F8\InnerPassFileSharing.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\freecell.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\JAVA\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [TBPanel] C:\Program Files\XpertVision\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "E:\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\reza\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Innerpass] C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\9E0D937F462E4362A83B254A9F8AB3F8\InnerPassFileSharing.exe autostart
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] E:\reza\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199258053546
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BFCF1F9A-D083-495F-868C-0F6558AD7FE5}: NameServer = 85.15.1.13 85.15.1.10
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 9667 bytes
This entry.

Quote

O4 - HKCU\..\Run: [Innerpass] C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\9E0D937F462E4362A83B254A9F8AB3F8\InnerPassFileSharing.exe

Appears to be from Skype and is labeled as adware. See here http://www.prevx.com/filenames/X1987307338720066266-X1/INNERPASSFILESHARING.EXE.html

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixWow! I downloaded that thing myself. It was supposed to be a real time conference and document sharing. It seemed to work okay for me, but the person who was trying to join me in the "room" said that her browser crashed when she tried to use this program. I guess that should have been a sign....
Now, I will go and do what you said.

Thanks again.

In peace
Dr. D.

P.S. should I tell the skype people that the program they are offering as an option has adware?ComboFix 09-05-31.06 - Irani 06/02/2009 0:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.3582.2901 [GMT 4.5:30]
Running from: c:\documents and settings\Irani\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\INSTALL.LOG
D:\Autorun.inf
E:\Autorun.inf
H:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-05-01 to 2009-06-01 )))))))))))))))))))))))))))))))
.

2009-06-01 17:30 . 2009-06-01 17:303371383----a-w-c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-01 15:54 . 2009-06-01 15:54--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-01 15:54 . 2009-06-01 15:54--------d-----w-c:\program files\SUPERAntiSpyware
2009-06-01 15:54 . 2009-06-01 15:54--------d-----w-c:\documents and settings\Irani\Application Data\SUPERAntiSpyware.com
2009-06-01 14:49 . 2009-06-01 14:49--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-06-01 02:15 . 2009-06-01 02:15--------d-----w-c:\windows\system32\config\systemprofile\Application Data\PC Suite
2009-05-21 14:43 . 2009-05-21 14:4369632----a-w-c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\9E0D937F462E4362A83B254A9F8AB3F8\zInnerPassUninstall.exe
2009-05-21 14:43 . 2009-05-21 14:43258048----a-w-c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\9E0D937F462E4362A83B254A9F8AB3F8\InnerPassFileSharing.exe
2009-05-21 14:43 . 2009-05-21 14:43242496----a-w-c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\9E0D937F462E4362A83B254A9F8AB3F8\tssCPopupNotify.dll
2009-05-21 14:43 . 2009-05-21 14:431828176----a-w-c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\9E0D937F462E4362A83B254A9F8AB3F8\Skype4COM.dll
2009-05-20 04:28 . 2009-05-03 07:492051864----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-05-20 04:28 . 2009-05-03 07:48354584----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll
2009-05-20 04:28 . 2009-05-03 07:48424472----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwdwsc.dll
2009-05-20 04:28 . 2009-05-03 07:48177432----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgmail.dll
2009-05-20 04:28 . 2009-05-03 07:49486168----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgrsx.exe
2009-05-20 04:28 . 2009-05-03 07:493288344----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-05-20 04:28 . 2009-05-03 07:48312088----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avglngx.dll
2009-05-20 04:27 . 2009-05-03 07:451437464----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-05-20 04:27 . 2009-05-03 07:45755992----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avginet.dll
2009-05-16 10:48 . 2009-05-03 07:492302232----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-05-16 10:48 . 2009-05-03 07:493399960----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-05-16 02:18 . 2009-06-01 17:43--------d-----w-c:\documents and settings\Irani\Application Data\skypePM
2009-05-16 02:18 . 2009-05-16 02:1856---ha-w-c:\windows\system32\ezsidmv.dat
2009-05-16 02:16 . 2009-06-01 19:43--------d-----w-c:\documents and settings\Irani\Application Data\Skype
2009-05-16 02:15 . 2009-05-16 02:15--------d-----w-c:\program files\Common Files\Skype
2009-05-16 02:15 . 2009-05-16 02:15--------d-----r-c:\program files\Skype
2009-05-16 02:15 . 2009-05-16 02:15--------d-----w-c:\documents and settings\All Users\Application Data\Skype
2009-05-15 05:57 . 2009-05-15 05:57--------d-----w-c:\documents and settings\All Users\Application Data\CyberLink
2009-05-05 18:41 . 2009-05-05 18:41--------d-----w-c:\documents and settings\Irani\Local Settings\Application Data\WinZip
2009-05-05 18:40 . 2009-05-05 18:41--------d-----w-c:\documents and settings\All Users\Application Data\WinZip

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 18:54 . 2009-02-09 23:07410984----a-w-c:\windows\system32\deploytk.dll
2009-06-01 17:32 . 2008-09-19 00:00--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2009-05-31 10:48 . 2008-01-01 08:07--------d--h--w-c:\program files\InstallShield Installation Information
2009-05-31 03:21 . 2009-02-04 15:544330----a-w-c:\documents and settings\Irani\Application Data\wklnhst.dat
2009-05-26 08:50 . 2008-09-19 00:0040160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 08:49 . 2008-09-19 00:0019096----a-w-c:\windows\system32\drivers\mbam.sys
2009-05-22 19:19 . 2008-01-02 02:17--------d-----w-c:\documents and settings\Irani\Application Data\Canon
2009-05-20 03:11 . 2008-10-27 19:08--------d-----w-c:\program files\MSECache
2009-05-09 16:16 . 2009-02-06 12:32--------d-----w-c:\documents and settings\Irani\Application Data\AVGTOOLBAR
2009-05-03 07:49 . 2009-02-05 19:5811952----a-w-c:\windows\system32\avgrsstx.dll
2009-05-03 07:49 . 2008-09-17 19:46325896----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-05-03 07:49 . 2008-09-17 19:4627784----a-w-c:\windows\system32\drivers\avgmfx86.sys
2009-05-03 07:49 . 2009-02-06 12:32108552----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-05-01 18:41 . 2009-05-01 18:4150----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\6172\track.dll
2009-05-01 18:41 . 2009-05-01 18:412562----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\6172\hitcounter.dll
2009-05-01 18:41 . 2009-05-01 18:412020----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\6172\externalredirect.dll
2009-05-01 18:41 . 2009-05-01 18:4150----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\4902\track.dll
2009-05-01 18:41 . 2009-05-01 18:412562----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\4902\hitcounter.dll
2009-05-01 18:41 . 2009-05-01 18:412020----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\4902\externalredirect.dll
2009-05-01 13:00 . 2009-05-01 13:00--------d-----w-c:\documents and settings\All Users\Application Data\Elaborate Bytes
2009-05-01 13:00 . 2009-05-01 12:5548--sh--w-c:\windows\S6E389119.tmp
2009-05-01 12:55 . 2009-05-01 12:55--------d-----w-c:\program files\Elaborate Bytes
2009-04-30 07:22 . 2009-04-30 07:22--------d-----w-c:\documents and settings\Irani\Application Data\CyberLink
2009-04-28 02:16 . 2008-09-19 10:584----a-w-C:\timeStmp.tmp
2009-04-22 07:08 . 2009-04-22 07:08--------d-----w-c:\documents and settings\Irani\Application Data\Apple Computer
2009-04-21 21:18 . 2009-04-21 21:189676----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\4370\prscript.dll
2009-04-21 21:18 . 2009-04-21 21:179676----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\15718\prscript.dll
2009-04-21 21:16 . 2009-04-21 21:161895----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\4370\adsadclient31.dll
2009-04-20 22:06 . 2008-09-17 14:03--------d-----w-c:\program files\Common Files\Adobe
2009-04-17 19:10 . 2009-04-17 19:108523----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\7930\prscript.dll
2009-04-17 19:10 . 2009-04-17 19:108523----a-w-c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\zotero\storage\48\prscript.dll
2009-04-10 00:21 . 2009-04-07 15:3660744----a-w-c:\documents and settings\Irani\g2mdlhlpx.exe
2009-03-11 18:53 . 2009-03-11 18:539728----a-w-c:\documents and settings\All Users\Application Data\Installations\{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}\Installations\CommonCustomActions\UninstPCS.exe
2009-03-11 18:53 . 2009-03-11 18:538192----a-w-c:\documents and settings\All Users\Application Data\Installations\{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}\Installations\CommonCustomActions\UninstCCD.exe
2009-03-11 18:53 . 2009-03-11 18:5315360----a-w-c:\documents and settings\All Users\Application Data\Installations\{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}\Installations\CommonCustomActions\UninstPCSFEMsi.exe
2009-03-06 14:22 . 2004-08-04 01:56284160----a-w-c:\windows\system32\pdh.dll
2001-10-22 08:33 . 2001-10-22 08:33425984----a-w-c:\program files\nokcvtr.exe
2001-09-29 15:16 . 2001-09-29 15:16961----a-w-c:\program files\menu.dat
2001-08-23 20:17 . 2001-08-23 20:171314719----a-w-c:\program files\nokhelp.hlp
2001-08-23 20:16 . 2001-08-23 20:16304----a-w-c:\program files\nokhelp.cnt
2001-07-29 15:29 . 2009-03-12 08:4396256----a-w-c:\program files\UnGins.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]
"Innerpass"="c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\9E0D937F462E4362A83B254A9F8AB3F8\InnerPassFileSharing.exe" [2009-05-21 258048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"="c:\program files\XpertVision\TBPanel.exe" [2008-01-29 2157064]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-03 13508608]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-03 86016]
"UVS11 Preload"="c:\program files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [2007-03-03 341488]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-03 1947928]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="E:\OpwareSE4.exe" [2007-02-04 79400]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"PCSuiteTrayApplication"="e:\reza\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-01 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-02-13 16857600]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-01-03 1626112]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="e:\reza\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-1-14 525664]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 06:35356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-03 07:4911952----a-w-c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Documents and Settings\\Irani\\My Documents\\reza p\\BlueSoleil.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/18/2008 12:16 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/6/2009 5:02 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 4:17 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 4:17 PM 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2/6/2009 5:02 PM 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2/6/2009 12:28 AM 298776]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [9/19/2008 4:54 AM 33752]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 4:17 PM 7408]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - JAVAQUICKSTARTERSERVICE
.
Contents of the 'Scheduled Tasks' folder

2009-05-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:04]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {BFCF1F9A-D083-495F-868C-0F6558AD7FE5} = 85.15.1.13 85.15.1.10
FF - ProfilePath - c:\documents and settings\Irani\Application Data\Mozilla\Firefox\Profiles\eisu2rnz.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np32asw.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-02 00:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=HEX:c8,28,51,af,b0,29,a3,98,7b,56,9d,92,f4,
b7,bf,04,e2,63,26,f1,3f,c8,ff,68,04,0f,49,10,65,c9,a0,b2,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,d6,b0,36,72,91,
6d,b3,0b,6a,9c,d6,61,af,45,84,18,80,59,6f,cc,97,4f,f6,73,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,f3,9d,89,01,e9,
30,39,d3,ff,7c,85,e0,43,d4,0e,fe,a0,a7,9d,cf,05,0f,f6,b6,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:6b,65,49,6a,7e,99,74,f7,58,7a,68,ea,29,
0e,66,d0,86,8c,21,01,be,91,eb,e7,83,13,05,42,88,ca,19,5e,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,63,0f,12,69,b6,
36,9c,04,f5,1d,4d,73,a8,13,5c,05,fd,51,fb,05,f1,e1,03,48,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:50,93,e5,ab,ec,6a,4e,ab,d2,af,95,b3,6b,
68,a0,62,df,20,58,62,78,6b,cf,c8,d5,aa,a9,bb,39,07,ab,0e,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,29,16,4e,27,3a,
1d,c4,7f,fb,a7,78,e6,12,2f,9a,ea,df,53,fe,94,ae,4c,32,c9,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,81,4d,1b,af,18,
18,bc,35,01,3a,48,fc,e8,04,4a,f1,69,ce,41,e8,23,6f,f4,8d,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,07,eb,58,9c,46,
8d,b4,2c,f6,0f,4e,58,98,5b,89,c9,2b,ad,e3,be,4b,66,1c,dc,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,6c,3f,29,8c,5e,
e1,64,2f,3d,ce,ea,26,2d,45,aa,78,08,aa,00,e1,9f,cb,b0,48,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,ff,5a,43,90,b9,
f6,94,9e,2a,b7,cc,b5,b9,7f,41,e7,73,94,d8,8f,32,d8,46,31,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,df,35,f4,ba,d6,
1f,61,40,6c,43,2d,1e,aa,22,2f,9c,ae,0a,ee,6a,ae,8c,7b,24,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(800)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-06-01 0:17
ComboFix-quarantined-files.txt 2009-06-01 19:47

Pre-Run: 2,489,245,696 bytes free
Post-Run: 2,482,802,688 bytes free

256--- E O F ---2009-05-16 16:32
Quote from: Drd on June 01, 2009, 01:36:43 PM

P.S. should I tell the skype people that the program they are offering as an option has adware?

Actually Skype doesn't have anything to do with it. It's third party software from https://www.innerpass.com/?

Can you give me the file path of the trojan AVG is finding? I don't see anything.Quote from: Drd on June 01, 2009, 01:55:33 AM
Hello: Last night I received a warning from my AVG Anti-Virus Free security that the computer was being attacked. I did a scan and found that there were two infections:
Both were Trojan Horse Agent 2JCS. One was lodged here:
C:\\Windows\System32\dllcache\logagent.exe That was "removed and healed"
Another was lodged here:
C:\\Windows\system32\logagent.exe This is listed in the AVG as "not healed" . When I click on the "infections" tab in the scan report, it says, "Object is white listed critical system file that should not be removed.

So what happens next? How do I get rid of the infection? Is it safe to keep using the computer when the infection hasn't been dealt with?

I'm using XP professional, version 5, service pack 3. I usually use a Firefox browser, although I also have IE on the system.

Thanks for your help.
In peace
Dr. D.

I am using XP Professional. This evening AVG warned about this file "C:\\Windows\system32\logagent.exe " infected.

I RESTARTED in safe mode.
Deleted the file manually.
Inserted the Windows CD to recover the original file.

And it worked for me. No more Trojan warnings.This is where they were. But I think that the Superspyware may have deleted the file. I couldn't delete it from the AVG because it was "white listed" and there was no choice offered to delete it.
C:\\Windows\System32\dllcache\logagent.exe That was "removed and healed"
Another was lodged here:
C:\\Windows\system32\logagent.exe This is listed in the AVG as "not healed" . When I click on the "infections" tab in the scan report, it says, "Object is white listed critical system file that should not be removed.

Is this cleared up now? Should I run another AVG scan or what?

Thanks

Dr. D
Whitelisted means it is not a threat. Is there a way to add it to the ignore list?

logagent.exe - Windows Media Player Log Agent http://www.fileresearchcenter.com/L/LOGAGENT.EXE-3321.htmlHi there people. Just got a warning for this myself on on AVG scan so I googled it hitting this very thread and then also this one:-

http://freeforum.avg.com/read.php?4,188951,188987

Seems its a false positive.

Cheers,

Ted.I'm a little confused here. Did I have a problem with my computer? Do I have one now or am I safe?

Thank you

In peace
Dr DIt's a FP so no there is not a problem.

Go here to report it to AVG so they will remove it from their BLACKLIST. YOU SUSPECT A FILE TO BE A FALSE POSITIVEOK . So thanks for all your help. I'm outta here.

In peace

Dr. D'EliaRe: trojan hoarse agent2.jcs
Posted by: sevcikp - AVG Team (IP Logged)
Date: June 1, 2009 09:53PM

Hello,

no need to sent the file to AVG Tech. We can confirm, that this detection really is false alarm. Update fixing this false is currently being prepared and should be released soon.
2916.

Solve : Should my computer make pop noises??

Answer»

Thank you for looking at this thread.

I have just changed to a new(ish) computer. It is a Celeron 2.8 Ghz with 1/2 gig ram, running Windows XP SP3. It has an 80 Gig SATA hard drive.

Being new, I would have THOUGHT it was a clean machine.
The drive was brand new and hardly used, except on the net for finding the drivers for the sound card and a few odd bits that didn't WORK properly.

Now when I go to web sites I hear a pop noise when I open some web pages.

Should my computer make such a noise?

Is this pop something that Windows has as a DEFAULT.


I swapped from the other computer for just exactly the same reason. I lost faith in the fact that these noises came too frequently, thinking it may have a virus or infection somewhere.
The computer doesn't make these pops all the time or from each web page I open.

If someone COULD give me some guidance I would very much LIKE to hear from you.

Thank you for your help. ImnoGuruGo to control panel>sounds and audio>sounds>select windows default sound scheme in the dropdown box ....see if that helps....you can make sound changes from here also....could also be a pop up blocker......TOOLS>popup blocker...toggle on/off ...see if it helpsThanks Karnac, for your help.
I'll try that now then.

I know Windows has a default sound section, and what I'm thinking is that if it were switched on there would be multiple sounds, say during several different operations, ie: opening/closing windows, saving data, restore up/down and so on.
I used to play with these things in my early years on computers, but long since found them distracting and annoying and thus forgot where I used to find them. (a bit like clipart stuff always loading new clipart that just took lots of space and never got used.)

If anything perhaps the popup blocker. That has better cred to me. Ok lets find out then.
Thanks again ImnoGuru. Ok then, I went through the section you outlined Karnac.

I found the sound was Windows XP Balloon.wav, under the Windows default sound scheme, system notification.
However I cant find how to delete just that one sound.

If I can delete just that sound, I can save that then as a new sound scheme.

I can set up a new scheme and name that, but I cant just delete the one notification or a group of sounds, nor can I do any other variation of sounds from it, (IT being the windows default sounds).
I was trying to find out if it was indeed just that sound that I'm hearing. (Well it is that sound, it just freaks me out that it is the only sound that occurs.) I would have thought I'd hear all of them but I don't.

So am I on the right track then, or should I run something like the HJT, SAS, MBAM or some other program to check the system?

Thank you ImnoGuru. I don't know if you've been down this path....

Control panel>Sounds and Audio>Program events>system notification>use the Sounds dropdown box to change the sound to NONE>click apply>click OK...This should turn off the balloon.wav pop

If this doesn't work, then consider a malware problem......there are instances where this file corrupts.Thanks Karnac, I'll give that a go, test it out for a day and see if that makes any difference.

I would think that the drive is clean really...
I haven't used it for some time and since it was new, as in brand new in the packet and sat idle for the most part, I cant really see how it would have become contaminated. (but there's always a way I suppose)

I should put AVG or some virus protection on it before doing anything else.
Many thanks Karnac ImnoGuru. Ah I see the drop down box now....
I didnt realise there was another box in there to use.
I've set it to none now. so I'll test it for a day and let you know.
Thanks again. ImnoGuru.

2917.

Solve : malwarebytes "Disabled.Security" message HELP!!?

Answer» HELLO, recently, a message is on my malwarebytes scan is stating that my antivirus and firewall was
disabled...........WHEN I DIDN'T!!
I'm afraid to quarantine and delete the file/date because it says that the data is registry data.If I delete it, my security might not work at all!
ALSO, there's an infection that says something about my INTERNET access.
PLEASE HELP!!!!!!
Below is the log of my recent scan. You will see some other infections, but I think I deleted the trojan fake alert one.
Malwarebytes' Anti-Malware 1.37
Database version: 2211
Windows 5.1.2600 Service Pack 3

6/2/2009 4:47:23 PM
mbam-log-2009-06-02 (16-47-23).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 295265
Time elapsed: 2 hour(s), 59 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -&GT; Bad: (1) Good: (0) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\program files\online services\PeoplePC\ISP5900\utilities\AtlBrowser.exe (Dialer) -> Not selected for removal.
C:\WINDOWS\Sysvxd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Can you zip up a copy of this file and ADD it to your next reply please.

c:\program files\online services\PeoplePC\ISP5900\utilities\AtlBrowser.exe

----------

You need to let MBAM fix everything else. I will do some investigating on the People PC file once I have it. Is that your ISP?

Also are you on Dial-up?
2918.

Solve : Panda Security: Basic Virus Course?

Answer»

This is a two-hour BASIC course, through which you will acquire a basic KNOWLEDGE on viruses and on how to be PROTECTED against them.

You can read it at your own pace. You can stop and start again where you left off, repeat it COMPLETELY, or just those chapters you LIKED the most. If you think this course is useful, recommend it to your friends.

Panda Security: Basic Virus Course

Note: You'll need to register to take the course...This will work good well for school

Thanks, i'll check it out.thx

2919.

Solve : Internet explorer redirected?

Answer»

Sorry forgot the report.

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3500+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : User ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus 8.5 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:87 Go (Free:25 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (Local Disk) - NTFS - Total:98 Go (Free:85 Go)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 01/06/2009|21:02 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing folders in APPLIC~1

[06/04/2007|17:25] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[09/04/2009|17:42] C:\DOCUME~1\ADMINI~1.BAS\APPLIC~1\Microsoft
[04/11/2008|21:12] C:\DOCUME~1\ADMINI~1.BAS\APPLIC~1\Spearit
[04/10/2008|13:18] C:\DOCUME~1\ADMINI~1.BAS\APPLIC~1\WinCare2008


[12/05/2007|16:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\4p-r9-67-55-p3-26
[18/08/2007|09:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\55-66-54-16-s6-0o
[12/05/2007|20:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\96-05-46-2p-3p-r9
[16/05/2007|19:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ACD Systems
[14/05/2009|18:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[06/04/2007|10:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
[21/04/2008|20:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[11/05/2007|17:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[28/03/2009|22:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avanquest
[30/05/2009|14:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg8
[22/06/2008|17:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[28/03/2009|22:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BVRP Software
[22/04/2007|07:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[21/10/2008|06:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Documents
[29/02/2008|20:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[11/11/2008|17:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD X Studios
[15/01/2008|19:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
[31/10/2008|21:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[02/09/2008|17:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard
[31/10/2008|10:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[31/10/2008|10:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP Product Assistant
[31/10/2008|09:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[10/05/2007|21:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[01/06/2009|21:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kontiki
[30/05/2009|16:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[27/07/2007|05:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft(2)
[30/05/2009|21:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[09/01/2009|22:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memory-Map-License
[04/11/2008|18:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[21/04/2008|20:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[07/03/2009|17:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NortonInstaller
[14/05/2009|18:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[05/04/2007|20:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[12/04/2007|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Quest
[12/06/2008|19:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\RoboForm
[10/12/2007|19:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Softdisk LLC
[04/11/2008|21:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spearit
[03/04/2009|19:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[14/02/2009|10:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[08/04/2008|19:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TreeCardGames
[22/06/2008|10:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[22/06/2008|19:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\vsosdk
[02/09/2008|19:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WEBREG
[14/04/2007|07:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[17/12/2008|19:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
[19/09/2008|18:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[11/11/2008|22:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\XOOM

[16/05/2009|18:51] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[22/04/2008|19:03] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[04/11/2008|21:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Spearit

[07/06/2008|21:02] C:\DOCUME~1\LOCALS~1\APPLIC~1\Acronis
[02/04/2008|05:53] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[30/05/2009|05:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\Macromedia
[09/04/2009|17:42] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[09/04/2009|17:42] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[11/05/2007|17:34] C:\DOCUME~1\User\APPLIC~1\ACD Systems
[14/05/2009|18:38] C:\DOCUME~1\User\APPLIC~1\Adobe
[16/08/2007|17:34] C:\DOCUME~1\User\APPLIC~1\AdobeUM
[07/04/2007|08:48] C:\DOCUME~1\User\APPLIC~1\Ahead
[18/11/2007|15:38] C:\DOCUME~1\User\APPLIC~1\Alien Skin
[15/08/2007|16:45] C:\DOCUME~1\User\APPLIC~1\Andrex Puppy
[25/05/2007|07:03] C:\DOCUME~1\User\APPLIC~1\Apple Computer
[28/03/2009|22:02] C:\DOCUME~1\User\APPLIC~1\Avanquest
[22/06/2008|17:16] C:\DOCUME~1\User\APPLIC~1\AVS4YOU
[22/06/2008|18:07] C:\DOCUME~1\User\APPLIC~1\AVSMedia
[22/04/2007|07:56] C:\DOCUME~1\User\APPLIC~1\CyberLink
[19/08/2007|08:47] C:\DOCUME~1\User\APPLIC~1\DMCache
[13/05/2007|17:50] C:\DOCUME~1\User\APPLIC~1\EPSON
[29/03/2009|08:15] C:\DOCUME~1\User\APPLIC~1\EurekaLog
[21/04/2007|09:05] C:\DOCUME~1\User\APPLIC~1\fltk.org
[29/11/2007|18:19] C:\DOCUME~1\User\APPLIC~1\FontHit
[29/03/2008|16:22] C:\DOCUME~1\User\APPLIC~1\GetRightToGo
[05/04/2007|19:48] C:\DOCUME~1\User\APPLIC~1\Google
[07/04/2007|18:33] C:\DOCUME~1\User\APPLIC~1\Help
[06/03/2009|21:11] C:\DOCUME~1\User\APPLIC~1\HideIP
[08/09/2008|17:23] C:\DOCUME~1\User\APPLIC~1\HP
[02/09/2008|17:34] C:\DOCUME~1\User\APPLIC~1\HPAppData
[02/04/2007|11:59] C:\DOCUME~1\User\APPLIC~1\Identities
[07/04/2007|18:16] C:\DOCUME~1\User\APPLIC~1\ieSpell
[31/08/2007|18:06] C:\DOCUME~1\User\APPLIC~1\InterTrust
[06/04/2007|11:04] C:\DOCUME~1\User\APPLIC~1\IsolatedStorage
[25/07/2007|18:26] C:\DOCUME~1\User\APPLIC~1\Lavasoft
[06/01/2008|20:31] C:\DOCUME~1\User\APPLIC~1\LimeWire
[12/08/2007|07:40] C:\DOCUME~1\User\APPLIC~1\LogicWeave Software
[14/04/2007|18:43] C:\DOCUME~1\User\APPLIC~1\Macromedia
[08/04/2008|19:40] C:\DOCUME~1\User\APPLIC~1\MahJong Suite
[30/05/2009|21:10] C:\DOCUME~1\User\APPLIC~1\Malwarebytes
[02/05/2009|21:38] C:\DOCUME~1\User\APPLIC~1\Microsoft
[31/07/2007|21:08] C:\DOCUME~1\User\APPLIC~1\Mozilla
[14/12/2007|23:26] C:\DOCUME~1\User\APPLIC~1\Nero
[21/04/2007|21:32] C:\DOCUME~1\User\APPLIC~1\Opera
[26/12/2007|13:14] C:\DOCUME~1\User\APPLIC~1\SecuROM
[13/02/2009|19:08] C:\DOCUME~1\User\APPLIC~1\Simply Super Software
[04/11/2008|21:12] C:\DOCUME~1\User\APPLIC~1\Spearit
[02/08/2007|17:21] C:\DOCUME~1\User\APPLIC~1\Sun
[10/05/2008|16:39] C:\DOCUME~1\User\APPLIC~1\SUPERAntiSpyware.com
[03/04/2009|19:04] C:\DOCUME~1\User\APPLIC~1\Symantec
[17/01/2009|17:53] C:\DOCUME~1\User\APPLIC~1\U3
[25/06/2008|20:58] C:\DOCUME~1\User\APPLIC~1\Vso
[27/07/2008|10:46] C:\DOCUME~1\User\APPLIC~1\WinCare2008
[05/04/2007|19:28] C:\DOCUME~1\User\APPLIC~1\WinRAR

--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[01/06/2009 11:01][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[01/06/2009 11:01][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/02/2006 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Program Files

[01/02/2009|11:21] C:\Program Files\1 Click PC Fix
[30/05/2009|07:31] C:\Program Files\A1Click Ultra PC Cleaner
[14/05/2009|18:39] C:\Program Files\Adobe
[01/06/2009|18:22] C:\Program Files\Advanced Diary
[25/02/2009|18:53] C:\Program Files\AgataSoft
[21/04/2008|21:00] C:\Program Files\Ahead
[18/11/2007|15:25] C:\Program Files\Alien Skin
[15/08/2007|16:44] C:\Program Files\Andrex Puppy
[14/11/2007|22:28] C:\Program Files\Astro Gemini Software
[02/02/2009|07:44] C:\Program Files\Atomic Clock Sync
[18/02/2009|18:11] C:\Program Files\audiograbber
[28/03/2009|21:56] C:\Program Files\Avanquest
[31/08/2007|17:07] C:\Program Files\AvantGo Connect
[23/11/2008|08:01] C:\Program Files\AVG
[22/06/2008|18:40] C:\Program Files\AVSMedia
[24/04/2007|07:36] C:\Program Files\Backup
[27/07/2007|05:53] C:\Program Files\BearSharePro
[01/05/2007|20:40] C:\Program Files\Bodrag
[10/11/2007|23:21] C:\Program Files\Bonjour
[30/05/2009|17:17] C:\Program Files\CCleaner
[31/01/2009|08:36] C:\Program Files\Christmas Time 3D Screensaver
[24/04/2007|07:49] C:\Program Files\cm2gpx
[24/04/2007|07:49] C:\Program Files\CmConvert
[14/05/2009|18:38] C:\Program Files\Common Files
[02/04/2007|11:49] C:\Program Files\ComPlus Applications
[24/04/2007|07:54] C:\Program Files\data
[08/12/2008|19:13] C:\Program Files\Driver Checker
[01/02/2009|21:33] C:\Program Files\Driver-Soft
[04/08/2007|19:08] C:\Program Files\DVD Shrink
[11/11/2008|17:54] C:\Program Files\DVD X Studios
[04/04/2009|20:33] C:\Program Files\EASEUS
[30/05/2009|17:14] C:\Program Files\Enigma Software Group
[11/11/2007|22:05] C:\Program Files\Fantasy Moon 3D Screensaver
[22/05/2009|21:20] C:\Program Files\File Renamer
[29/11/2007|18:19] C:\Program Files\FontHit Software
[12/05/2007|16:21] C:\Program Files\GameHouse
[31/05/2009|15:19] C:\Program Files\GASK
[19/04/2008|07:02] C:\Program Files\GetRight
[31/05/2009|19:39] C:\Program Files\Google
[17/08/2007|17:59] C:\Program Files\Grisoft
[26/12/2007|13:14] C:\Program Files\Hasbro
[31/10/2008|10:04] C:\Program Files\Hewlett-Packard
[31/10/2008|09:35] C:\Program Files\HP
[06/04/2007|18:11] C:\Program Files\ieSpell
[09/01/2008|18:07] C:\Program Files\images
[28/03/2009|21:57] C:\Program Files\InstallShield Installation Information
[15/04/2009|22:06] C:\Program Files\Internet Explorer
[19/10/2007|18:29] C:\Program Files\iPAQ Download Agent
[19/10/2007|18:36] C:\Program Files\iTRIS
[31/05/2009|06:50] C:\Program Files\Java
[19/10/2007|18:38] C:\Program Files\JewelMine
[18/04/2009|07:19] C:\Program Files\Jigsaw Puzzle Platinum Edition
[19/10/2007|18:50] C:\Program Files\Kakuro
[14/10/2008|20:54] C:\Program Files\Kontiki
[27/11/2008|21:10] C:\Program Files\Lavalys
[05/05/2008|21:32] C:\Program Files\LogicWeave
[16/04/2009|20:03] C:\Program Files\LSoft Technologies
[07/03/2008|18:31] C:\Program Files\Mahjong Fortuna 2 Deluxe
[08/04/2008|19:39] C:\Program Files\MahJong Suite
[30/05/2009|21:10] C:\Program Files\Malwarebytes' Anti-Malware
[29/05/2008|17:00] C:\Program Files\Memory-Map
[12/01/2008|17:46] C:\Program Files\Messenger
[30/05/2009|17:13] C:\Program Files\Microsoft ActiveSync
[28/03/2009|07:45] C:\Program Files\Microsoft AutoRoute
[19/09/2008|21:59] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[06/04/2007|07:35] C:\Program Files\microsoft frontpage
[22/05/2007|17:16] C:\Program Files\Microsoft IntelliPoint
[22/05/2007|17:15] C:\Program Files\Microsoft IntelliPoint 5.5
[02/02/2009|07:15] C:\Program Files\Microsoft IntelliType Pro
[01/11/2008|21:10] C:\Program Files\Microsoft IntelliType Pro 5.2
[26/04/2009|17:41] C:\Program Files\Microsoft Office
[26/10/2008|11:54] C:\Program Files\Microsoft Works
[26/04/2009|17:41] C:\Program Files\Microsoft.NET
[15/10/2007|17:29] C:\Program Files\MobiMate
[23/04/2009|18:04] C:\Program Files\Moffsoft Calculator 2
[26/04/2007|18:07] C:\Program Files\Motorola
[02/04/2007|11:49] C:\Program Files\Movie Maker
[07/12/2007|18:31] C:\Program Files\MSI
[02/04/2007|11:48] C:\Program Files\MSN
[02/04/2007|11:48] C:\Program Files\MSN Gaming Zone
[27/04/2007|06:58] C:\Program Files\MSXML 4.0
[02/02/2009|07:14] C:\Program Files\MSXML 6.0
[14/12/2007|23:24] C:\Program Files\Nero
[02/04/2007|11:49] C:\Program Files\NetMeeting
[14/05/2009|18:29] C:\Program Files\NOS
[02/04/2007|14:39] C:\Program Files\NVIDIA Corporation
[30/04/2009|21:14] C:\Program Files\Outlook Express
[19/10/2007|18:52] C:\Program Files\PAQmanP
[14/06/2007|19:03] C:\Program Files\Paragon Software
[18/01/2009|08:34] C:\Program Files\PCNetSoftware
[09/11/2007|18:20] C:\Program Files\Picasa2
[08/12/2007|09:15] C:\Program Files\Plus!
[27/10/2007|18:02] C:\Program Files\PopCap Games
[09/01/2008|18:07] C:\Program Files\QSort2000
[27/07/2007|05:54] C:\Program Files\QSort2000(2)
[12/04/2007|20:12] C:\Program Files\Quest
[11/05/2007|17:31] C:\Program Files\QuickTime
[17/01/2009|23:00] C:\Program Files\RCLogon
[01/02/2009|22:35] C:\Program Files\Realtek AC97
[10/05/2007|22:19] C:\Program Files\ReflexiveArcade
[21/01/2009|22:41] C:\Program Files\RegistryFix
[01/06/2009|18:49] C:\Program Files\RegVac Registry Cleaner
[26/05/2009|19:00] C:\Program Files\ReNamer
[05/04/2007|18:34] C:\Program Files\SAGEM
[10/12/2007|21:20] C:\Program Files\Santas Workshop
[07/04/2007|20:53] C:\Program Files\ScanSoft
[08/12/2007|09:18] C:\Program Files\Setup Files
[05/04/2007|19:35] C:\Program Files\Siber Systems
[09/12/2008|21:50] C:\Program Files\SIW -Technicians v1.71 (Build 636) +Businness License
[01/02/2009|11:21] C:\Program Files\Spotmau WinCare 2008
[30/05/2009|17:14] C:\Program Files\SpywareBlaster
[19/10/2007|18:54] C:\Program Files\SuDokuV2
[31/05/2009|22:01] C:\Program Files\SUPERAntiSpyware
[06/01/2008|20:32] C:\Program Files\temp
[18/04/2008|19:15] C:\Program Files\Tetris 5000
[05/04/2007|18:26] C:\Program Files\Tiscali Broadband
[02/05/2009|18:41] C:\Program Files\Top Password
[31/05/2009|08:28] C:\Program Files\Trend Micro
[14/02/2009|15:41] C:\Program Files\Trojan Remover
[02/04/2007|11:59] C:\Program Files\Uninstall Information
[07/04/2007|18:32] C:\Program Files\UserImages
[11/07/2008|20:10] C:\Program Files\VideoLAN
[22/06/2008|19:01] C:\Program Files\VSO
[19/09/2008|18:41] C:\Program Files\Windows Live
[09/01/2008|18:07] C:\Program Files\Windows Media Connect 2
[22/02/2008|23:17] C:\Program Files\Windows Media Player
[02/04/2007|11:48] C:\Program Files\Windows NT
[02/04/2007|11:50] C:\Program Files\WindowsUpdate
[24/11/2008|19:23] C:\Program Files\WinRar
[17/12/2008|19:16] C:\Program Files\WinZip
[30/05/2009|15:20] C:\Program Files\ww
[02/04/2007|11:51] C:\Program Files\xerox
[11/11/2008|22:01] C:\Program Files\XOOM

--------------------\\ Listing Folders in C:\Program Files\Common Files

[16/11/2008|09:45] C:\Program Files\Common Files\Adobe
[14/05/2009|18:38] C:\Program Files\Common Files\Adobe AIR
[31/12/2007|09:11] C:\Program Files\Common Files\Adobe Systems Shared
[21/04/2008|20:50] C:\Program Files\Common Files\Ahead
[28/03/2009|22:40] C:\Program Files\Common Files\AntiVirus
[22/06/2008|18:40] C:\Program Files\Common Files\AVSMedia
[26/04/2009|17:42] C:\Program Files\Common Files\DESIGNER
[05/04/2007|20:05] C:\Program Files\Common Files\EPSON
[02/09/2008|17:31] C:\Program Files\Common Files\Hewlett-Packard
[02/09/2008|17:31] C:\Program Files\Common Files\HP
[13/05/2007|17:05] C:\Program Files\Common Files\InstallShield
[02/08/2007|17:24] C:\Program Files\Common Files\Java
[10/11/2007|23:16] C:\Program Files\Common Files\Macrovision Shared
[27/04/2009|07:00] C:\Program Files\Common Files\Microsoft Shared
[26/04/2007|18:07] C:\Program Files\Common Files\Motorola Shared
[02/04/2007|11:49] C:\Program Files\Common Files\MSSoap
[04/05/2008|15:35] C:\Program Files\Common Files\Nero
[02/04/2007|14:39] C:\Program Files\Common Files\NVIDIA Shared
[02/04/2007|12:17] C:\Program Files\Common Files\ODBC
[12/04/2007|20:12] C:\Program Files\Common Files\Quest
[02/04/2007|11:49] C:\Program Files\Common Files\Services
[02/04/2007|12:17] C:\Program Files\Common Files\SpeechEngines
[03/04/2009|19:46] C:\Program Files\Common Files\Symantec Shared
[26/04/2009|17:41] C:\Program Files\Common Files\System
[19/09/2008|18:41] C:\Program Files\Common Files\WindowsLiveInstaller
[31/05/2009|22:01] C:\Program Files\Common Files\Wise Installation Wizard

--------------------\\ Process

( 50 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-01 21:03:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
disk error: C:\WINDOWS\System32\
please note that you need administrator rights to perform deep scan

--------------------\\ Searching for other infections


No other infections found !

[F:26][D:1]-> C:\DOCUME~1\User\LOCALS~1\Temp
[F:2][D:0]-> C:\DOCUME~1\User\Cookies
[F:7][D:6]-> C:\DOCUME~1\User\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 01/06/2009|19:53 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 01/06/2009|20:45 - Option : [1]
3 - "C:\Lop SD\LopR_3.txt" - 01/06/2009|21:00 - Option : [1]
4 - "C:\Lop SD\LopR_4.txt" - 01/06/2009|21:03 - Option : [2]

--------------------\\ Scan completed at 21:03:56
Did you run Option 2 with Lop S&D?

Right click on ComboFix and choose Rename. Rename it to Combo-Fix and then try running it again.I manualy deleated the files be for using option2 the last time.
Renaming has no effect on combofix or HIJACK this.
Kevin.Try this.

Use the ESET Online Antivirus Scanner

This scanner requires Internet Explorer

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.I think you may have done it.
[emailprotected] as CAB hook log:
OnlineScanner.ocx - registred OK
# version=6
# IEXPLORE.EXE=7.00.6000.16827 (vista_gdr.090226-1506)
# OnlineScanner.ocx=1.0.0.5863
# api_version=3.0.2
# EOSSerial=783d5aced2f9e143b9fd733630d2c369
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2009-06-01 09:14:37
# local_time=2009-06-01 10:14:37 (+0000, GMT Standard Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=1027 21 83 59 2955140781250
# scanned=84235
# found=2
# cleaned=2
# scan_time=1842
C:\Program Files\AgataSoft\AgataSoft ShutDown Pro\AgataSoft_ShutDown_Pro.exeprobably unknown NewHeur_PE virus (deleted - quarantined)00000000000000000000000000000000
H:\RECYCLER\S-4-6-13-100016428-100020748-100010818-9216.coma variant of Win32/Kryptik.QY trojan (cleaned by deleting - quarantined)00000000000000000000000000000000
Combo fix now works see log.
ComboFix 09-05-31.06 - User 01/06/2009 22:23.23 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.1023.647 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\User\Application Data\EurekaLog
c:\documents and settings\User\Application Data\EurekaLog\EurekaLog.ini
c:\windows\system32\drivers\gxvxcrvamexmyxvnpskbfxmhfulnkffxmkiex.sys
c:\windows\system32\gxvxcrqrdyyudpmxxtobaawmwkqbuwgwviaii.dll
c:\windows\system32\gxvxcufytiteomnrxoppxqpjcfpwnswqwkpvm.dll
H:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_GXVXCSERV.SYS


((((((((((((((((((((((((( Files Created from 2009-05-01 to 2009-06-01 )))))))))))))))))))))))))))))))
.

2009-06-01 20:41 . 2009-06-01 20:41--------d-----w-c:\program files\ESET
2009-06-01 18:51 . 2009-06-01 20:03--------d-----w-C:\Lop SD
2009-05-31 19:34 . 2009-05-31 19:34--------d-----w-C:\_OTMoveIt
2009-05-31 05:50 . 2009-05-31 05:50--------d-----w-c:\program files\Java
2009-05-30 20:51 . 2009-05-31 07:28--------d-----w-c:\program files\Trend Micro
2009-05-30 20:10 . 2009-05-30 20:10--------d-----w-c:\documents and settings\User\Application Data\Malwarebytes
2009-05-30 20:07 . 2009-05-26 12:2040160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-30 20:07 . 2009-05-30 20:10--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2009-05-30 20:07 . 2009-05-30 20:07--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-30 20:07 . 2009-05-26 12:1919096----a-w-c:\windows\system32\drivers\mbam.sys
2009-05-30 16:26 . 2009-05-31 05:50410984----a-w-c:\windows\system32\deploytk.dll
2009-05-30 16:26 . 2009-05-30 16:26152576----a-w-c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-30 15:41 . 2009-05-30 15:41698---ha-w-C:\aaw7boot.cmd
2009-05-30 14:20 . 2009-05-30 14:20--------d-----w-c:\program files\ww
2009-05-30 04:51 . 2009-05-30 04:51--------d-----w-c:\windows\system32\config\systemprofile\Application Data\HPAppData
2009-05-14 17:38 . 2009-05-14 17:38--------d-----w-c:\program files\Common Files\Adobe AIR
2009-05-14 17:29 . 2009-05-14 17:29--------d-----w-c:\documents and settings\All Users\Application Data\NOS
2009-05-14 17:29 . 2009-05-14 17:29--------d-----w-c:\program files\NOS
2009-05-13 10:04 . 2009-05-13 10:042051864----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-05-13 10:04 . 2009-05-13 10:043288856----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-05-13 10:04 . 2009-05-13 10:04423424----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwdwsc.dll
2009-05-13 10:04 . 2009-05-13 10:041262880----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-05-13 10:04 . 2009-05-13 10:04177432----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgmail.dll
2009-05-13 10:03 . 2009-05-13 10:03755992----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avginet.dll
2009-05-13 10:03 . 2009-05-13 10:031085208----a-w-c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 21:23 . 2008-10-14 19:12--------d-----w-c:\documents and settings\All Users\Application Data\Kontiki
2009-06-01 19:02 . 2007-04-02 15:1733488----a-w-c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-01 17:49 . 2007-11-28 06:32--------d-----w-c:\program files\RegVac Registry Cleaner
2009-06-01 17:22 . 2008-09-07 15:39--------d-----w-c:\program files\Advanced Diary
2009-05-31 21:01 . 2007-11-30 22:50--------d-----w-c:\program files\SUPERAntiSpyware
2009-05-31 21:01 . 2007-10-12 21:30--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-05-31 18:39 . 2007-04-05 18:46--------d-----w-c:\program files\Google
2009-05-31 14:19 . 2008-01-10 20:41--------d-----w-c:\program files\GASK
2009-05-30 19:01 . 2007-04-26 19:0229----a-w-c:\windows\popcinfo.dat
2009-05-30 16:17 . 2008-04-19 05:55--------d-----w-c:\program files\CCleaner
2009-05-30 16:14 . 2007-09-17 17:52--------d-----w-c:\program files\SpywareBlaster
2009-05-30 16:14 . 2007-05-08 15:50--------d-----w-c:\program files\Enigma Software Group
2009-05-30 16:13 . 2007-04-20 18:40--------d-----w-c:\program files\Microsoft ActiveSync
2009-05-30 15:49 . 2008-04-23 16:31--------d-----w-c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-30 13:29 . 2009-04-08 18:49--------d-----w-c:\documents and settings\All Users\Application Data\avg8
2009-05-30 06:37 . 2008-02-29 20:3510697----a-w-c:\documents and settings\All Users\Application Data\DVD X Studios\DVD X Player 4.1 Professional\DVDXPlayer.dll
2009-05-30 06:31 . 2008-01-06 19:23--------d-----w-c:\program files\A1Click Ultra PC Cleaner
2009-05-26 18:00 . 2009-02-19 19:50--------d-----w-c:\program files\ReNamer
2009-05-26 17:57 . 2007-12-08 13:42249856------w-c:\windows\Setup1.exe
2009-05-26 17:57 . 2007-12-08 13:4273216----a-w-c:\windows\ST6UNST.EXE
2009-05-22 20:20 . 2008-10-01 18:58--------d-----w-c:\program files\File Renamer
2009-05-02 17:41 . 2009-05-02 17:40--------d-----w-c:\program files\Top Password
2009-04-30 10:19 . 2009-04-08 18:5011952----a-w-c:\windows\system32\avgrsstx.dll
2009-04-30 10:19 . 2009-04-08 18:50325896----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-04-30 10:19 . 2009-04-08 18:5027784----a-w-c:\windows\system32\drivers\avgmfx86.sys
2009-04-30 10:19 . 2009-04-08 18:50108552----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-04-26 16:41 . 2008-05-30 16:45--------d-----w-c:\program files\Microsoft.NET
2009-04-23 17:04 . 2009-04-23 17:04--------d-----w-c:\program files\Moffsoft Calculator 2
2009-04-18 06:19 . 2007-12-27 11:15--------d-----w-c:\program files\Jigsaw Puzzle Platinum Edition
2009-04-16 19:03 . 2009-04-16 19:03--------d-----w-c:\program files\LSoft Technologies
2009-04-04 19:33 . 2009-04-04 19:33--------d-----w-c:\program files\EASEUS
2009-04-03 18:47 . 2009-04-03 17:50--------d-----w-c:\documents and settings\All Users\Application Data\Symantec
2009-04-03 18:46 . 2007-04-05 17:15--------d-----w-c:\program files\Common Files\Symantec Shared
2009-04-03 18:04 . 2009-04-03 18:04--------d-----w-c:\documents and settings\User\Application Data\Symantec
2009-03-19 13:03 . 2009-04-04 19:331907712----a-w-c:\windows\system32\BootMan.exe
2009-03-13 15:03 . 2008-11-11 21:029110----a-w-c:\documents and settings\All Users\Application Data\XOOM\X-OOM DVD Player 4 Deluxe\BlazeDVD.dll
2009-03-06 14:44 . 2006-02-28 12:00283648----a-w-c:\windows\system32\pdh.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\FolderProtect0]
@="{D7BC78F3-3624-455C-8C4B-9C77C3BFEE4E}"
[HKEY_CLASSES_ROOT\CLSID\{D7BC78F3-3624-455C-8C4B-9C77C3BFEE4E}]
2007-12-02 16:05348160----a-w-c:\program files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtectShellExtension.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\FolderProtect1]
@="{8A814C29-D3CD-4F9E-9770-DF8704503ACA}"
[HKEY_CLASSES_ROOT\CLSID\{8A814C29-D3CD-4F9E-9770-DF8704503ACA}]
2007-12-02 16:05348160----a-w-c:\program files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtectShellExtension.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\progra~1\MICROS~2\wcescomm.exe" [2006-06-26 1207080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2008-06-10 1442888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-05-11 155648]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-30 1947928]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-31 148888]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2007-04-16 577536]
"AgataSoft ShutDown Pro"="" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-24 160592]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-30 10:1911952----a-w-c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\SECURITY center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [08/04/2009 19:50 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [08/04/2009 19:50 108552]
R1 FolderProtectDriver;FolderProtectDriver;c:\program files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtectDriver.sys [27/07/2008 10:46 15616]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [09/04/2009 17:39 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [08/04/2009 19:49 298776]
R2 FolderProtectService;FolderProtectService;c:\program files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtectService.exe [27/07/2008 10:46 10240]
S1 SASKUTIL;SASKUTIL;


S2 gupdate1c9a98e341b062a;Google Update Service (gupdate1c9a98e341b062a);c:\program files\Google\Update\GoogleUpdate.exe [20/03/2009 20:00 133104]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [04/04/2009 20:33 3072]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [14/05/2009 18:29 33176]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [26/04/2007 18:07 40832]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-06-01 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-20 19:00]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys
SafeBoot-aawservice


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.tiscali.co.uk/
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = socks=
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-01 22:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2052111302-1454471165-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3F434468-0101-F776-A200-8A65B4C5E746}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"kaiedlmggadfepemjnkjjh"=hex:67,61,67,65,6e,6f,6c,69,6b,6a,64,6f,6c,61,00,00
"kaiedlmggadfepemjnkjeh"=hex:66,61,67,6e,65,66,70,67,66,69,6a,62,00,69

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="1D5ECA62741A2F4B50337E24301E42D5872E3F9 7E3EB811AE9F7B749ACCC95F54848B0083E5D09 B77A5C3A5105A27B794532EE1BD5F0EB4BD69AB E6733250B32D21B4E2921B127F16B9DE67702EE 1BAD8AEE76908ECADECE10111634D5BD934818D DB1C05193B21E59F2B3AD85853CC00A7542CBB4 210640E0A08C5D24008C431DA9ACF8E9D4D8D19 EEA13BB533CFBF815E988D2D6ED10B1B4A2B848 15ADD49E06ADD233E9984C19BC2A39A1143CFD0 DA5053E5EE4FE32279C84708C80D8514E1C2BFE 05B2D8C2725467A20E5284E7A956929EDEB2782 4FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E 127BECC74CFEBC9E127BECC74CFEBC9E127BECC 74CFEBC9E127BECC74CA6A0AC4980AC79335D57 5E7D6A3B9808A2D97226D213B5558EDD5E5BE2F 6E6673071632AFE4DDEDA355E9290F7451F39E7 450CFC03A9F9BF16F64F24E21120F2D9204F310 BC33E3ABA7875BE2B2FA5E11B7CEEEAFEE74036 72B4CC6FF439DCA7DC12F959A24DC600F05AF43 C08DB2D2C7421E388246CDF9253CFF5EADDAC4E 74EF4391B3AF4CEC6ABAF754DAB376D2E725BF6 78D774F3754550E9A4B9C8A3A2B3F545A17CD88 7BBBF1E9ECB2898F83E8D18A03EF2F88FB008CD 9998AE555B8A16806AA1E51AE8FBB616C2A9F19 1D820515D45A6B37F5349D7DC06CE42272B5B27 F406E27BECC9B33495D8BC0A2F5E5987A992281 2FD93CBAA1F51C5CEEAD733A0C0DA3534E55E37 2DDC128F79ED51A0483732376EA57C4E8E7CCC5 361C34859A871D600AEE22054CC6C2256D365F5 C2BA425BBD0F0F8503B33C09D7A2E98543A6142 C8F4C1ECE916212AC00C491640F448135C5DFE2 CB6CAD770E8765ED21F81FDF11A011DD5D52AFA E9CA0369E1AC4D4BC50A2E01C3A535A01D823D1 83BF3DD32C9236189DFDDE95A9327C4DC0F5C23 FCE85F949D721A19CB2B58217D913942CB07478 C4471EBB4B5614E0A9FCE5D6B24CF882B2CD3E9 1D8BA66C3E60F62724070DFDBC3F593FF37A2E4 D4D5EB4939CF86E464C3663BBE805BCD46ECBF3 4A7C986251EE2143670F0879C2CC7D39B433A95 D6F98FC058BA952BDBCD5FAEF8449A63262E6C1 444B78B1E6E40D91B9CB2F54DA6C74F3FA2A8F8 2A262585F3C090CCD4BE22930D3A4A0414079D3 E675389212C53A8841F1B94F1703979E1D89E0C A1AA19901AB4C80FDF0EFDFADFA12ABE668A3EA BFC17533A1869D42960CEE6A8F914A64FC2D6F4 20D710606E70096AE36569DA2CB0477E1433A54 DC713AE5D4E6AA01316DDA5D1E49E6B6F1185EE F1A914C029B1F4D4DE5748F2E7724664E26E14F A58269149F9E3869DA3A14AEEF1E8BAEBE24F29 3AF327A5952B0E786693519DE3970CCE92221DF 05EB8BF6BF48BC3CD76B1BC302BC8F1EDE10423 9C1DE30A22C6426B2A133584B390B271F15144C 40143F77D0F8F51AABD7"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(676)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-06-01 22:36
ComboFix-quarantined-files.txt 2009-06-01 21:36
ComboFix2.txt 2009-02-10 06:45
ComboFix3.txt 2009-02-04 06:41
ComboFix4.txt 2009-01-31 06:27
ComboFix5.txt 2009-06-01 21:18

Pre-Run: 27,784,314,880 bytes free
Post-Run: 27,791,364,096 bytes free

214--- E O F ---2009-05-13 06:03
ThanAll seems fine now.
Many Thanks Kevin.Finally!

Still a few things to do.

Go to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

Make sure that you tell me if you receive a success message about ADDING the above to the registry. If you do not get a success message, it did not work.

Delete the fixme.reg from the Desktop.

----------

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete: ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hi
Reg entry was OK.
Secunia Software Inspector said that java was not on this computer.
Went to java site and confirmed java is up to date but not working, checked out the settings suggested and everthing i is as it should be.
Thanks Kevin.I should like thank evilfantasy for his help with this topic.
With out his help I do not know what i would have done, Thanks for your time and understanding
you are a star.
Many thanks Kevin.Your welcome.

Safe surfing...
2920.

Solve : virus makes my micro sd folder invisible and damaged volume D?

Answer»

HELLO AGAIN !!

Sorry but the link of Dr.Web CureIt! that u have given to me is BROKEN i have downloaded it on download.com but the KEY liscence is expired .
COULD u give me a valide link please

PS: now i lost windows media PLAYER on my PC this virus KEEP destroye my PC

2921.

Solve : Virus preventing me downloading?

Answer»

Ran this this morning.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:40:15, on 01/07/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot MODE: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Common Files\aol\1206988110\ee\aolsoftware.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Sony\Network Utility\LANUtil.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\EPC\Toolbar\EPSIBar.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Windows\System32\GRVSA.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\AOL 9.0 VR\waol.exe
C:\Program Files\AOL 9.0 VR\shellmon.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.easyspace.com/webmail_login.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader LINK Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1206988110\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041508 serial=DR12CEl-3361936-xty lang=EN
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: EPSI ToolBar.lnk = C:\EPC\Toolbar\EPSIBar.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: RESEARCH - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11972 bytes
It's still there.

Go back to my post #41, and run those commands one more TIME...
I'm not sure, if I understand your post #42:
Quote

SC open service FAILED 5
Access denied

message?
I tried it again from the
c:\users\derek prompt. I then got

The specified service does not exist as an installed service

I then ran the delete my,,,,,,,etc
and got the same - the specified service does not exist as an installed service

Go Start>Run, type in:
services.msc
Click OK.

Services window will open. Check the list, and see, if there is MyWebSearchService, or something similar present. If something similar, post back its exact name.One or two come up all listed as inside the

Microsoft common console document

the folders are
1. x_86 microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en.us_e208...

2. x_86,,,same except after,,,,,, 6000.16386_none_cd2d20a848c...

The other two look "normal" and are
system32 (c:\windows)
en.us (C:\windows\system32)
I'm not sure, if I understand your answer.
What are the names of services, you found in "services.msc" window?I don't know what that list must have been? I ran it again now and did find a listing

My Web Search Service. I opened the properties and attempted to disable it as I cannot seem to delete it?Quote
I opened the properties and attempted to disable it
...and? Did it let you?
If so, post new HJT log.It did appear to let me disable it, but not delete it i searched in the cmd box but it cannot be found.
Here is the HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:00:06, on 05/07/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Apoint\Apoint.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Common Files\aol\1206988110\ee\aolsoftware.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Sony\Network Utility\LANUtil.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\EPC\Toolbar\EPSIBar.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Windows\System32\GRVSA.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\AOL 9.0 VR\waol.exe
C:\Program Files\AOL 9.0 VR\shellmon.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.easyspace.com/webmail_login.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1206988110\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041508 serial=DR12CEl-3361936-xty lang=EN
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: EPSI ToolBar.lnk = C:\EPC\Toolbar\EPSIBar.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11847 bytesWell done

Your computer is clean

1. Download, and INSTALL CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
Run CCleaner.

2. Turn off System Restore:

- Windows XP:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore".
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
- Windows Vista:
1. Click Start.
2. Right-click the Computer icon, and then click Properties.
3. Click on System Protection under the Tasks column on the left side
4. Click on Continue on the "User Account Control" window that pops up
5. Under the System Protection tab, find Available Disks
6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
8. Click OK

3. Restart computer.

4. Turn System Restore on.

5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

7. Let me know, how your computer is doing.
2922.

Solve : AVG to Kaspersky????

Answer»

i am using AVG 8 AV but i am ATTEMPTING to CHANGE AVG to Kaspersky 7.
if i have anti virus exists in my computer then i want to change it, do i need to UNINSTALL the existing AV then reinstall another AV?

please instruct me on this. thnks Yes, you will need to uninstall AVG first, and probably reboot, before installing Kaspersky.

Hope this helps.how about the virus in the virus vault? im afraid that if all virus there will BECOME activate after i uninstall AVGOpen AVG, and go to the virus vault, then REMOVE all the items from it.
However I very much doubt that they will be "set free" by uninstalling AVG.I'm not sure but I think there is an option during uninstall that asks you if you want to clear the vault.

2923.

Solve : AVG Free vs AVG Internet Security Suite?

Answer»

I notice that AVG offers "Trial Pay" for their AVG Internet Security Suite. This basically makes it free, if you remember to cancel the trial you sign up for with an advertising partner.

My question is do I WANT this? I use AVG Free, PC TOOLS Spyware Doctor. I don't seem to GET infected. I only use webmail so SPAM protection is not needed. The spyware and rootkit protection would be a good added bonus but I had problems with the free version of the webshield crashing firefox so I UNINSTALLED it.

What would you do?Quote from: thesecdude on July 04, 2008, 08:43:03 AM

What would you do?

I would get rid of AVG and use Avast! and run any appropriate Avast! 'shields.' Spyware Doctor is a good anti-spyware program and I would keep it as long as there was no incompatibility with Avast! and the combination didn't slow down my computer.

Just my opinion - good luck.

EDIT: Avast! has: a) anti-virus, B) anti-spyware, 3) anti-rootkit protections.
2924.

Solve : Bad codec install??

Answer»

Hey there. A day or so ago, I was surfing the internet, when I came to a page that asked me to install a file to view a movie. I, not thinking, installed it. Usually I'm very good about AVOIDING that sort of thing, but I guess I was tired. In result, I earned my first virus (or something) that visually did something to my laptop.

I'm trying hard to remember what it did, exactly, but a lot happened, and even more of it was brief. My background changed itself to a blue screen with a yellow box that said something along the lines of, "Warning! There is Spyware on your computer. Install an antivirus program immediately." Or something. I'd post a screenshot, but after following the READ this before requesting malware removal help forum, it went away. Let's see... My computer slowed down immensely, it would occasionally show the Blue Screen of Death, and the error would always be something different and weird. I can't remember any of them, but they all seemed like something that wouldn't even be on the computer. Every now and then, the blue screen would cause my computer to reboot, and when it loaded back up, I would get a pop-up error saying something about a script error, and M-Dos would run through something quickly (said it was a system32 file?), and I would usually get a BSoD after that too.

I really can't remember anything else. Like I said, everything that happened was quick, so I didn't get much time to ponder or write it all down. I know that all this has caused Firefox to quit working, and for awhile, IE would close itself down after loading the homepage. I was able to get Firefox to work once or twice (I don't know how) but now it just shows a Close Firefox error that says Firefox is already running. Task Manager claims that it is not.

I had run a couple other programs before following "Read this before requesting malware removal help." Spybot and a-squared a couple times. Both found different things. Spybot found zlob.downloader.vcd, but everytime I'd reboot, it'd find it again. A-squared usually found small adware programs that it claimed weren't dangerous.

Other than that, I followed "Read this before requesting malware removal help" to a T, but neither Super Anti-Spyware or MalwareBytes found anything. I'm not sure if I still have the virus, or if it was removed by Spybot or a-squared, and the remaining problems (Firefox still won't boot, computer is very slow, occasional freezes) are just left-overs.

If anything, I would like help getting Firefox to work. It's my main browser, and I feel weird using IE. Besides, one of the times Firefox -did- open, I noticed that my bookmarks had been deleted and I would like to work on getting those back as soon as possible.

And now, the HijackThis log. Thanks for any help you can give me.

[recovering disk space -- attachment deleted by admin]Open Hijackthis and select Do a system scan only then place a check mark next to:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Close all windows except for Hijackthis then click Fix checked.

EXIT Hijackthis and run CCleaner.

----------

Download Combofix by sUBs from one of the below links.

Important! Combofix.exe MUST be saved to and ran from the Desktop.
  • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
  • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
    • Click this link to see a list of security programs that should be disabled and how to disable them.
    • If yours is not listed and you don't know how to disable it, please ask.
  • Warning: Combofix DISCONNECTS your computer from the internet. The connection is automatically restored before Combofix completes its run.
  • Double click combofix.exe & follow the prompts.
    • Choose Yes to accept the Disclaimers.
  • When finished, it will produce a log for you.
  • Post that log in your next reply.
Warning: Do not mouseclick Combofix's window while it is running. That may cause it to stall
  • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
  • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
If needed, see this Combofix tutorial with screenshots that will detail more thoroughly the downloading and running of Combofix.

----------

Next post add
Combofix log
I hope I did that right.. The tutorial said to download the Windows Recovery thing, but Combofix didn't start installing it (like it said it would) until after it'd been running for a few minutes. But I think it all came out to the same result.

[recovering disk space -- attachment deleted by admin]Go to Start > Control Panel > Internet Options
In the General tab, Temporary Internet Files, click:Delete Files
When prompted, check:Delete all offline content
You can also check: Delete Cookies (You will have to re-enter passwords at websites that require them.)
Click OK

Then, go to Start > Run and enter: cleanmgr
Select the drive to clean: C:\
Check the following boxes and then press OK to remove:
  • Temporary Files
  • Temporary Internet Files
  • RecycleBin
Agree to the prompt to perform the action...

----------

Download SDFix.exe and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Now then reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard).
  • Finally copy and paste the contents of the results file Report.txt in your next reply.
.
----------

Let me know how things are now.
Hm.. Everything seems to be okay now. I was able to open Firefox, which makes me very happy. I don't see anything wrong now..

[recovering disk space -- attachment deleted by admin]Looks good.

Let's clear out the programs we've been using to clean up your computer, they are not suitable for
general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
.
  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

    1. Double click OTMoveIt2.exe to launch it.
    Vista users right click and choose Run As Administrator
    2. Click on the CleanUp! button.
    3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
    4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
    5. Once complete exit out of OTMoveIt2

    ----------

    Set a New Restore Point to prevent possible reinfection from an old one
    Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
    • Go to Start > Programs > Accessories > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More Options Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    You can find instructions on how to enable and re-enable system restore here:

    Windows XP System Restore Guide or Windows Vista System Restore Guide
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

    If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

    ----------

    Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum.

    Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

    To prevent unknown applications from being installed on your computer install WinPatrol 2008
    Using Winpatrol to protect your computer from malicious software

    Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business PRACTICES and spam.

    SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    *Using SpywareBlaster to protect your computer from Spyware and Malware
    *If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thank you very much. You were a lot of help. I'll remember to come back here next time I screw something up. =P ThanksNo problem.

    Safe surfing.....
    2925.

    Solve : Please help - Virus - i open internet, virus scan, restore computer shuts down?

    Answer»

    hello all, and please help me!
    i brought a new acer laptop a little over a week ago, and i have already mangaged to put a virus on it.
    i have managed to REMOVE the virus i think... after reading over forums i installed malware antivirus, alongside my norton. i started windows in safe mode and ran a scan, then deleted 'trojan tracker'. however when i started the laptop in normal mode i got the same problem, internet will not CONNECT (wireless) and when i click on anything that uses the internet; msn or update for software the computer shows and blue screen with black writting which says 'windows has shut down for your safety...... dumping phyisical memory'
    if i run a virus scan in normal mode when it hits on the file it comes up with the blue screen.
    i deleted all the FILES that i have downloaded using torrent, limewire etc, but still no look. please help!
    oh, and it will not SYSTEM restore, it goes through the whole process and when it turns back on it says unable to restore to point. whats wrong? have i deleted the file but changed settings, not allowing it on internet programs?? operating system is vistaSince it's new laptop, I assume, you don't have much personal data on it, yet. Use Recovery DVD to restore it to day one condition.it didn't come with any reformat cd, i made a restore point onto some cd's but when i got into the bios and try and format from the disks it doesn't work, any ideas on how to reformat harddrive etc..?
    thanksits come up with the error code;
    stop 0x0000008c (0xc0000005, 0x00000000, 0x8a08ca48, 0x00000000)
    can some please help!
    thanlsQuote

    i got into the bios and try and format from the disks
    What disks?
    Quote
    how to reformat harddrive etc..?
    Every Vista computer comes with EITHER Recovery DVDs (sometimes you receive instructions how to make them by yourself), or Recovery partition.
    Some manufacturers will send you set of Recovery DVDs for free.
    You need to contact Acer, since your laptop is under warranty. Monkeying with it may void warranty.thanks, i made the cd's when i brought the laptop, using system restore and saving everything to disk, it took 7 of them. my problem is that it will not boot from the disk, dont no why?
    thanksOK, we have some terminology issues here.
    What do you mean by: "when i got into the bios and try and format"?
    Why would you go to BIOS to format anything?
    You may want to make sure in BIOS, that in boot order CD/DVD drive is listed first, and then you restart computer with Recovery DVD in, and it should boot to Recovery DVD.
    yeah broni, i changed the order, and put cd first and hdd 2nd, then restarted and it wouldn't boot from the disks i made in system restore, are the disks right? thanks for the infoI assume, you put DVD in before you started computer, right?
    If so, when your computer starts, you should briefly see at the top of black screen this message:
    Press any key to boot from CD
    You must press any key at that very moment.
    2926.

    Solve : Re: Norton email scan turned off?

    Answer»

    Hey Gents, I too got a similar problem,

    The log file looks like below

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Norton SECURITY Scan\Nss.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Opera\Opera.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF READER Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
    O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
    O4 - S-1-5-18 Startup: Microsoft Office.lnk = C:\MSOFFICE\MSOFFICE.EXE (User 'SYSTEM')
    O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
    O4 - .DEFAULT Startup: Microsoft Office.lnk = C:\MSOFFICE\MSOFFICE.EXE (User 'Default user')
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: Microsoft Office.lnk = C:\MSOFFICE\MSOFFICE.EXE
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194142966984
    O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe



    Can somebody help me please jayaprakashgopal
    Next time, you need to start your own topic, when posting about your computer problem. This time, I'll create new topic for you.Please, repost HJT log, including its missing header.

    2927.

    Solve : Possible spyware?

    Answer»

    Quote from: Broni on June 30, 2008, 09:28:50 PM

    Yes, I'd definitely reinstall it. Your computer is clean now, but all those infections might have MESSED up Norton.

    It's not working after a reinstall :/ - couldn't start scanner engine error. Reinstalled, then error, tried ccleaner, then error.Uninstall Norton, using Norton Removal Tool: http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039
    Then, reinstall.It's just symantec antivirus from my SCHOOL, and not norton - but I'm following the steps - setup told me to add/remove symantec antivirus 9, and then run it, so will do that and post back.Still doesn't work :[I tell you what...Since you got it for free, uninstall that crappy tool, which is really poor antivirus program, and install one of two free antivirus programs:
    - Avast! free antivirus: http://filehippo.com/download_avast_antivirus/
    - AVIRA free antivirus: http://www.free-av.com/en/download/index.html
    Quote from: Broni on July 01, 2008, 10:25:28 PM
    I tell you what...Since you got it for free, uninstall that crappy tool, which is really poor antivirus program, and install one of two free antivirus programs:
    - Avast! free antivirus: http://filehippo.com/download_avast_antivirus/
    - Avira free antivirus: http://www.free-av.com/en/download/index.html


    Installed Avira - it's working fine. It DETECTED another Vundo trojan in a dll file which I deleted.

    Thanks again & God BlessI'm glad, we have one less computer "infected" with Norton.
    I suggest, you run Norton Removal Tool: http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039 to remove Norton's leftovers. I assure you, they're there.Quote from: Broni on July 04, 2008, 07:54:15 PM
    I'm glad, we have one less computer "infected" with Norton.
    I suggest, you run Norton Removal Tool: http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039 to remove Norton's leftovers. I assure you, they're there.

    Roger that, will do.

    Any suggestions on which one to download? As this just said Symantec.

    Thanks again, and God BlessIf you don't know which type of Norton it was, first download should do.
    2928.

    Solve : comp hanged n restart by itself after firefox prob?

    Answer» HEY guys
    the people over at ms xp directed me over here
    below is what i posted over there

    i was surfing on the net (bird-x.com if i am not wrong to be exact) using the firefox when the browser stop responding..and the comp freezes
    restarted the comp n tried to open the firefox again..
    as usual a "start new session" / "go back to last session"(cant rem the exact phrase) pop up...
    when i tried to go back to last session the comp hang again
    i tried startin a new session but the same thing happen

    i have since ran AVG anti virus scan that cant COMPLETE(comp restarts by itself be4 the scan could finish)
    and ad adware + spybot which found nothing malicious..
    also tried kaspersky online and again comp restarts be4 it could finish
    also tried deleting firefox but doesnt work...

    i am running on win xp sp 2
    my update runs on auto so it shldnt be too outdated

    thanks alot for the help

    i have since ran ccleaner but as i was trying to clear the firefox under application the comp hanged

    i will POST a hijackthis log laterLogfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:42:35 PM, on 7/1/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\BitTorrent_DNA\dna.exe
    C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
    C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\jiajun\Desktop\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [EPSON Stylus CX3700 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACP.EXE /F "C:\WINDOWS\TEMP\E_S162.tmp" /EF "HKLM"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [ZoneAlarm CLIENT] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\RunOnce: [wextract_cleanup0] rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\jiajun\LOCALS~1\Temp\IXP000.TMP\"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
    O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
    O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Program Files\Mozilla Firefox\plugins\NPSWF32_FlashUtil.exe -p
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189093044453
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
    O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

    --
    End of file - 8261 bytes
    I see no infection. Did you try System Restore?nope i have not done that
    but i have tried crap cleaner
    it always hangs at its clearing one file in firefox
    will do a system scan in safe mode lateralright
    just tried to scan with AVG in safe mode
    the comp restarts itself be4 the scan could complete
    anymore adviseS?Quote
    Did you try System Restore?
    er
    how do i activate system restoreClick Start, point to All Programs, point to Accessories, point to System Tools, and then click System Restore.
    2929.

    Solve : Lots of viruses?

    Answer»

    In what ways is it running slow?

    I suggest Defragmenting your Hard Drive and downloading CCleaner.
    With CCleaner, RUN tick System (and anything else you would like to remove) and run the cleaner. Then run a scan through the Registry a couple of times.

    Now, go to Start --> Run --> msconfig and press Enter
    Head over to the Startup tab and untick anything you don't need on startup.
    Note: if you untick something like itunes, it will still work with no problems.My computer was running slow after i logged in but after adjusting some things in msconfig that is fixed. After analyzing a message comes up saying that i do not have to defragment at this time.

    My computer is runing alot faster than before.

    Thank youQuote

    Now, go to Start --> Run --> msconfig and press Enter
    Head over to the Startup tab and untick anything you don't need on startup
    This was taken care of while WORKING with HJT log.

    TRID3NT
    What are computer specs: processor SPEED, amount of RAM, hard drive size/free space?My processor speed is 1.73GHz

    504MB of RAM

    My hard drive is 74.5 GB
    Used: 41.6
    Free:32.8Looks OK. Another 512MB of RAM for a few bucks would help.Quote from: Broni on July 03, 2008, 07:41:08 PM
    Quote
    Now, go to Start --> Run --> msconfig and press Enter
    Head over to the Startup tab and untick anything you don't need on startup
    This was taken care of while working with HJT log.
    Good Point.

    Quote from: TRID3NT on July 03, 2008, 02:37:24 PM
    After analyzing a message comes up saying that i do not have to defragment at this time.
    Do it anyways. I do it every day when the computer is idle.Thank you guys for helping me out

    computer seems to work just fine.Cool
    2930.

    Solve : online scan to get rid of "packed.generic.200"??

    Answer»

    Many things have happened, after MoveIt ran and I REBOOTED, the avenger log came up:

    Avenger log-

    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows XP

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.

    Hidden driver "UACd.sys" found!
    ImagePath: \systemroot\system32\drivers\UACrhbyyetusiutewx.sys
    Start Type: 1 (System)

    Rootkit scan completed.


    Completed script processing.

    *******************

    Finished! Terminate.

    Then the MoveIt log came up:

    MoveIt log-
    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== SERVICES/DRIVERS ==========
    Service\Driver UACd not found.
    Service\Driver UACd not found.
    ========== REGISTRY ==========
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys\\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys\modules\\ not found.
    Unable to delete registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UACd.sys\modules\\ .
    ========== FILES ==========
    File/Folder \\?\globalroot\systemroot\system32\uacnmsfijuybienyic.dll not found.
    ========== COMMANDS ==========
    User's Temp folder emptied.
    User's Internet Explorer cache folder emptied.
    File delete failed. C:\Documents and Settings\kevin\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    User's Temporary Internet Files folder emptied.
    Local Service Temp folder emptied.
    Local Service Temporary Internet Files folder emptied.
    Network Service Temp folder emptied.
    Network Service Temporary Internet Files folder emptied.
    Windows Temp folder emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05202009_222711

    Files moved on Reboot...

    THEN AVG came up and said that there were infections and did I want to move them to the vault. I clicked YES but it said access denied and did I want to delete them. I clicked yes and they were deleted. I checked the vault to be sure, and they were there. I deleted the contents of the vault.

    And finally Norton360 popped up and said that Backdoor.tidserv was detected and that a restart was needed. I did that but the Norton360 alert came up again.

    I checked the info that Norton had and it shows the affected areas as: 2 services, 15 files, 6 registry entries, 3 system actions and 1 browser cache.

    A lot of progress but it looks like new problems are appearing.On a whim I clicked on Malwarebytes setup and it opened up and ran through the install with no problems. It is scanning now...got my fingers crossed.whew, almost an hour scanning and Malwarebytes found 9 things, and they were removed. I rebooted and so far nothing has popped up again. Below is the log:

    Malwarebytes' Anti-Malware 1.36
    Database version: 1945
    Windows 5.1.2600 Service Pack 3

    5/21/2009 1:24:12 AM
    mbam-log-2009-05-21 (01-24-12).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 142272
    Time elapsed: 54 minute(s), 49 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 4
    Registry Values Infected: 0
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 3

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\Interface\{986a8ac1-ab4d-4f41-9068-4b01c0197867} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{8e3c68cd-f500-4a2a-8cb9-132bb38c3573} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\AppID\{a0e1054b-01ee-4d57-a059-4d99f339709f} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\System Volume Information\_restore{FAA3F5BE-A238-4FAB-91BF-59480E951B96}\RP0\A0000007.exe (Adware.Cinmus) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Program Files\Common\helper.sig (Trojan.Agent) -> Quarantined and deleted successfully.

    Success? I certainly hope so. Thanks for all the helpWoke up at 4:30 and the Norton360 scan was done. There were only tracking cookies and those were deleted easily. I will be running the scans on all of the accounts on the laptop, but it looks good for the infections to be gone.

    I will let you know if anything bad is found again, but for now


    THANK YOU EVILFANTASY!!Glad it finally worked.

    Lets run another scan just to DOUBLE check.

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.
    Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFix
    Here is the Combofix log

    ComboFix 09-05-19.08 - Joe 05/21/2009 13:13.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.413 [GMT -4:00]
    Running from: c:\documents and settings\Joe\Desktop\ComboFix.exe
    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: Norton 360 *On-access scanning disabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
    FW: Norton 360 *enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\setup.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_UACd.sys


    ((((((((((((((((((((((((( Files Created from 2009-04-21 to 2009-05-21 )))))))))))))))))))))))))))))))
    .

    2009-05-21 17:14 . 2009-05-21 17:146736----a-wc:\windows\system32\drivers\PROCEXP90.SYS
    2009-05-21 04:25 . 2009-05-21 04:25--------d-----wc:\documents and settings\kevin\Application Data\Malwarebytes
    2009-05-21 04:25 . 2009-04-06 19:3215504----a-wc:\windows\system32\drivers\mbam.sys
    2009-05-21 04:25 . 2009-04-06 19:3238496----a-wc:\windows\system32\drivers\mbamswissarmy.sys
    2009-05-21 04:25 . 2009-05-21 04:25--------d-----wc:\documents and settings\All Users\Application Data\Malwarebytes
    2009-05-21 04:25 . 2009-05-21 04:25--------d-----wc:\program files\Malwarebytes' Anti-Malware
    2009-05-21 02:27 . 2009-05-21 02:27--------d-----wC:\_OTMoveIt
    2009-05-18 19:19 . 2009-05-18 19:19--------d-----wc:\program files\Driver Magician Lite
    2009-05-17 18:59 . 2009-05-17 19:00--------d-----wc:\documents and settings\kevin
    2009-05-17 17:06 . 2009-05-17 17:54--------d-----wc:\documents and settings\Joe\.housecall6.6
    2009-05-17 16:00 . 2009-05-17 15:3615688----a-wc:\windows\system32\lsdelete.exe
    2009-05-17 15:36 . 2009-05-17 15:3564160----a-wc:\windows\system32\drivers\Lbd.sys
    2009-05-17 15:35 . 2009-05-21 12:24--------d-----wc:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-05-17 15:35 . 2009-05-21 17:21--------d-----wc:\program files\Spybot - Search & Destroy
    2009-05-17 15:34 . 2009-05-17 15:34--------dc-h--wc:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
    2009-05-17 15:34 . 2009-05-17 15:34--------d-----wc:\program files\Lavasoft
    2009-05-17 15:34 . 2009-05-17 15:36--------d-----wc:\documents and settings\All Users\Application Data\Lavasoft
    2009-05-17 15:28 . 2009-05-17 15:28--------d-----wc:\program files\Windows Media Connect 2
    2009-05-17 15:26 . 2009-05-17 15:27--------d-----wc:\windows\system32\drivers\UMDF
    2009-05-17 15:26 . 2009-05-17 15:26--------d-----wc:\windows\system32\LogFiles
    2009-05-15 02:17 . 2009-05-21 04:55--------d--h--wC:\$AVG8.VAULT$
    2009-05-15 02:13 . 2009-05-15 02:1311952----a-wc:\windows\system32\avgrsstx.dll
    2009-05-15 02:13 . 2009-05-15 02:13108552----a-wc:\windows\system32\drivers\avgtdix.sys
    2009-05-15 02:13 . 2009-05-15 02:13325896----a-wc:\windows\system32\drivers\avgldx86.sys
    2009-05-15 02:13 . 2009-05-17 16:24--------d-----wc:\windows\system32\drivers\Avg
    2009-05-15 02:12 . 2009-05-15 02:12--------d-----wc:\program files\AVG
    2009-05-15 02:12 . 2009-05-15 02:12--------d-----wc:\documents and settings\All Users\Application Data\avg8
    2009-05-14 23:16 . 2009-05-14 23:1653248----a-wc:\windows\system32\drivers\UACjhmyrlvskbrrwov.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-05-21 17:25 . 2005-12-16 08:32--------d-----wc:\program files\Common Files\Symantec Shared
    2009-05-21 05:24 . 2008-10-24 20:38--------d-----wc:\program files\Common
    2009-05-17 15:25 . 2005-12-16 05:28--------d-----wc:\program files\Windows Media Connect
    2009-05-17 15:25 . 2007-01-14 14:47126----a-wc:\documents and settings\Joe\Local Settings\Application Data\fusioncache.dat
    2009-05-16 01:39 . 2005-12-16 08:28--------d-----wc:\program files\Quicken
    2009-04-18 14:36 . 2008-10-26 18:36--------d-----wc:\program files\Norton 360
    2009-04-04 19:49 . 2008-04-06 14:2420---h--wc:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
    2009-04-04 19:48 . 2008-04-06 14:2120---h--wc:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
    2009-03-06 14:22 . 2005-12-16 02:51284160----a-wc:\windows\system32\pdh.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-23 68856]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-25 98304]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-25 77824]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-25 118784]
    "Apoint"="c:\program files\Apoint\Apoint.exe" [2004-11-18 118784]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
    "VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-11-29 217088]
    "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
    "VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-12 151552]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-30 7335936]
    "Switcher.exe"="c:\program files\Sony\Wireless Switch SETTING Utility\Switcher.exe" [2005-11-24 167936]
    "VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632]
    "HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-17 49152]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
    "osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-15 1947928]
    "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-17 516440]

    c:\documents and settings\Joe\Start Menu\Programs\Startup\
    Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-05-15 02:1311952----a-wc:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
    2005-05-21 01:4273728----a-wc:\windows\system32\VESWinlogon.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/17/2009 11:36 AM 64160]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/14/2009 10:13 PM 325896]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/14/2009 10:13 PM 108552]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/14/2009 10:13 PM 298776]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 953168]
    R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 3:37 PM 149352]
    R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
    R3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 10:32 PM 23888]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/25/2009 7:26 PM 101936]
    R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [12/15/2005 10:52 PM 28800]
    R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [12/15/2005 10:52 PM 217472]
    S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - COMHOST
    .
    Contents of the 'Scheduled Tasks' folder

    2009-05-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 15:35]
    .
    - - - - ORPHANS REMOVED - - - -

    Notify-WgaLogon - (no file)


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    mDefault_Search_URL = hxxp://www.google.com/ie
    uInternet Settings,ProxyServer = proxy:8002
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-05-21 13:23
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1300)
    c:\windows\system32\VESWinlogon.dll

    - - - - - - - > 'explorer.exe'(4928)
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\program files\Common Files\Symantec Shared\VAScanner\comHost.exe
    c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    c:\windows\ehome\ehrecvr.exe
    c:\windows\ehome\ehSched.exe
    c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
    c:\program files\Sony\VAIO Event Service\VESMgr.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    c:\windows\ehome\mcrdsvc.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\windows\system32\igfxext.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    c:\windows\system32\wbem\unsecapp.exe
    c:\windows\ehome\ehmsas.exe
    c:\program files\Apoint\ApntEx.exe
    .
    **************************************************************************
    .
    Completion time: 2009-05-21 13:29 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-05-21 17:29

    Pre-Run: 78,696,206,336 bytes free
    Post-Run: 78,620,049,408 bytes free

    198--- E O F ---2009-05-17 19:11

    Is this good news?
    Yes there is still one left.

    You need to uninstall either Norton or AVG. Two antivirus actually offers less protection because they "argue" with each other.

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    File::
    c:\windows\system32\drivers\UACjhmyrlvskbrrwov.sys

    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeHere is the latest ComboFix log

    ComboFix 09-05-19.08 - Joe 05/21/2009 14:51.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.443 [GMT -4:00]
    Running from: c:\documents and settings\Joe\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Joe\Desktop\CFScript.txt
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: Norton 360 *On-access scanning disabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
    FW: Norton 360 *enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

    FILE ::
    c:\windows\system32\drivers\UACjhmyrlvskbrrwov.sys
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\drivers\UACjhmyrlvskbrrwov.sys

    .
    ((((((((((((((((((((((((( Files Created from 2009-04-21 to 2009-05-21 )))))))))))))))))))))))))))))))
    .

    2009-05-21 17:14 . 2009-05-21 17:296736----a-wc:\windows\system32\drivers\PROCEXP90.SYS
    2009-05-21 04:25 . 2009-05-21 04:25--------d-----wc:\documents and settings\kevin\Application Data\Malwarebytes
    2009-05-21 04:25 . 2009-04-06 19:3215504----a-wc:\windows\system32\drivers\mbam.sys
    2009-05-21 04:25 . 2009-04-06 19:3238496----a-wc:\windows\system32\drivers\mbamswissarmy.sys
    2009-05-21 04:25 . 2009-05-21 04:25--------d-----wc:\documents and settings\All Users\Application Data\Malwarebytes
    2009-05-21 04:25 . 2009-05-21 04:25--------d-----wc:\program files\Malwarebytes' Anti-Malware
    2009-05-21 02:27 . 2009-05-21 02:27--------d-----wC:\_OTMoveIt
    2009-05-18 19:19 . 2009-05-18 19:19--------d-----wc:\program files\Driver Magician Lite
    2009-05-17 18:59 . 2009-05-17 19:00--------d-----wc:\documents and settings\kevin
    2009-05-17 17:06 . 2009-05-17 17:54--------d-----wc:\documents and settings\Joe\.housecall6.6
    2009-05-17 16:00 . 2009-05-17 15:3615688----a-wc:\windows\system32\lsdelete.exe
    2009-05-17 15:36 . 2009-05-17 15:3564160----a-wc:\windows\system32\drivers\Lbd.sys
    2009-05-17 15:35 . 2009-05-21 12:24--------d-----wc:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-05-17 15:35 . 2009-05-21 17:21--------d-----wc:\program files\Spybot - Search & Destroy
    2009-05-17 15:34 . 2009-05-17 15:34--------dc-h--wc:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
    2009-05-17 15:34 . 2009-05-17 15:34--------d-----wc:\program files\Lavasoft
    2009-05-17 15:34 . 2009-05-17 15:36--------d-----wc:\documents and settings\All Users\Application Data\Lavasoft
    2009-05-17 15:28 . 2009-05-17 15:28--------d-----wc:\program files\Windows Media Connect 2
    2009-05-17 15:26 . 2009-05-17 15:27--------d-----wc:\windows\system32\drivers\UMDF
    2009-05-17 15:26 . 2009-05-17 15:26--------d-----wc:\windows\system32\LogFiles
    2009-05-15 02:17 . 2009-05-21 04:55--------d--h--wC:\$AVG8.VAULT$
    2009-05-15 02:13 . 2009-05-15 02:1311952----a-wc:\windows\system32\avgrsstx.dll
    2009-05-15 02:13 . 2009-05-15 02:13108552----a-wc:\windows\system32\drivers\avgtdix.sys
    2009-05-15 02:13 . 2009-05-15 02:13325896----a-wc:\windows\system32\drivers\avgldx86.sys
    2009-05-15 02:13 . 2009-05-17 16:24--------d-----wc:\windows\system32\drivers\Avg
    2009-05-15 02:12 . 2009-05-15 02:12--------d-----wc:\program files\AVG
    2009-05-15 02:12 . 2009-05-15 02:12--------d-----wc:\documents and settings\All Users\Application Data\avg8

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-05-21 18:54 . 2005-12-16 08:32--------d-----wc:\program files\Common Files\Symantec Shared
    2009-05-21 05:24 . 2008-10-24 20:38--------d-----wc:\program files\Common
    2009-05-17 15:25 . 2005-12-16 05:28--------d-----wc:\program files\Windows Media Connect
    2009-05-17 15:25 . 2007-01-14 14:47126----a-wc:\documents and settings\Joe\Local Settings\Application Data\fusioncache.dat
    2009-05-16 01:39 . 2005-12-16 08:28--------d-----wc:\program files\Quicken
    2009-04-18 14:36 . 2008-10-26 18:36--------d-----wc:\program files\Norton 360
    2009-04-04 19:49 . 2008-04-06 14:2420---h--wc:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
    2009-04-04 19:48 . 2008-04-06 14:2120---h--wc:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
    2009-03-06 14:22 . 2005-12-16 02:51284160----a-wc:\windows\system32\pdh.dll
    .

    ((((((((((((((((((((((((((((( [emailprotected]_17.25.26 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-05-21 18:55 . 2009-05-21 18:5516384 c:\windows\Temp\Perflib_Perfdata_4f4.dat
    + 2009-05-21 18:54 . 2009-05-21 18:5416384 c:\windows\Temp\Perflib_Perfdata_2a8.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-23 68856]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-25 98304]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-25 77824]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-25 118784]
    "Apoint"="c:\program files\Apoint\Apoint.exe" [2004-11-18 118784]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
    "VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-11-29 217088]
    "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
    "VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-12 151552]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-30 7335936]
    "Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-11-24 167936]
    "VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632]
    "HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-17 49152]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
    "osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-15 1947928]
    "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-17 516440]

    c:\documents and settings\Joe\Start Menu\Programs\Startup\
    Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-05-15 02:1311952----a-wc:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
    2005-05-21 01:4273728----a-wc:\windows\system32\VESWinlogon.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/17/2009 11:36 AM 64160]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/14/2009 10:13 PM 325896]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/14/2009 10:13 PM 108552]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/14/2009 10:13 PM 298776]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 953168]
    R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 3:37 PM 149352]
    R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/25/2009 7:26 PM 101936]
    R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [12/15/2005 10:52 PM 28800]
    R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [12/15/2005 10:52 PM 217472]
    S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 10:32 PM 23888]
    S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - COMHOST
    .
    Contents of the 'Scheduled Tasks' folder

    2009-05-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 15:35]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    mDefault_Search_URL = hxxp://www.google.com/ie
    uInternet Settings,ProxyServer = proxy:8002
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-05-21 14:56
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1300)
    c:\windows\system32\VESWinlogon.dll

    - - - - - - - > 'explorer.exe'(3512)
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\program files\Common Files\Symantec Shared\VAScanner\comHost.exe
    c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    c:\windows\ehome\ehrecvr.exe
    c:\windows\ehome\ehSched.exe
    c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
    c:\program files\Sony\VAIO Event Service\VESMgr.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\windows\ehome\mcrdsvc.exe
    c:\windows\system32\igfxext.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    c:\windows\system32\wbem\unsecapp.exe
    c:\program files\Apoint\ApntEx.exe
    c:\windows\ehome\ehmsas.exe
    .
    **************************************************************************
    .
    Completion time: 2009-05-21 15:02 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-05-21 19:02
    ComboFix2.txt 2009-05-21 17:29

    Pre-Run: 78,615,195,648 bytes free
    Post-Run: 78,597,533,696 bytes free

    201--- E O F ---2009-05-17 19:11


    >crosses his fingers

    And I am uninstalling AVG, I think the owner has actually paid for Norton

      OK we can finish up now.

      This should remove all of the tools we used.

      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      • The above procedure will:
      • Delete the FOLLOWING:
      • ComboFix and its associated files and folders.
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      Download
    ATF Cleaner by Atribune to your Desktop.

    Alternate download link

    Note: Vista users must use Run As Administrator
    • Under Main: Select Files to Delete choose: Select All.
    • Click the Empty Selected button.
    • If you use Firefox browser click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • If you use Opera browser click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • Click Exit on the Main menu to close the program.
    .
    Note that your system will run slower for a reboot or two after having used this tool so don't panic.

    ----------

    Download OTCleanIt.exe and save it to your Desktop.
    • Double-click OTCleanIt.exe.
    • Click the CleanUp! button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes, if not delete it yourself.
    .

    WHEW again! Ok, deleted ComboFix, downloaded and ran the other two programs, is that it?

    I don't want to go through this again, but if I do I have all of these new programs to make use of.

    Thanks again.You should be good to go.

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Well, all of my computers are safe and uninfected, this whole episode was for a teacher at the school where I work. Now she knows not to click on a little box that promises to clean up her computer for a small fee. 8-)I learned the hard way long ago. Sometimes a hard lesson is the best lesson.

    Let us know if anything else comes up.EvilFantasy!!!!!

    I........ LOVE YOU VERY MUCH DUDE~! XD

    THX DUDE! YOUR MY COMPUTER SAVIOUR XD
    2931.

    Solve : Please deliberate carefully on these 'Suspicious Files'!?

    Answer»

    Hi Security Guys!

    I have just tried 'Sophos Free Standalone Antivirus' Product{its Buzz has started to grow with "Klingon" as its name}. On running a 'Full System Scan', it Quarantined 3 'Suspicious Files' for which I would REQUEST your careful deliberation!

    Please find the attached SCREENSHOT & guide whether these are just HOAX(False Positives) or its better to get rid of these !!??

    Thanks in advance...!

    Please find a "Better" 2nd Screenshot(detailed description)

    [attachment deleted by admin]Wopti Utilities woptiinfo.dll http://www.threatexpert.com/files/woptiinfo.dll.html

    The other two appear to b efrom iObit Advanced System Care.Hi Guys!

    Well, I took this matter to the HOUSE of Sophos. Submitted the samples of the 'Suspicious Files' & it came out to be the HOAX DETECTIONS(False Positives) from their Product!


    Read what these Guys have to say:

    Hi,

    Thanks for the samples.

    I have spoken to the Labs and the files that you submitted are not malicious.
    The warnings that we have GENERATED for these can be ignored.

    If you were running the full Anti-virus product you would be able to to
    authorise these files so that they are not detected again. As these were the
    only threats detected by the Threat detection test, I am happy to give your
    machine a clean bill of health.

    Please let me know if I can be of further assistance.

    Regards,

    James Barker
    Sophos Technical Support

    2932.

    Solve : Unable to access internet?

    Answer»

    Ive got the 3 logs... what do i do next?

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 06/19/2008 at 05:57 PM

    Application Version : 4.15.1000

    Core Rules Database Version : 3469
    Trace Rules Database Version: 1460

    Scan type : Complete Scan
    Total Scan Time : 01:45:05

    Memory items scanned : 398
    Memory threats detected : 1
    Registry items scanned : 5480
    Registry threats detected : 52
    File items scanned : 181901
    File threats detected : 14

    Adware.Vundo Variant/Resident
    C:\WINDOWS\SYSTEM32\OPNKLJCY.DLL
    C:\WINDOWS\SYSTEM32\OPNKLJCY.DLL

    Adware.webHancer
    HKLM\Software\Classes\CLSID\{c900b400-cdfe-11d3-976a-00e02913a9e0}
    HKCR\CLSID\{C900B400-CDFE-11D3-976A-00E02913A9E0}
    HKCR\CLSID\{C900B400-CDFE-11D3-976A-00E02913A9E0}
    HKCR\CLSID\{C900B400-CDFE-11D3-976A-00E02913A9E0}\InprocServer32
    HKCR\CLSID\{C900B400-CDFE-11D3-976A-00E02913A9E0}\InprocServer32#ThreadingModel
    HKCR\CLSID\{C900B400-CDFE-11D3-976A-00E02913A9E0}\ProgID
    HKCR\CLSID\{C900B400-CDFE-11D3-976A-00E02913A9E0}\Programmable
    HKCR\CLSID\{C900B400-CDFE-11D3-976A-00E02913A9E0}\VersionIndependentProgID
    C:\PROGRAM FILES\WEBHANCER\PROGRAMS\WHIEHLPR.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c900b400-cdfe-11d3-976a-00e02913a9e0}
    HKCR\WhIeHelperObj.WhIeHelperObj
    HKCR\WhIeHelperObj.WhIeHelperObj\CurVer
    HKCR\WhIeHelperObj.WhIeHelperObj.1
    HKCR\WhIeHelperObj.WhIeHelperObj.1\CLSID
    HKCR\Interface\{C89435B0-CDFE-11D3-976A-00E02913A9E0}
    HKCR\Interface\{C89435B0-CDFE-11D3-976A-00E02913A9E0}\ProxyStubClsid
    HKCR\Interface\{C89435B0-CDFE-11D3-976A-00E02913A9E0}\ProxyStubClsid32
    HKCR\Interface\{C89435B0-CDFE-11D3-976A-00E02913A9E0}\TypeLib
    HKCR\Interface\{C89435B0-CDFE-11D3-976A-00E02913A9E0}\TypeLib#Version
    HKCR\TypeLib\{C8CB3870-CDFE-11D3-976A-00E02913A9E0}
    HKCR\TypeLib\{C8CB3870-CDFE-11D3-976A-00E02913A9E0}\1.0
    HKCR\TypeLib\{C8CB3870-CDFE-11D3-976A-00E02913A9E0}\1.0\0
    HKCR\TypeLib\{C8CB3870-CDFE-11D3-976A-00E02913A9E0}\1.0\0\win32
    HKCR\TypeLib\{C8CB3870-CDFE-11D3-976A-00E02913A9E0}\1.0\FLAGS
    HKCR\TypeLib\{C8CB3870-CDFE-11D3-976A-00E02913A9E0}\1.0\HELPDIR
    HKLM\Software\WebHancer
    HKLM\Software\WebHancer#BaseDir
    HKLM\Software\WebHancer\CC
    HKLM\Software\WebHancer\CC#DistTag
    HKLM\Software\WebHancer\CC#DWLLTM
    HKLM\Software\WebHancer\CC#SLNTIND
    HKLM\Software\WebHancer\CC#ACCPTPS
    HKLM\Software\WebHancer\ESO
    HKLM\Software\WebHancer\ESO#aa
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent#UninstallString
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent#DisplayName
    C:\Program Files\WEBHANCER\Programs\license.txt
    C:\Program Files\WEBHANCER\Programs\readme.txt
    C:\Program Files\WEBHANCER\Programs\sporder.dll
    C:\Program Files\WEBHANCER\Programs\whagent.ini
    C:\Program Files\WEBHANCER\Programs
    C:\Program Files\WEBHANCER
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{6B5957BF-BA84-49A1-A324-D5FF8FFCC687}\RP241\A0118724.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{6B5957BF-BA84-49A1-A324-D5FF8FFCC687}\RP241\A0118734.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{6B5957BF-BA84-49A1-A324-D5FF8FFCC687}\RP241\A0118735.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{6B5957BF-BA84-49A1-A324-D5FF8FFCC687}\RP241\A0118736.EXE

    Unclassified.Unknown Origin
    HKLM\Software\Classes\CLSID\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}
    HKCR\CLSID\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}
    HKCR\CLSID\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}
    HKCR\CLSID\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}\InprocServer32
    HKCR\CLSID\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}\InprocServer32#ThreadingModel
    HKCR\CLSID\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}\ProgID
    HKCR\CLSID\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}\TypeLib
    SOCKINS32.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}

    Trojan.Vundo-Variant/Small
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67D33942-8B34-4F8E-99B0-4A8C2B989C30}
    HKCR\CLSID\{67D33942-8B34-4F8E-99B0-4A8C2B989C30}
    HKCR\CLSID\{67D33942-8B34-4F8E-99B0-4A8C2B989C30}\InprocServer32
    HKCR\CLSID\{67D33942-8B34-4F8E-99B0-4A8C2B989C30}\InprocServer32#ThreadingModel

    Adware.Vundo Variant/Rel
    HKLM\SOFTWARE\Microsoft\aoprndtws
    HKLM\SOFTWARE\Microsoft\FCOVM
    HKLM\SOFTWARE\Microsoft\RemoveRP
    HKU\S-1-5-21-1220945662-2052111302-725345543-1004\Software\Microsoft\rdfa

    Adware.Tracking Cookie
    www.googleadservices.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    shop.winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    shop.winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    shop.winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    shop.winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    shop.winanonymous.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]
    .adnetserver.com [ C:\Documents and Settings\Ste\Application Data\Mozilla\Firefox\Profiles\arm6k7ow.default\cookies.txt ]

    Trojan.Downloader-Gen
    C:\WINDOWS\SYSTEM32\SFT.RES

    Number 2:

    Malwarebytes' Anti-Malware 1.17

    Database version: 846

    8:38:27 PM 19/06/2008
    mbam-log-6-19-2008 (20-38-27).txt

    Scan type: Full Scan (C:\|I:\|)
    Objects scanned: 230726
    Time elapsed: 57 minute(s), 24 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 2
    Registry Keys Infected: 8
    Registry Values Infected: 4
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 10

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    C:\WINDOWS\system32\ftyfgmmu.dll (Trojan.Vundo) -> Unloaded module successfully.
    C:\WINDOWS\system32\opnklJcY.dll (Trojan.Vundo) -> Unloaded module successfully.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5d97396f-ead1-4144-a594-b35c497add05} (Trojan.Vundo) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{5d97396f-ead1-4144-a594-b35c497add05} (Trojan.Vundo) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{66186f05-bbbb-4a39-864f-72d84615c679} (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{66186f05-bbbb-4a39-864f-72d84615c679} (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\c4e5b160 (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\WebProxy (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows Installer (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BMc7d682fc (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\opnkljcy -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\opnkljcy -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\system32\ftyfgmmu.dll (Trojan.Vundo) -> Delete on reboot.
    C:\WINDOWS\system32\ummgfytf.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ummgfytf.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\opnklJcY.dll (Trojan.Vundo) -> Delete on reboot.
    C:\WINDOWS\system32\YcJlknpo.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\YcJlknpo.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{6B5957BF-BA84-49A1-A324-D5FF8FFCC687}\RP240\A0117677.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{6B5957BF-BA84-49A1-A324-D5FF8FFCC687}\RP241\A0118743.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\wbacnvtt.dll (Trojan.Agent) -> Delete on reboot.
    C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

    and the hijack this log...

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:44:51 PM, on 19/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
    O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'c:\program files\webhancer\programs\webhdll.dll' missing
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (CHECKERS Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
    O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00B0AFA.dat
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: Symantec

    Am i broken much?Download SDFix.exe and save it to your Desktop.

    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

    Now then reboot your computer in Safe Mode by doing the FOLLOWING:

    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode, then press Enter.
    • Choose your usual account.
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then PROMPT you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
      (Report.txt will also be copied to Clipboard).
    • Finally copy and paste the contents of the results file Report.txt with a NEW HijackThis log in your next reply.
    If SDFix won't run or you get errors, follow the link for instructions on running SDFix. How to use SDFix that was quick.

    ill get on it asap.

    post back later today.

    thanks a lotSDFix: Version 1.194
    Run by Ste on Fri 20/06/2008 at 07:06 PM

    Microsoft Windows XP [Version 5.1.2600]
    Running From: C:\SDFix

    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Checking Files :

    Trojan Files Found:

    C:\WINDOWS\index.html - Deleted

    Final Check :

    catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-06-20 19:16:21
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
    "p0"="C:\Program Files\DAEMON Tools\"
    "h0"=dword:00000000
    "khjeh"=hex:c2,fb,61,a1,d3,95,ca,a6,05,e9,47,76,bf,3b,c3,bb,f5,1d,8a,e2,42,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
    "a0"=hex:20,01,00,00,1a,3b,96,dd,43,65,67,d7,ee,ca,44,ad,2a,f1,9c,a4,1c,..
    "khjeh"=hex:77,5e,6e,e6,cc,99,d7,62,14,bf,d1,8e,9e,eb,47,8c,90,fc,d1,49,c9,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
    "khjeh"=hex:a0,50,c9,b6,e9,d3,a2,b1,bf,d0,3a,03,a4,c3,7d,90,74,64,13,03,df,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
    "khjeh"=hex:04,89,f2,50,f2,58,35,23,6f,1f,06,fa,6b,5c,4b,3d,dc,9e,13,b5,33,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
    "khjeh"=hex:ac,27,c6,17,c0,4a,65,2e,52,08,95,2a,47,95,fe,5d,6a,17,1a,5f,5b,..
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
    "s1"=dword:2df9c43f
    "s2"=dword:110480d0
    "h0"=dword:00000001

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
    "p0"="C:\Program Files\DAEMON Tools\"
    "h0"=dword:00000000
    "khjeh"=hex:c2,fb,61,a1,d3,95,ca,a6,05,e9,47,76,bf,3b,c3,bb,f5,1d,8a,e2,42,..

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
    "a0"=hex:20,01,00,00,1a,3b,96,dd,43,65,67,d7,ee,ca,44,ad,2a,f1,9c,a4,1c,..
    "khjeh"=hex:77,5e,6e,e6,cc,99,d7,62,14,bf,d1,8e,9e,eb,47,8c,90,fc,d1,49,c9,..

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
    "khjeh"=hex:a0,50,c9,b6,e9,d3,a2,b1,bf,d0,3a,03,a4,c3,7d,90,74,64,13,03,df,..

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
    "khjeh"=hex:04,89,f2,50,f2,58,35,23,6f,1f,06,fa,6b,5c,4b,3d,dc,9e,13,b5,33,..

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
    "khjeh"=hex:ac,27,c6,17,c0,4a,65,2e,52,08,95,2a,47,95,fe,5d,6a,17,1a,5f,5b,..
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
    "p0"="C:\Program Files\DAEMON Tools\"
    "h0"=dword:00000000
    "khjeh"=hex:c2,fb,61,a1,d3,95,ca,a6,05,e9,47,76,bf,3b,c3,bb,f5,1d,8a,e2,42,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
    "a0"=hex:20,01,00,00,1a,3b,96,dd,43,65,67,d7,ee,ca,44,ad,2a,f1,9c,a4,1c,..
    "khjeh"=hex:77,5e,6e,e6,cc,99,d7,62,14,bf,d1,8e,9e,eb,47,8c,90,fc,d1,49,c9,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
    "khjeh"=hex:a0,50,c9,b6,e9,d3,a2,b1,bf,d0,3a,03,a4,c3,7d,90,74,64,13,03,df,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
    "khjeh"=hex:04,89,f2,50,f2,58,35,23,6f,1f,06,fa,6b,5c,4b,3d,dc,9e,13,b5,33,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
    "khjeh"=hex:ac,27,c6,17,c0,4a,65,2e,52,08,95,2a,47,95,fe,5d,6a,17,1a,5f,5b,..
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
    "p0"="C:\Program Files\DAEMON Tools\"
    "h0"=dword:00000000
    "khjeh"=hex:c2,fb,61,a1,d3,95,ca,a6,05,e9,47,76,bf,3b,c3,bb,f5,1d,8a,e2,42,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
    "a0"=hex:20,01,00,00,1a,3b,96,dd,43,65,67,d7,ee,ca,44,ad,2a,f1,9c,a4,1c,..
    "khjeh"=hex:77,5e,6e,e6,cc,99,d7,62,14,bf,d1,8e,9e,eb,47,8c,90,fc,d1,49,c9,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
    "khjeh"=hex:a0,50,c9,b6,e9,d3,a2,b1,bf,d0,3a,03,a4,c3,7d,90,74,64,13,03,df,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
    "khjeh"=hex:04,89,f2,50,f2,58,35,23,6f,1f,06,fa,6b,5c,4b,3d,dc,9e,13,b5,33,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
    "khjeh"=hex:ac,27,c6,17,c0,4a,65,2e,52,08,95,2a,47,95,fe,5d,6a,17,1a,5f,5b,..

    scanning hidden registry entries ...

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D58D1DA8-8627-E12A-CDEE-90E322F20B12}]
    "abcldaggfohelnlbeoijeomdnhdcicbdle"=hex:66,62,63,6c,69,70,64,6d,6d,68,6d,61,65,6d,6d,70,61,63,6d,6a,6c,..
    "bbcldaggfohelnlbeonjnahngndalhjicfkn"=hex:61,62,68,69,68,63,66,64,66,6d,63,66,6d,68,66,6d,68,63,6b,66,67,..

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0


    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\EA Games\\Battlefield 1942\\BF1942.exe"="C:\\Program Files\\EA Games\\Battlefield 1942\\BF1942.exe:*:Enabled:BF1942"
    "C:\\Program Files\\EA Games\\Battlefield Vietnam\\BfVietnam.exe"="C:\\Program Files\\EA Games\\Battlefield Vietnam\\BfVietnam.exe:*:Enabled:BfVietnam"
    "C:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"="C:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
    "C:\\Program Files\\Electronic Arts\\The Lord of the Rings, The Rise of the Witch-king\\game.dat"="C:\\Program Files\\Electronic Arts\\The Lord of the Rings, The Rise of the Witch-king\\game.dat:*:Enabled:The Lord of the Rings, The Rise of the Witch-king"
    "C:\\Program Files\\Team17 Software Ltd\\Worms Forts Under Siege\\WF.exe"="C:\\Program Files\\Team17 Software Ltd\\Worms Forts Under Siege\\WF.exe:*:Enabled:WF"
    "C:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"="C:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe:*:Enabled:Company of Heroes - Opposing Fronts"
    "C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
    "C:\\Program Files\\The Creative Assembly\\Rome - Total War\\RomeTW.exe"="C:\\Program Files\\The Creative Assembly\\Rome - Total War\\RomeTW.exe:*:Enabled:Rome: Total War"
    "C:\\Program Files\\Port Royale\\PortRoyale.exe"="C:\\Program Files\\Port Royale\\PortRoyale.exe:*:Enabled:Port Royale"
    "C:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Railroads!\\RailRoads.exe"="C:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Railroads!\\RailRoads.exe:*:Enabled:Sid Meier's Railroads!"
    "C:\\Program Files\\EA Games\\MOHAA\\Mohaa.exe"="C:\\Program Files\\EA Games\\MOHAA\\Mohaa.exe:*:Enabled:Medal of Honor Allied Assault(tm)"
    "C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"="C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
    "C:\\Program Files\\The Creative Assembly\\Rome - Total War\\rometw-alx.exe"="C:\\Program Files\\The Creative Assembly\\Rome - Total War\\rometw-alx.exe:*:Enabled:Rome: Total War - Alexander"
    "C:\\Program Files\\Xfire\\Xfire.exe"="C:\\Program Files\\Xfire\\Xfire.exe:*:Enabled:Xfire"
    "C:\\Program Files\\BitComet\\plugin_emule\\plugin_eMule.exe"="C:\\Program Files\\BitComet\\plugin_emule\\plugin_eMule.exe:*:Enabled:eMule plugin host for BitComet"
    "C:\\Program Files\\Hamachi\\hamachi.exe"="C:\\Program Files\\Hamachi\\hamachi.exe:*:Enabled:Hamachi Client"
    "C:\\Program Files\\D-Link\\AirPlus G\\AirGCFG.exe"="C:\\Program Files\\D-Link\\AirPlus G\\AirGCFG.exe:*:Enabled:D-Link AirPlus Utility"
    "C:\\Program Files\\Paradox Interactive\\Europa Universalis III\\eu3game.exe"="C:\\Program Files\\Paradox Interactive\\Europa Universalis III\\eu3game.exe:*:Enabled:Europa Universalis III"
    "C:\\Program Files\\Vietcong2\\vietcong2.exe"="C:\\Program Files\\Vietcong2\\vietcong2.exe:*:Enabled:Vietcong 2"
    "C:\\Documents and Settings\\Ste\\My Documents\\LimeWire\\LimeWire.exe"="C:\\Documents and Settings\\Ste\\My Documents\\LimeWire\\LimeWire.exe:*:Disabled:LimeWire"
    "C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
    "C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
    "C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
    "C:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"="C:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe:*:Enabled:LaunchPad"
    "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
    "C:\\Program Files\\Flying Lab Software\\Pirates of the Burning Sea\\PlayPOTBS.exe"="C:\\Program Files\\Flying Lab Software\\Pirates of the Burning Sea\\PlayPOTBS.exe:*:Enabled:Pirates of the Burning Sea"
    "C:\\Program Files\\Flying Lab Software\\Pirates of the Burning Sea\\PotBS.exe"="C:\\Program Files\\Flying Lab Software\\Pirates of the Burning Sea\\PotBS.exe:*:Enabled:PotBS"
    "C:\\Program Files\\Westwood Chat\\WCHAT.DAT"="C:\\Program Files\\Westwood Chat\\WCHAT.DAT:*:Enabled:Westwood Online for Windows"
    "C:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm)\\RA95.EXE"="C:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm)\\RA95.EXE:*:Enabled:RA95"
    "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
    "C:\\Program Files\\SSI\\Close Combat Invasion Normandy\\CC5.exe"="C:\\Program Files\\SSI\\Close Combat Invasion Normandy\\CC5.exe:*:Enabled:Close Combat(tm)V: Invasion Normandy"
    "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
    "C:\\Program Files\\EA Games\\Battlefield 2\\BF2.exe"="C:\\Program Files\\EA Games\\Battlefield 2\\BF2.exe:*:Enabled:Battlefield 2"
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
    "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
    "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
    "C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"="C:\\Program Files\\AVG\\AVG8\\avgnsx.exe:*:Enabled:avgnsx.exe"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    Remaining Files :


    File Backups: - C:\SDFix\backups\backups.zip

    Files with Hidden Attributes :

    Sun 15 Jun 2008 1,580,208 ..SH. --- "C:\WINDOWS\system32\ummgfytf.tmp"
    Sat 29 Sep 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
    Fri 6 Aug 2004 1,949,696 A..HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\launcher.exe"
    Fri 6 Aug 2004 53,760 A..HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\mnyinsta.dll"
    Sat 12 Jun 2004 94,208 A..HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\RmvSuite.exe"
    Sat 3 Jul 2004 35,328 A..HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\setuplng.dll"
    Sat 22 Nov 2003 20,480 A..HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\unregwtr.exe"
    Mon 1 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
    Fri 9 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\BIT3.tmp"
    Sat 3 Sep 2005 4,348 A..H. --- "C:\Documents and Settings\Ste\My Documents\My Music\License Backup\drmv1key.bak"
    Sat 3 Sep 2005 20 A..H. --- "C:\Documents and Settings\Ste\My Documents\My Music\License Backup\drmv1lic.bak"
    Sat 3 Sep 2005 400 A..H. --- "C:\Documents and Settings\Ste\My Documents\My Music\License Backup\drmv2key.bak"
    Sat 3 Sep 2005 1,536 A..H. --- "C:\Documents and Settings\Ste\My Documents\My Music\License Backup\drmv2lic.bak"

    Finished!

    and the Hijackthis log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:23:10 PM, on 20/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
    O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'c:\program files\webhancer\programs\webhdll.dll' missing
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
    O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00B0AFA.dat
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 7222 bytes


    done and done, next?Open Hijackthis and select Do a system scan only then place a check mark next to:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Close all windows and click Fix checked.

    Exit Hijackthis and then run CCleaner.

    ----------

    A malicious .DLL file is disrupting the LSP chain on your computer. We need to get rid of it.

    • Please download LSPFix
    • Run the LSPFix.exe that you have just finished downloading.
    • Check the I know what I'm doing box.
    • In the Keep box you should see one or more instances of wsock3.dll.
    • Select every instance of webhdll.dll and move each one to the Remove box by clicking the >> button.
    • When you are done click Finish>>.
    .
    Restart the computer.

    If needed see Using LSP-Fix to remove Spyware & Hijackers for more detailed instructions.

    ----------

    I'm pretty sure there is a rootkit involved as well so we need to have a closer look.

    Download Combofix by SUBS from one of the below links.

    Important! Combofix.exe MUST be saved to and ran from the Desktop.
    • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
    • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
      • Click this link to see a list of security programs that should be disabled and how to disable them.
      • If yours is not listed and you don't know how to disable it, please ask.
    • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
    • Double click combofix.exe & follow the prompts.
      • Choose Yes to accept the Disclaimers.
    • When finished, it will produce a log for you.
    • Post that log in your next reply.
    Warning: Do not mouseclick Combofix's window while it is running. That may cause it to stall
    • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
    • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
    If needed, see this Combofix tutorial with screenshots that will detail more thoroughly the downloading and running of Combofix.

    ----------

    Next post add
    Combofix log
    I want to learn this problem because i also incur this in try to call computer technician.


    _________________
    Thermostat
    2933.

    Solve : What are some good tools??

    Answer»

    What are some good TOOLS to REMOVE viruses and trojans and spyware ect? Not looking for the actual protection but the removal.How can you have removal without protection?

    Is there something you want to remove now?

    Are you looking for free antivirus?I have a LOT of computers I'm working on that have viruses worms ect... on them that I first wanted to remove them before I put the protection on. So I was wondering what were some good removal tools for that kind of stuff?If you go ahead and install a free antivirus (AVG Free is highly recommended in the forums), it will SCAN your computer, find all the malware and it should get rid of them.

    However, you can follow these instructions but you will have to do it for every computer.
    Avast is also a good one to use, I personally LIKE it better then avg. But thats for you to decide.Quote

    I first wanted to remove them before I put the protection on
    It's the other way around.Quote from: Broni on June 30, 2008, 10:37:30 PM
    Quote
    I first wanted to remove them before I put the protection on
    It's the other way around.
    Yeah. That's what I meant. *Argh Jet Lag*Eaxtly
    2934.

    Solve : Downloaded something bad from Isohunt...?

    Answer»

    Good, but we're not done here, yet.
    At least, you're able to work in Normal Mode, now.
    However, some INFECTIONS won't show in Safe Mode, so we have to re-run couple of programs.
    Re-run Malwarebytes. Post its log.
    When done, re-run HijackThis, and post its log.First log:

    Malwarebytes' Anti-Malware 1.18
    Database version: 895

    2:57:25 PM 6/28/2008
    mbam-log-6-28-2008 (14-57-21).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 95198
    Time elapsed: 35 MINUTE(s), 11 second(s)

    Memory Processes Infected: 0
    Memory MODULES Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 4

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Documents and Settings\owner\Application Data\Desktopicon\eBayShortcuts.exe (Trojan.Agent) -> No action taken.
    C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP99\A0028502.dll (Trojan.Vundo) -> No action taken.
    C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP99\A0028503.dll (Trojan.Vundo) -> No action taken.
    C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP99\A0028504.dll (Trojan.Vundo) -> No action taken.
    hjtlog:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:01:41 PM, on 6/28/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\Program Files\Common Files\Virtual Token\vtserver.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\TPHDEXLG.EXE
    C:\WINDOWS\system32\TpKmpSVC.exe
    C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\IBM ThinkVantage\Common\SCHEDULER\tvtsched.exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    C:\Program Files\ThinkVantage\AMSG\Amsg.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe
    C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\IBM ThinkVantage\Client Security Solution\pwmgr.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcMurocHlpr.exe
    C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
    C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.asu.edu/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: (no name) - {A40C8CFE-B3A1-4431-B096-B8845A9BC573} - C:\WINDOWS\system32\yayyvuUn.dll (file missing)
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
    O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\ThinkVantage Fingerprint Software\ctlcntr.exe" /startup
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [cssauth] "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" silent
    O4 - HKLM\..\Run: [PDService.exe] "C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe"
    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
    O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKCU\..\Run: [amsg] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
    O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
    O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
    O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
    O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [JAVA_IBM] Java (IBM)
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1206561896640
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Ltd. - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
    O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
    O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
    O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
    O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
    O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
    O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe

    --
    End of file - 14176 bytes
    BumpYour Malwarebytes log shows "No action taken" after each line. You either posted the log from before the scan, or you did something wrong.
    Please, repost.

    No reason for "bump". We're all volunteers here. We have to work, eat, sleep, take care of kids, and kiss girlfriend/wife, once in a while. Quote from: Broni on June 28, 2008, 09:01:51 PM

    Your Malwarebytes log shows "No action taken" after each line. You either posted the log from before the scan, or you did something wrong.
    Please, repost.

    No reason for "bump". We're all volunteers here. We have to work, eat, sleep, take care of kids, and kiss girlfriend/wife, once in a while.

    I fixed the problems after i copied the log, ill re-run it and post itSounds good.
    ...and after you post new Malwarebytes log, I'll need fresh HJT log.Malware log:
    Said no malicious files found

    Malwarebytes' Anti-Malware 1.18
    Database version: 895

    8:57:05 PM 6/28/2008
    mbam-log-6-28-2008 (20-57-05).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 95408
    Time elapsed: 30 minute(s), 10 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    HJT LOG:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:58:22 PM, on 6/28/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\Program Files\Common Files\Virtual Token\vtserver.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\TPHDEXLG.EXE
    C:\WINDOWS\system32\TpKmpSVC.exe
    C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    C:\Program Files\ThinkVantage\AMSG\Amsg.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe
    C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\IBM ThinkVantage\Client Security Solution\pwmgr.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcMurocHlpr.exe
    C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
    C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DfrgNTFS.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.asu.edu/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: (no name) - {A40C8CFE-B3A1-4431-B096-B8845A9BC573} - C:\WINDOWS\system32\yayyvuUn.dll (file missing)
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
    O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\ThinkVantage Fingerprint Software\ctlcntr.exe" /startup
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [cssauth] "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" silent
    O4 - HKLM\..\Run: [PDService.exe] "C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe"
    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
    O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKCU\..\Run: [amsg] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
    O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
    O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
    O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
    O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [JAVA_IBM] Java (IBM)
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1206561896640
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Ltd. - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
    O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
    O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
    O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
    O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
    O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
    O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe

    --
    End of file - 14408 bytes
    Is your Norton subscription current, and is it up to date? It seems like it's only partially running.Yes its up to date and i dont know about the partially running. But ive been reading on here that yall suggest to use another anti virus like AVT8 or something along those lines. did the logs look ok? Is the computer still infected?*** You need to update Java:
    http://java.sun.com/javase/downloads/index.jsp
    Java Runtime Environment (JRE) 6 Update 6
    Uninstall all previous versions of Java through Add\Remove.

    1. Print this post out, since you won't have an access to it, at some point.

    2. Close all windows, except for HijackThis.

    3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

    - O2 - BHO: (no name) - {A40C8CFE-B3A1-4431-B096-B8845A9BC573} - C:\WINDOWS\system32\yayyvuUn.dll (file missing)
    - *O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    - *O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    - *O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    - *O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    - *O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    - O4 - Global Startup: Bluetooth.lnk = ?
    - O4 - Global Startup: Digital Line Detect.lnk = ?
    - *O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    - O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present (checkmark this entry if you did not activate the 'Lock homepage from changes' option in some kind of anti-spyware tool)
    - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    4. Click on Fix checked button.

    5. Restart computer.

    6. Post new HijackThis log.Got the new java and here the HJT:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:14:25 PM, on 6/30/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\Program Files\Common Files\Virtual Token\vtserver.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\TPHDEXLG.EXE
    C:\WINDOWS\system32\TpKmpSVC.exe
    C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
    C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
    C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcMurocHlpr.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    C:\Program Files\ThinkVantage\AMSG\Amsg.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe
    C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\IBM ThinkVantage\Client Security Solution\pwmgr.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.asu.edu/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
    O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\ThinkVantage Fingerprint Software\ctlcntr.exe" /startup
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [cssauth] "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" silent
    O4 - HKLM\..\Run: [PDService.exe] "C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe"
    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
    O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [amsg] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
    O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
    O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1206561896640
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Ltd. - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
    O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
    O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
    O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
    O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
    O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
    O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe

    --
    End of file - 13209 bytes
    Your computer is clean

    1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
    Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
    Run CCleaner.

    2. Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    3. Restart computer.

    4. Turn System Restore on.

    5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

    6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

    7. Let me know, how your computer is doing.
    2935.

    Solve : Computer Hang?

    Answer»

    Let's do some cleanup and also let me know how the computer is now.

    Let's clear out the programs we've been using to clean up your computer, they are not suitable for
    general malware removal and could cause damage if launched accidentally. These steps will also HELP secure the work you have done.
    .

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    .
    The above procedure will:
    • Delete:
      • ComboFix and its associated files and folders.
      • VundoFix backups, if present
      • The C:\Deckard folder, if present
      • The C:_OtMoveIt folder, if present
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean RESTORE Point.
      .
      ----------

      Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

      1. Double click OTMoveIt2.exe to launch it.
      Vista users right click and choose Run As Administrator
      2. Click on the CleanUp! button.
      3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
      4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
      5. Once complete exit out of OTMoveIt2

      ----------

      Use the Secunia Software Inspector to check for out of DATE software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      GO to Microsoft Windows Update and get all critical updates.



      How is everything now?


      Hi evilfantasy,

      I have done all the action as instructed by you.
      Now my PC is back to normal.
      Once again thanks ALOT for your expertise help.
      Glad it's back to normal. Let us know if anything else comes up.....
      2936.

      Solve : How do I report a possible virus hosting website??

      Answer»

      Okay, I came accross this by complete accident.
      Here is the link but I dont think many people will want to click on it:
      Code: [SELECT]http://www.subculture.com/backdoor.html
      You cant actually get a virus just by clicking on it but adult material came up on it also.
      It keeps RELOADING the page and I think its CONNECTED to the LOVE-LETTER.TXT.vbs virus.

      I was wondering how to report a website like this.

      Thanks.

      Link editedIf you GOT the URL VIA e-mail report to http://www.antiphishing.org/report_phishing.html but you may want to report it anyway even if you didn't get it from e-mail.
      If you use something like trustwatch you can report to them: http://www.trustwatch.com/index.html
      You can report to the FBI at the Internet Crime Center http://www.ic3.gov/complaint/


      thesecdude -www.security-tech-reviews.com

      2937.

      Solve : I WOULD LIKE TO ASK A QUESTION ONLY A VIRUS WOULD EXPECT?

      Answer»

      i TOOK a test on this site i did pretty good actually excellent you wouldn't know it but
      one of the questions was could you get a virus through a scanner. i know from the med field that a virus needs a host(a live host) that is specific for it to survive. i chose no and the choice was correct.
      i have a question though and the reason why is
      i used to never use my d drive for anything
      i used to never use a usb mem slap stick either (long ago in college)
      recently i have been babbling the satanic verses of the underground computer programs of windows with my mouse (my goal is to start using the keyboard and some commands) during that time i have managed to loose contact with my computer on serveral occasions. i also use the mem stick the same way.
      now the question: i got a virus, trojan, a flea, a worm, a roach, in my computer i had downloaded limewire, NEW explorer, mozilla, FOXFIRE, in a short period of time. i noticed if i used explorer the pops happened if i used foxfire it didn.t then it started happening with both. i tried to fight it with my bare hands for a few days no avail (almost)
      before i deleted the c drive to start over i used the mem stick to save the windows program because i wanted to study these invaders. so now i have them quarintined in two FOLDERS and some other progrms
      could i freely tear them a new DNA without effecting my computer.
      how would you and could you explain how to open one of those programs
      i can open the ones that look like notepad and it tells you everything it did and how it found you and what it was looking, waiting, and exspecting.
      i am as confused as virus in steril file.
      i am as confused as trojan at the front door
      if you have any idea what i might be trying to ask can you GIVE an attempt to aswer then we might be able to narrow down a pattern.
      thank you so much
      ruby


      2938.

      Solve : Trojan.ZipCodec.dsc?

      Answer»

      hello,
      while doing "disc cleanup" the above(subject) appeared. i googled it and arrived at "bleepingcomputer.com".
      he said that strange things were happening on his computer. the answer to his post was to reboot in safe mode then double-click SmitfraudFix.exe - #2clean - enter. a Registry cleaning prompt will appear-do you want to clean? - yes - enter - in order to rremove the Desktop background and clean registry keys associated with the infection. then the tool would check to see if wininet.dll is infected. then restart.

      although the kinds of things that were happening to him weren't happening to me - just the fact that it showed up in my "disc cleanup" makes me question it. should i follow the posted directions, too?

      i'm a neophyte and anything i can do to help save my pc, i'll do.

      thank you.

      Following directions in other help threads can potentially damage your PC.

      Start HERE

      Once complete post the logs in this thread and a Malware Removal Specialist will be along to help.dear evilfantasy,
      thank you so much for the detailed info.
      before i start to follow your directions i did a "IPC"search" of my pc. i was going to scan/send to you, but i received a message that the file was too big. that is because the search was superimposed on my desktop and i don't know how to remove the desktop background & just send the search info.
      i will give it to you in this reply and (if you will) you can tell me if i need to proceed w/ your directions, please.
      these were in my "search - all files/folders":
      Trojan.Zipcodec.dsc,Trojan.ZipCodec.prf,Zipclix.dsc,Zipclix.prf,ipcfg.xml,ipconf.tsp,ipconfig.exe,wmipcima.dll,wmipcima.mfl,wmipcima.mof,SNIPCI.HTM,SNIPCI.TXT.

      these are repeated three times on the searchpage.

      thank youYou need to follow my instructions. I know how to read the logs from the scans and am not sure what I would do with the IPC Search results.ok, how do i do the scans?Quote from: evilfantasy on June 24, 2008, 07:09:20 PM

      Start HERE


      dear evilfantasy,

      mea culpa! incorrect word. how do i get a "log"?

      thnx.

      All of the direction sare in the link I gave. Read them and it will EXPLAIN everything.

      Is English your first language?SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 06/29/2008 at 00:47 AM

      Application Version : 4.15.1000

      Core Rules Database Version : 3493
      Trace Rules Database Version: 1484

      Scan type : Complete Scan
      Total Scan Time : 00:36:19

      Memory items scanned : 367
      Memory threats detected : 0
      Registry items scanned : 5417
      Registry threats detected : 0
      File items scanned : 50086
      File threats detected : 0
      Malwarebytes' Anti-Malware 1.19
      Database version: 901
      Windows 5.1.2600 Service Pack 3

      1:32:58 AM 6/29/2008
      mbam-log-6-29-2008 (01-32-58).txt

      Scan type: Quick Scan
      Objects scanned: 40902
      Time elapsed: 4 minute(s), 7 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)
      gfile of Trend Micro HijackThis v2.0.2
      Scan saved at 2:35:34 AM, on 6/29/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
      C:\WINDOWS\System32\DLA\DLACTRLW.EXE
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\WINDOWS\stsystra.exe
      C:\Program Files\Lexmark 3300 Series\lxccmon.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
      C:\Program Files\Dell Support\DSAgnt.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\Digital Line Detect\DLG.exe
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
      C:\WINDOWS\system32\lxcccoms.exe
      C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\sniper.exe\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

      http://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

      Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -

      C:\WINDOWS\System32\DLA\DLASHX_W.DLL
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

      Files\Java\jre1.6.0_06\bin\ssv.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

      files\google\googletoolbar2.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program

      Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
      O2 - BHO: CutePDF Form Filler - {D41289F2-69C6-417B-897E-C653D677CBAF} - (no file)
      O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter

      Edition\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [LXCCCATS] rundll32

      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,[emailprotected]
      O4 - HKLM\..\Run: [lxccmon.exe] "C:\Program Files\Lexmark 3300 Series\lxccmon.exe"
      O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe"

      -scheduler
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

      /S
      O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
      O4 - HKCU\..\Run: [DellSupport-] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User

      'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

      (User 'Default user')
      O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
      O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

      Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

      Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

      Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

      C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

      Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

      Files\Messenger\msmsgs.exe
      O15 - TRUSTED Zone: *.stumbleupon.com
      O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -

      http://support.dell.com/systemprofiler/SysPro.CAB
      O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office GENUINE Advantage Validation Tool) -

      http://go.microsoft.com/fwlink/?linkid=58813
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

      http://go.microsoft.com/fwlink/?linkid=48835
      O16 - DPF: {3BA3B159-7533-4F96-A2CE-EE5894BBD3D5} (Scanner.SysScanner) -

      http://i.dell.com/images/global/js/scanner/SYSSCANNER.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -

      http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

      http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132223658171
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

      http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132223807796
      O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) -

      http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37440.cab
      O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -

      http://www.crucial.com/controls/cpcScanner.cab
      O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) -

      https://ediagnostics.lexmark.com/serval.cab
      O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) -

      http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
      O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) -

      http://by107fd.bay107.hotmail.msn.com/activex/HMAtchmt.ocx
      O17 - HKLM\System\CCS\Services\Tcpip\..\{4BCCA856-D6C9-4042-9F69-556AA6C6A331}: NAMESERVER =

      68.94.156.1,68.94.157.1
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Program

      Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
      O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google

      Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common

      Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner -

      C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
      O23 - Service: McAfee SpamKiller Server (MskService) - Unknown owner -

      C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe (file missing)
      O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio

      Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
      O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file

      missing)
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -

      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      O24 - Desktop Component 0: (no name) - http://static.dropline.net/cats/images/zoom-zoom.jpg
      O24 - Desktop Component 1: (no name) - http://www.japanspecial.com/w-hagoromo-d21.jpg

      --
      End of file - 9758 bytes
      Open hijackthis and select do a system scan only then place a check mark next to the following entries.

      O2 - BHO: CutePDF Form Filler - {D41289F2-69C6-417B-897E-C653D677CBAF} - (no file)
      O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

      Now close all windows and click Fix checked.

      Exit Hijackthis and run CCleaner.

      ---------

      Looking over your log, it seems you don't have any evidence of an anti-virus software.

      Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network.Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories.

      • Avast! Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
      • AVG Free Edition - Free edition of the AVG anti-virus program for Windows.
      • AntiVir Personal - Free anti-virus software for Windows. Detects and removes more than 50,000 viruses. Free support.
      .
      It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

      ----------

      What problems are you having with the PC?
      dear evilfantasy,

      as i stated principally - i'm a neophyte and when something new/odd turns up someplace i don't expect it
      i have a tendency to panic.
      i can't afford a new pc, but with your stellar assistance i don't have to worry about it.

      thank you. i am truly appreciative !!!

      AND

      etiam, english est meus primoris lingua. Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      -----

      Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

      -----

      Learn more about how to protect yourself while on the internet.

      So how did I get infected in the first place? by Tony Klien.

      How to prevent Malware by Miekiemoes.
      2939.

      Solve : Actually this is an old Topic-Windows Security Center?

      Answer»

      I don't understand what you mean. What are you doing when it says this?I am RUNNING the Secunia: Online Software Inspector
      This is what I Mean:
      Secunia: Online Software Inspector
      The Secunia Online Software Inspector will inspect your operating system and software for INSECURE versions and missing security UPDATES. A default inspection normally lasts 5-40 seconds, while a thorough inspection may take several minutes. Note: If you have anti-virus software or similar enabled, an inspection may increase significantly in duration.
      Detection Statistics:

      0 Applications Detected in Total
      0 Insecure Versions Detected
      0 Secure Versions Detected

      Running For:
      0 minutes, 0 seconds

      Errors Detected:
      0 Errors Detected
      Enable thorough system inspection
      Enable the Secunia Online Software Inspector to search for software installed in non-default locations.

      Did you find this scan useful?
      Then you might find it even more useful to run our powerful installable programs, capable of conducting very thorough and indepth scans.
      Personal EDITION (free) | Business Edition


      Status / Currently Processing:

      There might be problems loading the Java Applet in your browser.




      Applications / Result Version Detected Status





      ME AGAIN: It is the page where the Start and Stop Buttons are at.
      It looks the same after I hit start as it did before I hit start.
      There is NO Detection Statistics, NO Running For time , and
      NO Applications/Results ect. I don't know if anything even
      happened when I clicked the Start Button. Except I now have a Java
      Icon on the Task Bar.



      Are you using Internet Explorer?Yes I am using Internet ExplorerTry using the personal psi. https://psi.secunia.com/NO GO.
      I got a Internet Explorer message, when 30% of download was completed that said:

      'Internet Explorer cannot download PSISetup.exe from psi.secunia.com.
      The server returned an INVALID or unrecognized response.'You can skip that step. Just be sure to visit Windows update.OKTHANK YOU, EVIL!!!!! I think you got it fixed. Things are running very nicely. And thank you for taking the time to help others. I wish I was smart enough to do the same. You've saved my sanity(what's left anyway).
      Thank You agin,
      Bluerose14

      2940.

      Solve : Here we go again..possible virtumonde?

      Answer»

      I have had this problem before and fixed it but this time I'm beat!
      Here's the problem....
      Missing icons ,task bar and unable to update microsoft.
      We had a friend borrow our pc when he came over to our house this past weekend and he goes to myspace and facebook.
      My computer was fine except the updates was disabled and I could not start it up again so.. I researched and tried to fix it. The pc started downloading something strange and my Anti Vir went nuts. The pc froze and I had to reboot. When it rebooted the icons and task bar were missing. The only thing showing on my desktop was the wallpaper. I checked Safe Mode and it was the same there as well.
      I could not restore because it had mysteriously been turned off.
      I ran Spybot search and Destroy and it got rid of some things. I reran spybot and it got rid of alot of things. I ran Lavasoft anti spyware and it found nothing. I ran Antivir and it found nothing. I downloaded Spyware doctor and it found Virtumonde. It could not eliminate it so I downloaded Trojan Remover and it got rid of some things but still no icons etc. I ran SD fix ....nothing
      I did the sfc/ scannow....nothing
      I ran the kelly's corner fixes...nothing
      I ran vundofix.....it found nothing
      I checked on msconfig....nothing
      ran A squared.....nothing
      Repaired windows XP..... now I cannot see my hidden files and I can only access things with ctrl-alt-delete (task manager)
      Ok... I am guessing you will tell advise me to reformat but I am hoping to avoid this because it is a pain to re set up ATT DSL
      I have not run combofix due to the pc will give me an error message and not allow it.
      I keep getting corrupt file error messages everytime I run anything that scans it for spyware or virusware....

      Ok I'm out of ideas...need help please..

      Also I am on my work pc so I will not be able to post a hijack log til this evening

      Thanks..
      ~Bettina~

      Try renaming Combofix and then running it.

      Download and rename Combofix by sUBs from one of the below links.
      (Try all three if necessary)

      Link #1
      Link #2

      Combofix MUST be saved to the desktop.

      STOP all of your antivirus, antispyware, and other protection monitoring programs
      Click this link to see a list of security programs that should be disabled and how to disable them.

      Close all other BROWSER windows.

      Now right click on the combofix.exe icon on your Desktop and select Rename. Rename it to cf.exe This may help Combofix to run where certain malware attempts to block the original file name from running.

      Open task Manager and copy the below text into the New Task window.

      "%userprofile%\desktop\cf.exe" /killall

      Click the OK button and Combofix will begin to run and do the following.

      - It will terminate some running processes.
      - It will set your clock to a 24 hour setting (will be restored to normal when finished running properly)
      - It will disconnect your PC from the internet. The connection is automatically restored before Combofix completes its run. If Combofix runs into DIFFICULTY and terminates prematurely, the connection can be manually restored by restarting your machine.
      - If malware is found, Combofix will reboot your PC automatically when finished with the scan. When your PC restarts and after you log BACK in, Combofix will finish running and create a log. Do not interrupt this process.

      - Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall.

      - Do not attempt to use the internet or run anything else while it is running as you will most likely interfere with what it needs to do.

      When finished, it will produce a log (C:\combofix.txt) for you.

      Post the contents of that log in your next reply.
      Update:

      The pc got so bad that I had to reformat and wipe it clean.
      My browser got hijacked by a Antivirus pro 2008 and it would not even let me go to any other site. So..after thinking a bit I reformatted. I have done lots of virus/spyware scans since reformatting and the pc is clean. I have not REINSTALLED all my other programs yet but plan on doing it soon. It is running on basic programs right now.
      Can the virus still be in my pc? I did not have restore on

      Thanks for all your help... A reformat should have wiped everything nasty off of the PC.

      Thanks for letting us know.

      2941.

      Solve : Error message when starting the computer!?

      Answer»

      Hi guys,

      I have been TALKING to one of the specialists in the Microsoft windows forums and they have recommended that i talk to a Malware removal specialist, they are almost certain that i have some bugs on my computer.

      Each time i start my computer it is asking me to restart so that updates can be installed - so i restart my computer and i still get the same message. I went into the control panel and checked my automatic updates and everything seems fine, only now i get that same message and also another message:


      error loading C:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL


      I have read through the list of requirements that is needed before i attempt to remove and infections on my computer and I am unsure about a few things. I am currently running Windows XP, service pack 2 home [/b]edition and I also have Norton internet security.

      Do I need to install AVG anti virus and if I do will it run alright with Norton still on my machine?

      It also tells me that i must have SP1a or higher - Do I need to install SP1a when i already have SP2?

      I would really appreciate any HELP you could give me on this issue

      Thanks
      Yeah MyWebSearch is a malware...
      Quote

      Do I need to install AVG anti virus and if I do will it run alright with Norton still on my machine?
      No. You can't run TWO antivirus programs.
      Quote
      Do I need to install SP1a when i already have SP2?
      No.

      Print these instructions out.

      1. Download SUPERAntiSpyware Free for Home Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
      * An icon will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "YES". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      PHYSICALLY DISCONNECT FROM THE INTERNET

      Restart computer in Safe Mode.
      To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

      * Open SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences button.
      * Click the Scanning Control tab.
      * Under Scanner Options make sure the following are checked (leave all others unchecked):
      o Close browsers before scanning.
      o Scan for tracking cookies.
      o Terminate memory threats before quarantining.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
      * On the left, make sure you check C:\Fixed Drive.
      * On the right, under "Complete Scan", choose PERFORM Complete Scan.
      * Click "Next" to start the scan. Please be patient while it scans your computer.
      * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to reboot, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      Post SUPERAntiSpyware log.

      RECONNECT TO THE INTERNET

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and follow the prompts to install the program.
      * At the end, be sure a checkmark is PLACED next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Download HijackThis:
      http://www.snapfiles.com/get/hijackthis.html
      Post HijackThis log.
      2942.

      Solve : how to find antivirus updates ip address??

      Answer»

      Hello,

      I am using macafee total protection for small business as an antivirus software for server and clients. Once in a while I do manual updates. My QUESTION is, how can I find the Ip address of the SITES that macafee USES to CONNECT for updates.I don't know, but why?

      2943.

      Solve : GOT cssrss.exe & winlogon.exe viruses?

      Answer»

      Computer : ZOOMSTORM
      PRO Intel (R) Celeron (R) CPU 430 1.80 GHZ
      1.00 GB
      System Type : 32 BIT operating system
      WINDOWS VISTA

      HI i have had this computer now for about 2 months i have AVG and Avira Anitvir personal. I have just downloaded spyware doctor but for same reason none of the anti virus sofeware find this VIRUS. The way i found out was looking at my task manager and saw cssrss.exe so looked this up on Google and it SAID it was very harmful to the computer and it has winlogon.exe normally with which i have found.

      I have try scanning the computer with everything but no joy. You have helped me out before with my sister computer had spme bad virus on it SO ONLY ONE PLACE I TRUST IN THIS MATTER IS HERE. Cos everything you have told me has worked

      SO PLEASE CAN YPU HELP ME OUT AGAIN BEFORE THIS VIRUS TAKES OVER MY COMPUTER

      THANK YOU SO MUCH

      JENZO

      Malwarebytes' Anti-Malware 1.19
      Database VERSION: 899
      Windows 6.0.6001 Service Pack 1

      22:21:15 28/06/2008
      mbam-log-6-28-2008 (22-21-15).txt

      Scan type: Quick Scan
      Objects scanned: 34526
      Time elapsed: 7 minute(s), 51 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)
      HERE IS A SYSTEM LOG

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:20:53, on 28/06/2008
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\System32\smss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\MICROSOFT Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Windows\system32\IoctlSvc.exe
      C:\Windows\system32\svchost.exe
      c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
      C:\Windows\system32\taskeng.exe
      c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\AVG\AVG8\avgtray.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Users\JENZO\Program Files\DNA\btdna.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Windows Media Player\wmpnetwk.exe
      C:\Program Files\BBC Alerts\BBC_Alerts.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\Spyware Doctor\pctsAuxs.exe
      C:\Program Files\Spyware Doctor\pctsSvc.exe
      C:\Program Files\Spyware Doctor\pctsTray.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Windows\system32\wbem\wmiprvse.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [Skytel] Skytel.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\JENZO\Program Files\DNA\btdna.exe"
      O4 - HKCU\..\Run: [BBC Alerts] "C:\Program Files\BBC Alerts\BBC_Alerts.exe"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: avgrsstx.dll
      O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

      --
      End of file - 7661 bytes
      The log is clean.
      I can see csrss.exe running, not cssrss.exe
      csrss.exe is legit Windows file.but when i run my task mananger is has cssrss.exs & winlogon.exe running.When i try 2 stop then i just doubles up so two are running then

      BUT i take your word for it everything is ok this site as alway sorted out my other viruses

      THANK YOU SO MUCH

      JENZO
      winlogon.exe is also legit Windows file, unless it's not located in C:\Windows\System32.
      Search your computer for it, and see where it's located.
      Can you post a screenshot, showing Task Manager with cssrss.exe running? There is only one "s" DIFFERENCE between legit, and bad file.

      2944.

      Solve : Malware Protector 2008 Attacked my PC...remnants remain?

      Answer»

      Hello this is my first post so excuse me if I don't included everything needed for a proper assessment.

      I was attacked by this Malware Protector Virus and I think I removed most of it by I still get that blue screen background when my computer reboots. Its got a yellow box in the middle that reads "Warning! Spyware Detected on you computer...etc."

      I'm not sure if there are any other issues at work silently that I'm not aware of so I just wanted the experts to take a look. I read a followed this post "Read this before requesting malware removal help "

      Here are my logs in this order

      SuperAntispyware log
      Malwarebytes' log
      Hijackthis log


      [recovering disk space -- attachment deleted by admin]You're running two antiviruses: Avast, and Norton. One has to go.
      If you decide to uninstall Norton, use this: http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039
      If you remove Norton, you have to turn Windows firewall on. LET me know.ok sorry i took so long to reply. I removed Norton by following your link, and turned on my windows firewall. I'm gonna NEED fresh HJT log.K here it is Thank you

      [recovering disk space -- attachment deleted by admin]1. Print this post out, since you won't have an access to it, at some point.

      2. Close all windows, except for HijackThis.

      3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

      - O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
      - *O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
      - *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      - *O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
      - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      - *O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      - O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
      - O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
      - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      - O4 - HKCU\..\Policies\Explorer\Run: [aigxz] C:\WINDOWS\system32\aigxz.exe
      - O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
      - O4 - HKUS\.DEFAULT\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'Default user')
      - O4 - Startup: gameutil.exe.lnk = ?
      - O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab
      - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


      4. Click on Fix checked button.

      5. Restart computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

      6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

      7. DELETE following files/folders (if present):

      - aigxz.exe file from C:\WINDOWS\system32
      - Symantec Shared folder from C:\Program Files\Common Files

      8. Restart in Normal Mode.

      9. Post new HijackThis log.






      WOW holy crap, ok after I restarted the first time from safe to normal mode I got a very serious looking blue screen that talked about a physical memory dump taking place and that it was successful. There was a technical issue number that read something like this

      ***Stop: 0x00000050 {and etc}

      and something about BIOS

      I guess I should have written down what I saw for a better explaination but I got really nervous and turned off my computer for fear of something HORRIBLE.

      But alas, it started up no problem this time and here is another HJT log.Invisible, I assume?...LOLinvisible haha i dont know this language!?!?Quote

      here is another HJT log
      Where?Oops here it is.

      [recovering disk space -- attachment deleted by admin]Your computer is clean

      1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
      Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
      Run CCleaner.

      2. Turn off System Restore:

      - Windows XP:
      1. Click Start.
      2. Right-click the My Computer icon, and then click Properties.
      3. Click the System Restore tab.
      4. Check "Turn off System Restore".
      5. Click Apply.
      6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
      7. Click OK.
      - Windows Vista:
      1. Click Start.
      2. Right-click the Computer icon, and then click Properties.
      3. Click on System Protection under the Tasks column on the left side
      4. Click on Continue on the "User Account Control" window that pops up
      5. Under the System Protection tab, FIND Available Disks
      6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
      7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
      8. Click OK

      3. Restart computer.

      4. Turn System Restore on.

      5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

      6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

      7. Let me know, how your computer is doing.

      THANK YOU SOOO MUCH, you guys are amazing!!You're very welcome
      Computer doing OK, I assume...?
      2945.

      Solve : Entry in Hijack log?

      Answer»

      That's how I got rid of them.
      Deckard's System Scanner v20071014.68
      Run by Dave on 2008-06-26 22:53:55
      Computer is in Normal Mode.
      --------------------------------------------------------------------------------



      -- HijackThis (run as Dave.exe) ------------------------------------------------

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:53:58 PM, on 26/06/2008
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\System32\smss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\Ati2evxx.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\Ati2evxx.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
      C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      C:\Program Files\ltmoh\ltmoh.exe
      C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
      C:\Program Files\Toshiba\SmoothView\SmoothView.exe
      C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
      C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
      C:\Program Files\ThreatFire\TFTray.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Windows\System32\spoolsv.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
      C:\Windows\ehome\ehtray.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Synaptics\SynTP\SynToshiba.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\agrsmsvc.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
      C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\rpcnet.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\ThreatFire\TFService.exe
      C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
      C:\Windows\system32\TODDSrv.exe
      C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
      C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
      C:\Windows\system32\conime.exe
      C:\Windows\system32\wuauclt.exe
      C:\Windows\system32\taskeng.exe
      C:\Users\Dave\Desktop\dss.exe
      C:\DOWNLO~1\Dave.exe
      C:\Windows\system32\wbem\wmiprvse.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,START Page = http://exclusive.aliant.net/home.jsp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
      O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
      O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
      O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
      O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
      O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
      O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
      O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\system32\rpcnet.exe
      O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
      O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
      O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
      O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
      O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
      O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
      End of FILE - 9819 bytes

      -- Files created between 2008-05-26 and 2008-06-26 -----------------------------

      2008-06-22 20:33:44 0 d-------- C:\Program Files\PSCS2
      2008-06-09 00:31:20 0 d-------- C:\Midi Files
      2008-06-08 16:18:21 0 d-------- C:\Program Files\Alwil Software
      2008-05-29 11:51:25 0 --a------ C:\Program Files\gditst
      2008-05-29 11:50:20 306688 --a------ C:\Windows\IsUninst.exe
      2008-05-26 13:26:31 0 d-------- C:\Program Files\SpeedFan


      -- Find3M Report ---------------------------------------------------------------

      2008-06-26 22:35:48 17408 --a------ C:\Windows\system32\rpcnetp.exe
      2008-06-26 22:35:45 47104 --a------ C:\Windows\system32\rpcnet.dll
      2008-06-26 22:32:49 0 d-------- C:\Program Files\Common Files\Symantec Shared
      2008-06-25 17:50:04 0 d-------- C:\Program Files\Java
      2008-06-25 17:46:25 0 d-------- C:\Program Files\Common Files
      2008-06-12 03:07:21 0 d-------- C:\Program Files\Windows Mail
      2008-06-11 20:44:13 0 d-------- C:\Program Files\NCH Swift Sound
      2008-06-03 12:20:03 17408 --a------ C:\Windows\system32\rpcnetp.dll
      2008-05-25 11:53:35 0 d-------- C:\Program Files\coolpro2
      2008-05-23 16:11:15 0 d-------- C:\Program Files\Apple Software Update
      2008-05-23 16:07:18 0 d-------- C:\Program Files\iTunes
      2008-05-23 16:07:12 0 d-------- C:\Program Files\iPod
      2008-05-12 22:27:48 0 d-------- C:\Program Files\QuickTime
      2008-05-12 22:05:52 0 d-------- C:\Users\Dave\AppData\Roaming\Apple Computer
      2008-05-12 22:04:32 0 d-------- C:\Program Files\Bonjour
      2008-05-12 22:02:07 0 d-------- C:\Program Files\Common Files\Apple
      2008-05-11 19:57:07 0 d-------- C:\Users\Dave\AppData\Roaming\Media Player Classic
      2008-05-11 11:48:20 0 d-------- C:\Program Files\Microsoft Silverlight
      2008-04-30 11:42:01 0 d-------- C:\Program Files\ThreatFire
      2008-04-17 14:14:53 31007 --a------ C:\Users\Dave\AppData\Roaming\UserTile.png
      2008-04-05 14:13:53 174 --ahs---- C:\Program Files\desktop.ini
      2008-04-01 00:49:06 47104 --a------ C:\Windows\system32\rpcnet.exe


      -- Registry Dump ---------------------------------------------------------------

      *Note* empty entries & legit DEFAULT entries are not shown


      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
      25/06/2008 05:50 PM34816--a------C:\Program Files\Java\jre6\bin\jp2ssv.dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [19/01/2008 04:38 AM]
      "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [10/11/2006 04:35 PM]
      "RtHDVCpl"="RtHDVCpl.exe" [09/08/2007 08:26 AM C:\Windows\RtHDVCpl.exe]
      "NDSTray.exe"="NDSTray.exe" []
      "SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [15/08/2007 04:31 AM]
      "LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [09/01/2007 03:23 AM]
      "TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [29/03/2007 10:39 AM]
      "HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [07/12/2006 04:49 PM]
      "SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [15/06/2007 09:01 PM]
      "00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [22/05/2007 04:32 PM]
      "Camera Assistant Software"="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" [22/05/2007 10:50 AM]
      "ThreatFire"="C:\Program Files\ThreatFire\TFTray.exe" [24/04/2008 07:52 PM]
      "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [06/12/2007 09:12 AM]
      "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 10:16 PM]
      "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [28/03/2008 11:37 PM]
      "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30/03/2008 10:36 AM]
      "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [15/05/2008 08:19 PM]
      "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [25/06/2008 05:50 PM]

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [19/01/2008 04:33 AM]
      "TOSCDSPD"="TOSCDSPD.EXE" []
      "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [19/01/2008 04:33 AM]
      "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43 AM]

      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
      Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 1:01:04 AM]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "ConsentPromptBehaviorAdmin"=2 (0x2)
      "EnableLUA"=0 (0x0)
      "EnableUIADesktopToggle"=0 (0x0)

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
      @="Service"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
      @="Driver"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
      @="Driver"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
      @="Volume shadow copy"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
      @="IEEE 1394 Bus host controllers"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
      @="SBP2 IEEE 1394 Devices"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
      @="SecurityDevices"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      LocalServicensi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient SstpSvc
      LocalSystemNetworkRestrictedhidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum


      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad7b7f86-0bc7-11dd-a878-00a0d198404c}]
      AutoRun\command- F:\LaunchU3.exe


      [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed COMPONENTS\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
      C:\Windows\system32\unregmp2.exe /ShowWMP

      [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
      %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



      -- End of Deckard's System Scanner: finished at 2008-06-26 22:54:38 ------------

      Everything looks OK. don't know why HJT is disappearing.

      * Puzzled...I'm going to load it again and see what happens overnight.It's been 24 hrs. and Hijack is still on my laptop. It must have been the remnants of Norton that was messing things up. Another knock against Norton.Strange but it may have been Norton.

      Is everything OK now?Yup, PURRING right along. Thanks

      2946.

      Solve : Not again...?

      Answer»

      AVG Free 8.0 just did a full system scan on my computer. After reading the total number of warnings, I'm worried. It says it found 24528 warnings, most of them are Adware.CoolWebSearch infections and tracking cookies, but I found one result called "Trojan.Zapchast".

      So my question to my heros at CH: Do I need to get help from a malware removal specialist?

      I don't want to have to wait another 3 hours to do a scan, so I'm going to remove all the unhealed infections, but I've got a list of infections AVG found.

      OS: Windows XP Home Edition SP2
      Antivirus: AVG Free 8.0
      Antispyware: AVG Free 8.0
      Firewall: COMODO Firewall PRO 3
      Browser: Mozilla Firefox 3

      Thanks!You can't rely on just AVG. Download update and use SuperAntiSpyware as well as MalwareBytes.Quote from: evilfantasy on June 22, 2008, 10:46:52 AM

      You can't rely on just AVG. Download update and use SuperAntiSpyware as well as MalwareBytes.

      OK. Although AVG 8.0 has it's own anti-spyware scanner now.

      But I'll still download SuperAntiSpyware and MalwareBytes.I've DOWNLOADED, installed and scanned with those two applications. Nothing was found.Dairyman...

      Visit Trend Micro's HouseCall...

      Run an online scan...this will take a while. This online scan will find and DISINFECT any "nasties" it finds on your PC.

      Afterwards...download and run HijackThis...and post the log here, so the Malware Specialists can take a look.Personally, I think AVG 8.0 is still having serious problems. In this case, being oversensitive, but...

      Download HijackThis:
      http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
      Click on Download HijackThis Installer
      Post HijackTHis log.Thank you both for your replies.

      I will run the Trend Micro HouseCall and post a HJT log.

      ~~ dairymanIs it okay if I skip the Trend Micro HouseCall? I started it at something like 4:30 PM and went on till 7:30 PM, so I canceled it because it was taking too long.

      Here's a HijackThis log.



      [RECOVERING disk space -- attachment deleted by admin]Fix this entry.

      O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)

      Were the "threats" actual FILES or were they just cookies? You mean AVG or the Trend Micro HouseCall?

      Trend Micro HouseCall mostly found updates that were not installed. I'll install them ASAP.Just for a double check run this.

      Download Dr.Web CureIt! & save it to your desktop.
      • Double-click on cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
      • Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
      • Once the short scan has finished, Click Options > Change settings
      • Choose the "Scan tab" and UNcheck "Heuristic analysis"
      • Back at the main window, click "Custom Scan", then "Select drives" (a red dot will show which drives have been chosen).
      • Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
      • When done, a message will be displayed at the bottom advising if any viruses were found.
      • Click "Yes to all" if it asks if you want to cure/move the file.
      • When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
        (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
      • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
      • Save the DrWeb.csv report to your desktop.
      • Exit Dr.Web Cureit when done.
      • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
      You can use Notepad to open the DrWeb.cvs report by right clicking it and selecting Open with > Notepad
      2947.

      Solve : ShieldsUP!?

      Answer»

      i just ran some of the sans there http://www.grc.com/x/ne.dll?rh1dkyd2 and for the common ports it PASSED when i fist visted the site then i ran it again and FAILED so i closed it and desided to run it again and i passed all 3 times i ran it its the same way with the all service ports and i passed the file sharing one every time what does this MEAN? i think it failed the times because my computer tried to respond to the PACKETS or something LIKE thatHiccup?hmm mabye

      2948.

      Solve : Suspected Antivirus XP 2008 Infection?

      Answer»

      From the Combofix log.

      Quote

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c8512ae-954c-11db-8c23-00032511a4c7}]
      \Shell\AutoRun\command - E:\system\viewer\Viewer.exe
      \Shell\View your videos\command - E:\system\viewer\Viewer.exe

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c05356c-b427-11dc-8e73-00032511a4c7}]
      \Shell\AutoRun\command - E:\wd_windows_tools\setup.exe

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4e748df1-8696-11dc-8e36-00032511a4c7}]
      \shell\autorun\command - E:\LaunchU3.exe -a

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aad9bb44-db12-11dc-8ead-00032511a4c7}]
      \Shell\AutoRun\command - E:\LaunchU3.exe -a
      Got it! - from the U3 references, I would guess that he had a flash drive attached. I'll have him scan it.

      Thank you for all of your help!

      Anything else to do? Computer seems to be back to normal! Yes makes since that it is a flash drive.

      Final steps.

      Let's clear out the programs we've been using to clean up your computer, they are not SUITABLE for
      general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
      .
      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      .
      The above procedure will:
      • Delete:
        • ComboFix and its associated files and folders.
        • VundoFix backups, if present
        • The C:\Deckard folder, if present
        • The C:_OtMoveIt folder, if present
        • Reset the clock settings.
        • Hide file extensions, if required.
        • Hide System/Hidden files, if required.
        • Set a new, clean Restore Point.
        .
        ----------

        Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

        1. Double click OTMoveIt2.exe to launch it.
        Vista users right click and choose Run As Administrator
        2. Click on the CleanUp! button.
        3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
        4. Click YES at the next prompt (list DOWNLOADED, Do you want to begin cleanup process?)
        5. Once complete exit out of OTMoveIt2

        ----------

        Set a New Restore Point to prevent possible reinfection from an old one
        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
        • Go to Start > Programs > Accessories > System Tools and click System Restore
        • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
        • The new restore point will be stamped with the CURRENT date and time. Keep a log of this so you can find it easily should you need to use System Restore.
        • Next go to Start > Run and type Cleanmgr
        • Click OK
        • Click the More Options Tab.
        • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
        You can find instructions on how to enable and re-enable system restore here:

        Windows XP System Restore Guide or Windows Vista System Restore Guide
        .
        ----------

        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

        If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

        ----------

        Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum.

        Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

        To prevent unknown applications from being installed on your computer install WinPatrol 2008
        Using Winpatrol to protect your computer from MALICIOUS software

        Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

        SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based BROWSERS like Firefox.
        *Using SpywareBlaster to protect your computer from Spyware and Malware
        *If you don't know what ActiveX controls are, see here

        Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.@Evilfantasy - Thank you for all of your help!No problem.

        Safe surfing.....
        2949.

        Solve : Checkup?

        Answer»

        Heya Malware Specialists. I have a pretty interesting task here.

        One of my old 'experimental' laptops has been pretty much screwing around for the past few days. (keyboard not working, cd drive not coming out, slowness, not starting up, not booting into windows, ect...)
        It's like it's on strike....
        Strange thing is, I just hit the thing twice and the keyboard is working now...

        Anyways, I would really appreciate it if you could have a look at my experimental Antivirusless computer. I got a Hijackthis log here:
        (excuse the time and date....the laptop is pretty hold... )


        Logfile of Trend MICRO HijackThis v2.0.2
        Scan saved at 12:13:07 AM, on 02-Jan-01
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\LEXBCES.EXE
        C:\WINDOWS\system32\LEXPPS.EXE
        C:\WINDOWS\System32\Atievxx.exe
        C:\Program Files\Executive Software\Diskeeper\DkService.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
        O2 - BHO: GOOGLE Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - (no file)
        O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)
        O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: VIEWPOINT Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
        O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
        O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
        O8 - Extra context MENU item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
        O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094074807773
        O17 - HKLM\System\CCS\Services\Tcpip\..\{F1E957A9-0D06-4CB5-AFBA-659202D5154B}: NameServer = 64.60.0.18,64.60.0.17
        O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
        O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing)
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

        --
        End of file - 3806 bytes


        Ha, I still use a win98 FAIRLY often. Thats ancient!!

        Looks fine besides the few harmless fixes. You do have a Symantec service running. If you would like to get rid of it do this:

        Start > Run > type:

        sc stop SymWSC

        Then click OK.

        Next Start > Run > type:

        sc delete SymWSC

        Then click OK.

        Open Hijackthis and select Do a system scan only.

        Place a check mark next to the following entries: (if there)

        O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - (no file)
        O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)
        O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML


        Important: Close all windows except for Hijackthis and then click Fix checked.

        Exit Hijackthis.Will do, Thanks EF!Yeah, thanks again. Now the PF Usage when the computer Starts Up is 77mb

        That will go well with the (very) low amount of RAM it has.It was probably the Norton service running.Forgot to add to also delete the Symantec folder.

        C:\Program Files\Common Files\Symantec SharedSure thing.

        2950.

        Solve : Computer running like a three legged dog.?

        Answer»

        Hi All

        I am running a 3Ghz computer, with 1Gb of ram, and a Nivida Gforce 6600. I am running windows XP pro version 2002 service pack 2.

        In the last few months I have noticed that it is slowing down. It first started with taking ages to shut down. We are talking 5 mins, which is longer than my computer at work. It aslo takes about 3 mins to start up. I have always hibernated my computer because its faster starting up but now even that takes about 3 mins to decide its awake.

        The final straw is now when I go to go into a program it spends 30 seconds making loud data noises and blinking a red light. Now thats normal and good but I remember when its use to think for about 2 seconds before complying with a command. The response times are getting longer and longer and I want to fix it.

        The problem is I am not sure why my computer has gone from being a lightning bolt to a grandmother. Does anyone know why computers get slower, and how to fix it? I have tried defrags, disk optomizers, ram optomizers, all the programs that are supposed to keep the computer running fast but it doesn't work.

        Also when Nortan antivirus does its once weekly virus scan of all drives thats it - I can't do much else beside using word because it slows the system down majorly.

        Any help will be greatly appreciated.

        Thanks
        Razor Have you checked your startup list to get rid of all unnecessary programs running in the background?

        The best thing you can do is get rid of Norton anti-virus which is a resource hog (see here.) Install AVG 8 (the free version is probably all you need). Run CCleaner to clear out temp & other unnecessary files, also to cleanup the registry.

        Good luckhave you done a fresh restart of your computer within the last week?

        if you use hibernate (as i do for my laptop) you need to do a complete shutdown or restart so that the computer can clear its memory.

        Dusty: Thank you. I am considering getting rid of Nortan. Just one question: Why do I have to go through all those steps to remove it? Won't the uninstall do the job?

        Programming_pat: Yes I have to restart my computer simply to keep it from stalling completely. I sometimes restart 3 times in a row to get it to run semi smoothly. It gets a complete shutdown at least once a week. (Takes forever too)Quote

        Dusty: Why do I have to go through all those steps to remove it? Won't the uninstall do the job?

        The Norton uninstaller is not a very efficient tool, it will leave file(s) and registry entries behind. These may come under the names of Norton or Symantec, that's why you should search on both names.

        D.

        Norton is a real bear to remove. AVG is a very good replacement.removing norton is like removing a leech from ones nether regions- also it might have missed some malware that another anti-virus might see clearly. (AVG....)You may also...

        Download HijackThis:
        http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
        Click on Download HijackThis Installer
        Post HijackTHis log.

        We'll see what's running there.Thanks. Ok, heres the log. Its kinda gibberish to me, but if you can help it'd be great.

        Also I have used msconfig on the run command to take out any 'non essential' startup programs that might slow things down, and have also done registry scans and fixes. After I did this I found that if I shrinked a prgram to the taskbar I couldn't tell it to go to the system tray, which I could before I started the clean up. I think I may have removed something that allows the taskbar to do this. Anyone know what it is?



        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 9:54:27 p.m., on 21/06/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
        C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
        C:\WINDOWS\system32\brsvc01a.exe
        C:\WINDOWS\system32\brss01a.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
        C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
        C:\WINDOWS\System32\GEARSec.exe
        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
        C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\VProSvc.exe
        C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
        C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
        C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
        C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
        C:\WINDOWS\system32\taskswitch.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
        C:\Program Files\Customizer XP\RAMIdle.exe
        C:\WINDOWS\system32\Rundll32.exe
        C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
        E:\Hive Cleanup\uphclean.exe
        C:\WINDOWS\system32\WFXSVC.EXE
        C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
        C:\WINDOWS\system32\Fast.exe
        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
        C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
        C:\Program Files\Microsoft IntelliType Pro\itype.exe
        C:\Program Files\Microsoft IntelliPoint\ipoint.exe
        C:\WINDOWS\system32\fast.exe
        C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
        C:\Program Files\interMute\AdSubtract\AdSub.exe
        C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
        C:\WINDOWS\explorer.exe
        C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
        C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
        C:\Program Files\Avant Browser\avant.exe
        C:\WINDOWS\system32\wuauclt.exe
        E:\Hijackthis\HiJackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.xtramsn.co.nz/0SEENNZ/SAOS01?FORM=TOOLBR
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.xtramsn.co.nz/0SEENNZ/SAOS01?FORM=TOOLBR
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www1.web3000.com/redir/iepage.asp?sku=872
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www1.web3000.com/redir/iepage.asp?sku=872
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.htm
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1035
        R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
        O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
        O2 - BHO: SmartShopper - {2BA1C226-EC1B-4471-A65F-D0688AC6EE3A} - C:\Program Files\SmartShopper\Bin\2.0.25\SmrtShpr.dll
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O2 - BHO: SurfingEnhancer - {57636FBF-8C24-0D22-E203-3D4DFA59E2A4} - C:\Program Files\SurfingEnhancer\SurfingEnhancer-1.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O2 - BHO: SmartEnhancer - {F608C2D0-846D-4F0E-E47A-88367C887707} - C:\Program Files\SmartEnhancer\SmartEnhancer-1.dll
        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: AdSubtract Toolbar - {F14AABDD-0232-4e5a-9B52-4178AC0A62B5} - C:\WINDOWS\system32\adsubtb.dll
        O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
        O4 - HKLM\..\Run: [RAM Idle] C:\Program Files\Customizer XP\RAMIdle.exe
        O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
        O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
        O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe"
        O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
        O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
        O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
        O4 - HKLM\..\Run: [Smart Start UP] C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe /Automation
        O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe
        O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
        O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] E:\Registery booster\RegistryBooster 2\RegistryBooster.exe /S
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Startup: AdSubtract.lnk = C:\Program Files\interMute\AdSubtract\AdSub.exe
        O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
        O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm025YYNZ
        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
        O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
        O8 - Extra context menu item: AdSubtract: Bypass Site - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/360
        O8 - Extra context menu item: AdSubtract: Cloak Image - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/361
        O8 - Extra context menu item: AdSubtract: Report Site - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/359
        O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\COMPONENTS\en-nz\msntabres.dll.mui/229?a2943e292dd54475837fa350d01564b7
        O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-nz\msntabres.dll.mui/230?a2943e292dd54475837fa350d01564b7
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\SmartShopper\Bin\2.0.25\SmrtShpr.dll
        O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
        O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O10 - Unknown file in Winsock LSP: c:\program files\netsonic\netsonic.dll
        O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/ZwinkyInitialSetup1.0.1.0.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: BCL easyPDF SDK 5 Loader (bepldr) - Unknown owner - C:\Program Files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe
        O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
        O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
        O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
        O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: LightScribeService Direct DISC Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
        O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
        O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\VProSvc.exe
        O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
        O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
        O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
        O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
        O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
        O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
        O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
        O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
        O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
        O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Ulead Systems, Inc. - (no file)
        O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE

        --
        End of file - 15218 bytesThere's a 3-legged stray dog that lives on my street. He runs pretty well actually. I'm not kidding either. Whew, I think the malware experts are going to have a hayday with this one. I normally don't get involved in the malware cases, but I believe I see signs that you've got your browser and your system in general BADLY junked up with malware. Standby until one of the malware experts here gets back to you.

        In the mean time, look at the lines in your HijackThis report that start with "O2 - BHO:". That's where I noticed some junk, starting with MyWebSearch Search Assistant. Here's some info to digest while you're waiting:
        http://www.pchell.com/support/mywebsearch.shtml
        http://spywaredlls.prevx.com/RRDFCA44688083/SURFINGENHANCER-2.DLL.html
        http://www.castlecops.com/tk44492-SmartEnhancer.htmlFirst of all, never use any registry cleaners, if you're not sure what you're doing.
        What program did you use to play with registry? That's what we need to start with.

        Secondly, as soybean noticed, your computer has severe infections. That's another proof, how "good" Norton is.
        We'll deal with infections in a moment, but you need to answer my primary question, first.Ok, looks like I may be in some trouble. I actually used three programs, trying to see which one was best.
        One was Resistry first aid, which after getting it to fix about 400 entries I decided it was not as good as Registery Repair 2005 which I ran before hand and fixed around 1100 entries. I also downloaded and used a trial resistry named Registry booster. As it was only a trial it fixed only 15 entries.

        I have also noticed that when I run Nortons one button check up, it does a registry scan, which I have nopt paid much attention to in the past. This check up runs about once a week.If you have Windows XP CD, go Start>Run, type in:
        sfc /scannow
        Click OK.Ok, I have done that. It ran this screen that said it was scanning for windows components or something. Nothing happened though, No message after it finished. It didn't ask for any further commands. Does this mean that PARTS alright?