Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3001.

Solve : Trying to find the cause of random hangups?

Answer»

On my HP Presario sr1750nx, 3500+ amd athlon64, 1gbmem, 200gbhard drive, win XP sp3. While I was in sys MANG in hidden DEVICES I FOUND a driver titled MCSTRM , with the yellow exclamation POINT tellimg me that it was inactive and missing part of it's drives. It was also activated by other programs, on searching I found that it can be a bit of malware too. Anybody know something about this???Welcome to CH.

If you think this is virus related then we need the logs from this thread

3002.

Solve : anti spy/malware?

Answer»

hello,

what is the most EFFECTIVE free anti spy/malware available?

thnx.On which operating SYSTEM?win/mac/etcTrusted free antivirus.

Remember to only install one antivirus!

1) Avast! Home Free Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Comodo Antivirus
5) PC Tools AntiVirus Free Edition

----------

Trusted free firewalls.

1) Comodo (UNCHECK during installation "Install Comodo SafeSurf..", Make Comodo my DEFAULT SEARCH provider" and "Make Comodo Search my homepage" if you choose this one)
2) Online Armor
3) Sunbelt/Kerio
4) Agnitum
5) PC Tools Firewall Plus

3003.

Solve : Someone pls help me with my logs...?

Answer»

Hi, can someone pls help me with my LOGS. Below are the logs. Thanks!

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/03/2008 at 02:26 PM

Application Version : 4.15.1000

Core Rules Database Version : 3524
Trace Rules Database Version: 1514

Scan type : Complete Scan
Total Scan Time : 00:56:31

Memory items scanned : 558
Memory threats detected : 0
Registry items scanned : 4835
Registry threats detected : 0
File items scanned : 52027
File threats detected : 6

Adware.Tracking Cookie
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt

Trojan.Vundo-Variant/Small-V2
C:\WINDOWS\SYSTEM32\BOETHWMJ.DLL
C:\WINDOWS\SYSTEM32\OWNWDNNH.DLL

Trojan.Vundo-Variant/Small
C:\WINDOWS\SYSTEM32\EPGNKA.DLL
C:\WINDOWS\SYSTEM32\FUDQSO.DLL

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:20:01 PM, on 8/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\sniper.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.sg/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {3944EB28-3DA6-41A2-933B-DEBBD450E81C} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /QS
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
O16 - DPF: {A9ED6AA2-D9D4-4D71-9586-E293E2E3580B} (GameDesire Marbles&Diamonds&Runes) - http://67.15.101.33/g_bin/eng/marbles_2_0_0_32.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: bqsyze.dll,avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ddcYqpPG - ddcYqpPG.dll (file missing)
O20 - Winlogon Notify: DfLogon - C:\WINDOWS\SYSTEM32\LogonDll.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DF5Serv - Faronics Corporation - C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 11484 bytes

Malwarebytes' Anti-Malware 1.24
Database version: 1018
Windows 5.1.2600 Service Pack 2

3:10:09 PM 8/3/2008
mbam-log-8-3-2008 (15-10-09).txt

Scan type: Quick Scan
Objects scanned: 42823
Time elapsed: 8 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)It's very important to run only one antivirus at a time. Running two actually gives you less protection.

To completely REMOVE Norton/Symantec go to Add or Remove Programs and uninstall anything with Norton, Symantec or Live Update in the name.

Download the Norton Removal Tool (SymNRT) to your Desktop.

Once downloaded please close ALL open browsers, also save any work because this MAY require a restart.

  • Go to your desktop and double click on the removal tool and then click Setup.
  • Once open Click Next
  • Accept the license agreement and click Next
  • Type in the letters/numbers that you see into the text box then click Next.
  • Then click Next and the tool will start running.
  • Once finished restart the PC and run the tool again to ensure everything has been removed.
.
----------

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

* O2 - BHO: (no name) - {3944EB28-3DA6-41A2-933B-DEBBD450E81C} - (no file)
* O20 - Winlogon Notify: ddcYqpPG - ddcYqpPG.dll (file missing)


Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis and restart the computer to register the changes.

----------

How is the computer now?Hi evilfantasy, thank you for your reply. My pc seems to be running very slowly and many programs tend to have problems again. I will re-do the steps u teach again and removed the norton. After which, I will post the logs again. Hope that solve my problems.You don't NEED to redo the steps, they won't turn up any new results. Let me know how everything is after removing Norton.Hi evilfantasy, now my pc having new problems. Now it can't cannot connect to the internet and ws2_32.dll problem. I had removed Norton but nothing seems to be ok. Can you help?

Thanks!And also the system is running very slowly. It takes 5 to 10 mins or more to load up when I turn on the pc. Is there anything or application I could use to speed up the pc? But of course to resolve the internet issue first. I can't connect to the internet at all. I'm using wireless and it can't connect to my wireless network. I tried restart many times but still can't. And I also tried to run RegCure. Whenever I tried to open RegCure, windows pop up saying, "Windows sockets initialization failed".

Pls let me know what other informations you require as I'm really a greenhorn to pc.

Thanks!You need to run this tool. WinSock XP Fix.

After that do you have your XP CD?


hi evilfantasy, i do not have my XP CD.Did you try the WinSock XP Fix?
3004.

Solve : How to renamed files infected by virus MALAS??

Answer» HONESTLY I don't KNOW. Your BETTER off STICKING with who was HELPING you on that.
3005.

Solve : Infected laptop problem?

Answer»

A few days ago my wife foolishly opened an email from the customs department which after a bit of research contained a virus which is circulating. Basically I cannot use the laptop, however there are files on there that I would like to save. When I boot up the PC it goes to the Windows loggin screen and when I try to get past this it starts to dump physical memory then reboots. I've tried safe boot etc but exactly the same. I've also tried to reinstal windows as a REPAIR but still the same problem. Is ther anyway of clearing the virus without being in windows? I would like to save the files but I also really need to use the laptop again so if there is NOTHING that can be done then I will have to reinstall windows and start again.

THANKS,
Richard.Do you have another computer?

If so, you might need to hook the current hard DRIVE up as a slave on the other computer.I have a desktop PC. Is ther any simple way to hook up the laptop drive to a normal PC?You will need something like this:


2.5" laptop HDD to IDE CONVERTER

(thanks Patio)

3006.

Solve : Trojan.Packed.NsAnti?

Answer»

Second Hijack this


second scan hijack

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:01:22, on 31/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot MODE: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\FarStone\VirtualDrive\vdtask.exe
C:\Program Files\FarStone\VirtualDrive\Netsrv.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Trend Micro\HijackThis\snare.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Virtual Drive] "C:\Program Files\FarStone\VirtualDrive\vdtask.exe"
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=081508 serial=DR12CES-6935367-CQC lang=EN
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: RESEARCH - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/AcPreview.ocx
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 8297 bytes
This scan is after I put in my pendrive,I always virus scan everytime I put a pen drive in No virus found,
I did a hijach this, an It showed I had the amvo again,so I formated my pen drive, did another combofixed again this is the log, I have reformatted my pendrive again, took the drive out and reinserted it, did a hijack this scan nothing.

Q. 1. when the pendrive is in why doesn't combofix scan that drive also?
2. why doesn't my AV, pull it out?




ComboFix 08-07-31.02 - Peter 2008-08-02 10:29:38.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.178 [GMT 1:00]
Running from: C:\Documents and Settings\Peter\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\kdxdweli.cmd
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
D:\Autorun.inf
G:\Autorun.inf
H:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))
.

2008-08-02 10:20 . 2008-08-02 10:20d--------C:\Documents and Settings\Mercy
2008-08-01 09:52 . 2008-08-01 09:52d--------C:\Program Files\Intense Language Office
2008-07-31 11:00 . 2008-07-31 11:05d--------C:\Program Files\Evrsoft First Page 2006
2008-07-31 11:00 . 2005-09-23 17:02887,296--a------C:\WINDOWS\system32\KsDHTMLEDLib.ocx
2008-07-31 10:22 . 2008-07-31 10:23d--h-----C:\WINDOWS\system32\GroupPolicy
2008-07-31 09:18 . 2008-07-31 09:18d--------C:\WINDOWS\ERUNT
2008-07-31 09:14 . 2008-07-31 13:21d--------C:\SDFix
2008-07-29 12:23 . 2008-07-29 12:23d--------C:\Deckard
2008-07-29 12:20 . 2008-07-29 12:2033--a------C:\WINDOWS\SYMGAMES.INI
2008-07-28 16:47 . 2008-07-28 16:47d--------C:\Documents and Settings\Peter\Application Data\Autodesk
2008-07-25 11:10 . 2008-07-25 11:10d--------C:\Program Files\GSP
2008-07-24 15:16 . 2008-07-24 15:16d--------C:\Documents and Settings\Peter\Application Data\farstone
2008-07-23 17:00 . 2008-07-23 17:17d--------C:\Documents and Settings\Peter\Application Data\CyberLink
2008-07-23 17:00 . 2008-07-23 17:17d--------C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-20 16:34 . 2008-07-20 16:34d--------C:\WINDOWS\system32\LogFiles
2008-07-20 16:33 . 2008-07-20 16:34d--------C:\WINDOWS\system32\drivers\umdf
2008-07-19 15:13 . 2002-09-10 15:11311,296--a------C:\WINDOWS\system32\hptcpmui.dll
2008-07-19 15:13 . 2003-01-31 14:17208,896--a------C:\WINDOWS\system32\hptcpmon.dll
2008-07-19 15:13 . 2003-01-31 14:17135,168--a------C:\WINDOWS\system32\hptcpmib.dll
2008-07-19 15:13 . 2001-08-13 10:313,399--a------C:\WINDOWS\system32\hptcpmon.ini
2008-07-19 15:13 . 2008-07-19 15:13136--a------C:\WINDOWS\system32\AddPort.ini
2008-07-19 15:05 . 2008-07-28 12:19d--------C:\Program Files\[emailprotected]
2008-07-18 15:47 . 2008-07-18 15:47d--------C:\Documents and Settings\Peter\Application Data\AdobeUM
2008-07-18 14:24 . 2008-07-21 08:33d--------C:\Program Files\Malwarebytes' Anti-Malware
2008-07-18 14:24 . 2008-07-18 14:24d--------C:\Documents and Settings\Peter\Application Data\Malwarebytes
2008-07-18 14:24 . 2008-07-18 14:24d--------C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-18 14:24 . 2008-07-07 17:3534,296--a------C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-18 14:24 . 2008-07-07 17:3517,144--a------C:\WINDOWS\system32\drivers\mbam.sys
2008-07-18 12:16 . 2008-07-18 12:16d--------C:\Program Files\Common Files\Wise INSTALLATION Wizard
2008-07-18 10:39 . 2004-08-03 23:0125,856--a------C:\WINDOWS\system32\drivers\usbprint.sys
2008-07-18 09:53 . 2008-07-18 12:16d--------C:\Program Files\SUPERAntiSpyware
2008-07-18 09:53 . 2008-07-18 12:16d--------C:\Documents and Settings\Peter\Application Data\SUPERAntiSpyware.com
2008-07-18 09:53 . 2008-07-18 09:53d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-18 09:31 . 2008-07-18 09:31d--------C:\Program Files\Trend Micro
2008-07-18 09:25 . 2004-08-03 23:0826,496--a--c---C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-17 11:30 . 2008-07-17 11:3053,680--a------C:\WINDOWS\FontData.fdb
2008-07-17 10:38 . 2008-07-17 10:38d--------C:\Documents and Settings\Peter\Application Data\Corel
2008-07-16 18:04 . 2008-07-16 18:04d--------C:\Program Files\VCop2
2008-07-16 16:49 . 2008-07-28 10:0816--a------C:\WINDOWS\system32\coh.cache
2008-07-16 16:11 . 2008-07-16 16:11d--h-----C:\WINDOWS\$hf_mig$
2008-07-16 16:11 . 2006-05-09 20:0022,752--a------C:\WINDOWS\system32\spupdsvc.exe
2008-07-16 16:06 . 2008-07-16 16:06d--------C:\Program Files\WexTech
2008-07-16 16:06 . 2008-07-16 16:06d--------C:\Program Files\Common Files\LHSPF
2008-07-16 16:06 . 2000-05-02 10:03225,280--a------C:\WINDOWS\system32\awrtl30.dll
2008-07-16 16:06 . 1998-08-04 11:22111,616---------C:\WINDOWS\system32\Ltih30tb.dll
2008-07-16 16:05 . 2000-10-20 13:25487,184--a------C:\WINDOWS\system32\Mrt7enu.dll
2008-07-16 16:05 . 2000-10-20 13:25446,464--a------C:\WINDOWS\system32\hhactivex.dll
2008-07-16 16:05 . 2000-10-20 13:2579,360--a------C:\WINDOWS\system32\acdbres.dll
2008-07-16 16:05 . 2000-10-20 13:2531,744--a------C:\WINDOWS\system32\Hlp95en.dll
2008-07-16 16:04 . 2008-07-16 16:05d--------C:\Program Files\Volo View Express
2008-07-16 16:04 . 2008-07-16 16:04d--------C:\Documents and Settings\Peter\WINDOWS
2008-07-16 16:04 . 2000-10-20 13:25299,520--a------C:\WINDOWS\uninst.exe
2008-07-16 16:01 . 2008-07-16 16:06d--------C:\Program Files\Common Files\Wextech Shared
2008-07-16 16:00 . 2008-07-16 16:06d--------C:\Program Files\Common Files\Autodesk Shared
2008-07-16 16:00 . 2008-07-28 16:41d--------C:\Program Files\Autodesk Architectural Desktop 3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-01 14:56---------d-----wC:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-31 09:48---------d-----wC:\Program Files\Common Files\Symantec Shared
2008-07-25 10:10---------d--h--wC:\Program Files\InstallShield Installation Information
2008-07-25 10:09---------d-----wC:\Program Files\Common Files\InstallShield
2008-07-23 12:33---------d-----wC:\Documents and Settings\Peter\Application Data\Ahead
2008-07-16 14:52---------d-----wC:\Program Files\CyberLink
2008-07-16 14:49---------d-----wC:\Program Files\Common Files\Ahead
2008-07-16 14:46---------d-----wC:\Program Files\Common Files\Adobe
2008-07-16 14:45---------d-----wC:\Program Files\Nero
2008-07-16 14:45---------d-----wC:\Documents and Settings\All Users\Application Data\Nero
2008-07-16 14:23---------d-----wC:\Program Files\Norton AntiVirus
2008-07-16 14:22---------d-----wC:\Documents and Settings\All Users\Application Data\Symantec
2008-07-16 14:20806----a-wC:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-07-16 14:208,014----a-wC:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-07-16 14:2048,776----a-wC:\WINDOWS\system32\S32EVNT1.DLL
2008-07-16 14:20115,000----a-wC:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-07-16 14:20---------d-----wC:\Program Files\Symantec
2008-07-16 14:11---------d-----wC:\Program Files\Microsoft Works
2008-07-16 14:10---------d-----wC:\Program Files\MSBuild
2008-07-16 14:08---------d-----wC:\Program Files\Corel
2008-07-16 14:08---------d-----wC:\Program Files\Common Files\Corel
2008-07-16 13:50---------d-----wC:\Program Files\FarStone
2008-07-16 13:39---------d-----wC:\Program Files\microsoft frontpage
1997-07-21 18:301,045,776--sha-wC:\WINDOWS\system32\Msjet35.dll
1997-06-23 02:00123,664--sha-wC:\WINDOWS\system32\Msjint35.dll
1997-06-23 11:0624,848--sha-wC:\WINDOWS\system32\Msjter35.dll
1997-06-23 11:06252,176--sha-wC:\WINDOWS\system32\Msrd2x35.dll
1997-06-23 11:06287,504--sha-wC:\WINDOWS\system32\Msxbse35.dll
.

((((((((((((((((((((((((((((( [emailprotected]_ 9.40.03.66 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-16 14:12:161,165,584----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-08-01 14:47:551,165,584----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
- 2008-07-16 14:12:1620,240----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-08-01 14:48:0120,240----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-07-16 14:12:16159,504----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
+ 2008-08-01 14:47:57159,504----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
- 2008-07-16 14:12:16217,864----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
+ 2008-08-01 14:48:00217,864----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
- 2008-07-16 14:12:1718,704----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-08-01 14:48:0118,704----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-07-16 14:12:1735,088----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-08-01 14:48:0335,088----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-07-16 14:12:16845,584----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-08-01 14:47:59845,584----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
- 2008-07-16 14:12:16922,384----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-08-01 14:48:00922,384----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
- 2008-07-16 14:12:16272,648----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-08-01 14:48:00272,648----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
- 2008-07-16 14:12:17888,080----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-08-01 14:48:02888,080----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-07-16 14:12:161,172,240----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-08-01 14:47:571,172,240----a-rC:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-07-16 14:05:43217,864----a-rC:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2008-08-01 14:56:14217,864----a-rC:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2008-07-16 15:17:05343,424----a-wC:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-08-02 09:01:38343,424----a-wC:\WINDOWS\system32\FNTCACHE.DAT
+ 2001-04-15 03:20:0047,616----a-wC:\WINDOWS\system32\intedreg.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 18:05 143360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"ILO_Office_Manager"="IntEdReg.exe" [2001-04-15 04:20 47616 C:\WINDOWS\system32\intedreg.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 08:59 115816]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-01-14 10:11 771704]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"Virtual Drive"="C:\Program Files\FarStone\VirtualDrive\vdtask.exe" [2001-10-20 05:47 57344]
"CorelDRAW Graphics Suite 11b"="C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe" [2003-11-25 13:39 729088]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2006-11-10 16:19 1051648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 15:10 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 22:55 54832]
"Intense Registry Service"="IntEdReg.exe" [2001-04-15 04:20 47616 C:\WINDOWS\system32\intedreg.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:56 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2008-07-16 14:48:56 25214]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-07-16 15:33:15 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\FarStone\\VirtualDrive\\netsrv.exe"=
"C:\\Program Files\\[emailprotected]\\LookAtLan.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=

R2 cdant;cdant;C:\WINDOWS\system32\drivers\cdant.sys [2001-09-06 22:13]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{39686e63-595a-11dd-9a1d-000d87b86781}]
\Shell\AutoRun\command - wscript.exe sys.vbs
\Shell\open\Command - wscript.exe sys.vbs

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder

2008-07-31 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Peter.job
- C:\Program Files\Norton AntiVirus\Navw32.exe [2007-01-14 12:09]
.
.
------- Supplementary Scan -------
.
O8 -: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-02 10:31:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-02 10:33:51
ComboFix-quarantined-files.txt 2008-08-02 09:33:16

Pre-Run: 11,423,133,696 bytes free
Post-Run: 11,416,059,904 bytes free

216
I think I've got rid of the problem. I''ll wait for your reply.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:08:56, on 04/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\FarStone\VirtualDrive\vdtask.exe
C:\Program Files\FarStone\VirtualDrive\Netsrv.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Intense Language Office\Common\OffMan.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\snare.exe
C:\Program Files\Trend Micro\HijackThis\snare.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Virtual Drive] "C:\Program Files\FarStone\VirtualDrive\vdtask.exe"
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=081508 serial=DR12CES-6935367-CQC lang=EN
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Intense Registry Service] IntEdReg.exe /CHECK
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ILO_Office_Manager] IntEdReg.exe /OFFMAN
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%20Files/Autodesk%20Architectural%20Desktop%203/AcPreview.ocx
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 8368 bytes
Quote

I think I've got rid of the problem. I''ll wait for your reply.

What did you do? There are still trojans left.

Read this article: Danger: Remote Access Trojans.

If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay and forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one! If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach.

Your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because the Backdoor Trojan has been removed the computer is now secure. Many experts in the security COMMUNITY believe that once infected with this type of malware, the best course of action is to reformat and reinstall the OS.

When should I re-format? How should I reinstall?.
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Should you decide not to follow that advice, we will do our best to help clean the computer of any infections but we cannot guarantee it will be 100% secure afterwards or that the removal will be successful.

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

File::
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\FarStone\VirtualDrive\netsrv.exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{39686e63-595a-11dd-9a1d-000d87b86781}]
3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you SEE in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick combofix's window while it is running. That may cause your system to freeze

----------

3007.

Solve : Avira?Windows ME?

Answer»

For Windows 2000 and above I would SUGGEST installing MBAM for an on demand scanner - http://www.besttechie.net/tools/mbam-setup.exe

For the ME computer there is also SAS to use as an on demand scanner, might not be a bad idea to give it a RUN in CASE there is anything else hiding. But do be forewarned it may delete SmileyCentral - http://www.superantispyware.com/download.html evilfantasy,I shall follow both the reccommendation.truenorth

3008.

Solve : rundll malware plz help?

Answer»

Hey guys,

For some odd reason every time i turn on my laptop, a RunDLL error occurs.


The message says Error Loading C:\Windows\system32\mfjtlrtfjtgb.dll
The specified module could not be found.

I scanned with Malwarebytes' Anti-Malware and it couldnt find anything.

Then i ran Hijackthis.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:37:54 PM, on 8/4/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Sony\VAIO PC Wireless LAN Wizard\AutoLaunchWLASU.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [{edb89f6b-240f-2834-9539-8e26f7558230}] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\mfjtlrtfjtgb.dll" DllStart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [VWLASU] "C:\Program Files\Sony\VAIO PC Wireless LAN Wizard\AutoLaunchWLASU.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VAIO Center Access Bar] "c:\program files\sony\VAIO Center Access Bar\VCAB.exe" 1
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: acaptuser32.dll
O20 - WINLOGON Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 14603 bytes



The uninstall list

2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
Ad-Aware
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
Adobe After Effects CS3
Adobe After Effects CS3
Adobe After Effects CS3 Presets
Adobe After Effects CS3 Third Party Content
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Flash CS3
Adobe Flash CS3 Professional
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Flash Video Encoder
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe MotionPicture Color Files
Adobe PDF Library Files
Adobe Reader 8.1.0
Adobe Setup
Adobe Setup
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe Video Profiles
Adobe WinSoft Linguistics Plugin
Adobe XMP DVA Panels CS3
Adobe XMP Panels CS3
AIM 6
Antares Auto-Tune v4.39
Apple Mobile Device Support
Apple Software Update
ArcSoft Magic-i Visual Effects Installer
ASIO4ALL
Atheros USB Wireless LAN Driver Installer
CCleaner (remove only)
Click to DVD 2.0.05 Menu Data
Click to DVD 2.6.00
Compatibility Pack for the 2007 Office system
Cool Edit Pro 2.1
Corel Paint Shop Pro Photo XI
Corel Snapfire
Counter-Strike
CycoreFX HD 1.6 for After Effects
Digidesign Shared Plug-Ins 7.4
DivX Codec
DivX Converter
DivX Player
DivX Web Player
GearDrvs
Gunbound Revolution
HDAUDIO SoftV92 Data Fax Modem with SmartCP
HijackThis 2.0.2
HyperCam 2
ijji - Gunz
Instant Mode
Interlok driver setup x32
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Java™ SE Runtime Environment 6
LimeWire PRO 4.12.3
LiveUpdate 3.2 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Malwarebytes' Anti-Malware
McAfee VirusScan Enterprise
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.0.1)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 Parser and SDK
Norton 360
OpenMG Limited Patch 4.7-07-15-19-01
OpenMG Secure Module 4.7.00
PDF Settings
PFConfig 1.0.144
Pivot Stickfigure Animator
Project64 1.6
Protector Suite QL 5.8
QuickBooks
QuickBooks Product Listing Service
QuickBooks Simple Start Free Starter Edition
QuickTime
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
Realtek High Definition Audio Driver
Roxio Easy Media Creator Home
Security Update for Excel 2007 (KB946974)
Security Update for Excel 2007 (KB946974)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB951808)
Security Update for Microsoft Office system 2007 (KB951808)
Security Update for Microsoft Office Word 2007 (KB950113)
Security Update for Microsoft Office Word 2007 (KB950113)
Security Update for Office 2007 (KB947801)
Security Update for Office 2007 (KB947801)
Security Update for Visio 2007 (KB947590)
Security Update for Visio 2007 (KB947590)
Setting Utility Series
SonicStage Mastering Studio
SonicStage Mastering Studio Audio Filter
SonicStage Mastering Studio Plugins
Sony Video Shared Library
Spybot - Search & Destroy
Starcraft
SUPERAntiSpyware Free Edition
Synaptics Pointing Device Driver
Total Video Converter 3.10
Trapcode 3DStroke
Trapcode Form
Trapcode Shine
Trapcode Starglow
TuneUp Utilities 2008
Uniblue PowerSuite
Uniblue RegistryBooster 2
Update for Microsoft Office Outlook 2007 (KB952142)
Update for Office 2007 (KB946691)
Update for Office 2007 (KB946691)
Update for Outlook 2007 Junk Email Filter (kb953463)
VAIO Application Uninstaller
VAIO Azure Float Wallpaper
VAIO Camera Capture Utility
VAIO Center Access Bar
VAIO Content Folder Setting
VAIO Content Importer / VAIO Content Exporter
VAIO Content Metadata Intelligent Analyzing Manager
VAIO Content Metadata Manager Setting
VAIO Content Metadata XML Interface Library
VAIO Control Center
VAIO Entertainment Center
VAIO Entertainment Platform
VAIO Event Service
VAIO Floral Dusk Wallpaper
VAIO Help And Support
VAIO Launcher
VAIO Media 6.0
VAIO Media AC3 Decoder 1.0
VAIO Media Content Collection 6.0
VAIO Media Integrated Server 6.1
VAIO Media Redistribution 6.0
VAIO Media Registration Tool 6.0
VAIO Movie Story
VAIO Movie Story Template Data
VAIO MusicBox
VAIO MusicBox Sample Music
VAIO OOBE
VAIO Original Function Setting
VAIO PC Wireless LAN Wizard
VAIO Power Management
VAIO Productivity Center
VAIO Security Center
VAIO Service Utility
VAIO Teal Whisper Wallpaper
VAIO Update 3
VeohTV BETA
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Player Firefox Plugin
WinDVD for VAIO
WinRAR archiver
Wireless Switch Setting Utility
Zune
Zune
Zune Language Pack (ES)
Zune Language Pack (FR)Welcome to CH.

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - (no file)

Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Go to add/remove programs (Programs and Features) and uninstall: (Don't choose to restart until they are all uninstalled)

Java™ 6 Update 3
Java™ 6 Update 5
Java™ SE Runtime Environment 6


Restart the computer.

----------

Download Combofix by sUBs from one of the below links. Be sure top save it to the Desktop.
Link #1
Link #2

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.

When finished ComboFix will produce a log for you.Post that log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

----------

Now run a new HijackThis scan and post the log along with the ComboFix log.hi, thank you for helping me. im going to do as you say right nowI had to attach it because it exceeded the text limit

[recovering disk space -- attachment deleted by admin]Need a new HijackThis log also.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:50:59 PM, on 8/4/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Service Utility\VAIO-SUTOOL.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Sony\VAIO PC Wireless LAN Wizard\AutoLaunchWLASU.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\Explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [VWLASU] "C:\Program Files\Sony\VAIO PC Wireless LAN Wizard\AutoLaunchWLASU.exe"
O4 - HKLM\..\Run: [VAIO Center Access Bar] "c:\program files\sony\VAIO Center Access Bar\VCAB.exe" 1
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: acaptuser32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 13778 bytes

      Uninstall ComboFix.

      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      ----------

      Download
OTMoveIt2 by OldTimer
  • Save it to your desktop.
Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

  • Double-click OTMoveIt2.exe to run it.
  • Copy the lines in the codebox below.
Code: [Select][kill explorer]
C:\Windows\System32\bjuwckqkyt.exe
C:\Windows\unvise32.exe
EmptyTemp
[start explorer]
  • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the GREEN bar) and paste it in your next reply.
  • Close OTMoveIt2
should i reboot?


Explorer KILLED successfully
C:\Windows\System32\bjuwckqkyt.exe moved successfully.
C:\Windows\unvise32.exe moved successfully.
< EmptyTemp >
File delete failed. C:\Users\Anhtuyet\AppData\Local\Temp\etilqs_4oEQWGDKaKIJfF1gK3Xs scheduled to be deleted on reboot.
File delete failed. C:\Users\Anhtuyet\AppData\Local\Temp\061d7df21e7b420bbf81f860b2a6409d\filesys.dll scheduled to be deleted on reboot.
File delete failed. C:\Users\Anhtuyet\AppData\Local\Temp\061d7df21e7b420bbf81f860b2a6409d\http.dll scheduled to be deleted on reboot.
File delete failed. C:\Users\Anhtuyet\AppData\Local\Temp\NAILogs\UpdaterUI_ANHTUYET-PC.log scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08042008_211107
Yes, please restart then run this next scan and post the log from it.

Use the Kaspersky Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon and choose Run as Administrator.

Click on SCAN NOW
Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Save the file to your desktop.
Post the Kaspersky log in your next reply.



Sorry for the long response, the kaspersky took a long time. Heres the attachment

[recovering disk space -- attachment deleted by admin]The only thing showing is the MalwareBytes Quarantine which can be emptied.

Time to cleanup. Let me know if you have any questions.

1. Double click OTMoveIt2.exe to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
5. Once complete exit out of OTMoveIt2

----------

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

----------

Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and BECOME less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thanks a lot man my computer is finally error free. I appreciate what you have helped me with, hopefully if i have more trouble in the future ill go to u

Two more questions
1. Should i keep Spybot Search & destroy and ad-aware??
2. Somtimes my laptop has no sound and i check the volume mixer, it says its properly working. Then i close my laptop and put my fingerprint on for the password. When it turns on it works for a little. Then if i haven't played anything with sounds it stops working for unknown reasons.

Thanks againQuote
1. Should i keep Spybot Search & destroy and ad-aware??

I would get rid of ad-aware and use MalwareBytes instead.

Keep SpyBot, update it and also click the Immunize feature after updating.

Quote
2. Somtimes my laptop has no sound and i check the volume mixer, it says its properly working. Then i close my laptop and put my fingerprint on for the password. When it turns on it works for a little. Then if i haven't played anything with sounds it stops working for unknown reasons.

It would be BEST to start a new topic in the Windows or Software forum on this.


Glad you are malware free. Safe surfing.....
3009.

Solve : Computer running sluggish all of the sudden?

Answer»

Quote

Hows Startup in MSConfig?
It was done through HJT, AS ALWAYS.Defrag?not bad. Only the things i want running are. Is it possible that it could be the zonealarm security suite? I just recently installed it. But I don't really like it. nothing to defrag. Just tried it. NothingQuote from: Broni on July 05, 2008, 08:10:42 PM
Quote
Hows Startup in MSConfig?
It was done through HJT, AS ALWAYS.
Just wondering if anything was added after HijackThis.Do oyu want me to post a new copy of HJT? Maybe something changed.Go ahead.
You may try also uninstalling ZA, but before you do, download replacements:
- Avira free antivirus: http://www.free-av.com/en/download/index.html
or
- Avast! free antivirus: http://filehippo.com/download_avast_antivirus/

and
- Comodo free firewall: http://www.personalfirewall.comodo.com/
or
Windows firewall up.

Physically disconnect from the Net, while MAKING changes.Quote from: paudashlake on July 05, 2008, 08:02:50 PM
task killer www.rsdsoft.com

eraser www.heidi.ie/eraser

For what it's worth - I had to delete the new version of Eraser about a month ago because of consistent errors that showed up with Event Viewer. I can't remember the exact error but my boot TIME increased quite a bit, that's why I went looking. The Heidi Forum was no HELP so I just uninstalled it.Any better?nopeHave you considered running Lavasoft's Ad-Aware program? I have found success in running this program first before my weekly ritual of tweeking my PC. The website provides a Freeware copy, and I have used it for 3 years no Virus yet.

http://lavasoft.com/

Please advise if this was helpful? I have other steps you can use that have helped me.Welcome, NickBurns but this topic is a month old....and the Original Poster is gone...Nick, your input is appreciated, but like Carbon said, the original poster has deleted their account and is no longer a member.

On that note, I am going to go ahead and lock this thread.
3010.

Solve : Infections won't go away, IE freezes?

Answer»

Hey all! Recently I've been having problems with Trojans and other infections. Also my Internet Explorer keeps freezing on me. This hasn't been a problem before. But almost every time I open IE and open some new tabs, it freezes. I keep running spyware and virus scans and they keep popping up. I'm attaching my SuperAnti spyware, Malwarebytes and HJT logs as requested. If anything else is needed, please just let me know.

I'd appreciate any help!

Thanks in advance-
Christy



[recovering disk space -- attachment deleted by admin]I'll take a look and get back to you in a minute...Looks like someone's been DOWNLOADING cracks, which is probably how you got infected. Also, I don't see any anti-virus or firewall software running on your computer. This needs to be corrected ASAP. On that note, I also see that you have CyberDefender installed...you may want to read a little about it here:
http://forums.spybot.info/archive/index.php/t-10042.html
Personally, I would get rid of it.

Is Juno your current ISP, or is it NetZero?
Either way, all of these toolbars might be contributing to your IE problem. If you want, we can look into it.

Go ahead and run HijackThis and place checkmarks next to the following entries...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.44.66;64.136.52.66;searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*windowsupdate.com; (the rest is cut off to reserve space)
O2 - BHO: (no name) - {14F4272A-5E14-439F-B1ED-3B50E78B7739} - (no file)

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)

O15 - Trusted Zone: http://www.bigfishgames.com
O15 - Trusted Zone: http://*.bigfishgames.com
O15 - Trusted Zone: http://onecare.live.com
O15 - Trusted Zone: http://www.pogo.com


As a general rule of thumb, it's best to not allow any sites into your Trusted Zone, so you should remove those. With that said, close all windows except for HijackThis (you may want to print my instructions, as you will have to close this window as well) and click on Fix Checked.

Once you are done with that...
1. Download VundoFix and save it to your desktop.
2. Run VundoFix and click on Scan For Vundo.
3. Once it's done scanning, click on Remove Vundo.
4. When it prompts you to remove the files, click on Yes.
5. Your desktop will go blank as it's removing files. Don't worry, this is normal.
6. It will prompt you to restart your computer, so click OK.
7. When your computer is turned back on, your problem should be gone.
8. The program normally produces a Vundofix.txt file. Please locate this file and paste the contents in your next post.

And then, just to be thorough...
1. Download VirtumundoBeGone and save it to your desktop.
2. Reboot into Safe Mode.
3. Once you are in Safe Mode, run VirtumundoBeGone and follow the instructions.
4. Exit when it has finished and reboot back into normal mode.
5. The program normally produces a VBG.txt file. Please locate this file and paste the contents in your next post.



When you post those logs, post a new HJT log as well.Ok, did what you suggested. I'm attaching the logs here too. As for the firewall, I've been relying on WinXP firewall. What else is suggested for the firewall and virus protection?

thanks for the help-
Christy

[recovering disk space -- attachment deleted by admin]Did VundoFix not produce a log? Well, in any case, it looks like your Vundo infection has already been cleaned out. However, I would like you to run one more scan. Download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls.

Your logs are coming up clean, but this little program is really good at finding things that we can't see.

The Windows Firewall helps, but its protection is subpar. There are several free firewalls available, but my favorite is Comodo. There are others such as ZoneAlarm, Kerio/Sunbelt, and several others. Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.

As for anti-virus, many people prefer AVG, and it is what I currently use. The protection is great, but the current version gives some people trouble, so you may want to consider using Avast, Avira/AntiVir, or another program (I can give you a list if you'd like). Just look around on Google and see which one seems to be more to your liking. Like with a firewall, you should only have one anti-virus active.

While you're at it, you may also want to go to Tools > Windows Update from your IE browser and upgrade your Windows to SP3.



Also, you didn't answer this question...
Quote from: CBMatt on August 05, 2008, 11:33:05 PM

Is Juno your current ISP, or is it NetZero?
Either way, all of these toolbars might be contributing to your IE problem. If you want, we can look into it.
Hey CBMatt-

Alrighty then, first of all I ran VundoFix and then the VirtumundoBeGone but the only log I got was the one I attached on the previous post. After your last post I ran ComboFix and am attaching the log for you. I now have AVG AV and Firewall installed and running. I also updated my IT browser to SP3.
Quote
Is Juno your current ISP, or is it NetZero?
Either way, all of these toolbars might be contributing to your IE problem. If you want, we can look into it.

I'm sorry, I completely forgot about that question! I am now using Hughes Net as my internet provider. The others are dial-up I have in case of a satellite outage. I DID tell HijackThis to get rid of them though since I haven't used them in quite a while. Oh, also, since installing AVG, it put a toolbar on my desktop too. Should I get rid of it as well?

So, I think I've finished everything you suggested. Anything else you need?

thanks!
Christy

[recovering disk space -- attachment deleted by admin]A toolbar? I've never known AVG to install a toolbar. Unless it's related to the SafeSearch, which I have never used...
http://one9.us/blog/how-to/disable-avg-80-safe-search

ComboFix picked up a few things and you should be relatively clean now (be sure to keep running scans on a regular basis), but it's hard to say because it looks like you crack a lot of games, and these cracks and keygens are notorious for infecting users with viruses. If you keep up such activity, you will never keep your computer virus-free.

Also, you must be very careful with HJT because if you remove the wrong things, you can really screw up your system. Anyway, how is your computer running now? Any changes?The toolbar came with a paid subscription to AVG. I've used the free AVG before and decided to try the paid one. The info on the toolbar is here: http://www.grisoft.com/ww.product-avg-toolbar-tlbrc if you are interested.

I think my computer is running better now. Haven't had any freezes lately.

thanks for your help-
ChristyOkay, gotcha. I've never used the paid version, so I'm not entirely familiar with every feature. According to AVG's site, the toolbar comes with Active Surf-Shield and LinkScanner. Personally, I am against these extra features as they are known for causing a lot of lag with some users, so I would remove it. However, if you aren't experiencing any problems and/or you want the toolbar, it's not going to cause you any harm.

If you end up experiencing anymore problems, FEEL free to come back and we'll give it all another run-through. But if you're not having trouble, then you should be good to go. I think ComboFix is a HANDY program to keep around, but because it's constantly being updated, it's best to re-download it whenever you need it. So, let's go ahead and uninstall by going to Start > Run...then type in combofix /u and click on OK. Note the space between "combofix" and "/u".





Here are some additional procedures that you should follow to help with the security of your computer...
Next, let's clean your restore points and SET a new one:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Restart your computer.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.
System Restore will now be active again.

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SpywareGuard to catch and block spyware before it can execute.
  • IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.
To keep your operating system up to date visit here MONTHLY: And to keep your system clean run these free malware scanners weekly:
And be aware of what emails you open and websites you visit.

To learn more about how to protect yourself while on the internet, read this article by Tony Klein: So how did I get infected in the first place?Once again thanks a lot for your help. I completed this list of things to do and am good to go..I hope! lol

If anything else comes along I'll be back.

take care-
ChristySounds good to me. Best of luck to you!As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3011.

Solve : Is My Computer OK??

Answer»

Different computer...wanted to know if it's all good.
Logs attached.

[recovering disk space -- attachment deleted by admin]I will take a look and get back to you in a few minutes...Well, your HijackThis shows a couple of things that I would personally get rid of, but nothing that I consider malicious.

Your MBAM picked up a few nasty little buggers. Open up your Add/Remove Programs and look for the following entries:
AdwareAlert
RegistrySmart
Starware337


If you find these, uninstall them. If not, then you should be okay. I would suggest ditching McAfee for something BETTER, however, but that's my personal preference.none of those programs are there...am I ok?
Anything from hijack this to delete...if so...what?
Thanks.If those no longer exist, then you should be fine. You may want to download CCleaner (install without Yahoo! toolbar) and configure it according to this guide.

Quote from: bluecountry on August 06, 2008, 10:53:07 AM

Anything from hijack this to delete...if so...what?
That's up to you, really. I would get rid of all of the Verizon, Google, and Yahoo junk because it's just a bunch of CLUTTER in my opinion. And I would ditch McAfee for AVG and Comodo because these two programs have superior protection. But it's your call. These programs aren't malicious, I just think of them as subpar.

Also, from your IE browser, you should go to Tools > Windows Update so you can get the latest service pack.




Oh, and before I forget...
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Restart your computer.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.
System Restore will now be active again.Hmmm...what verzion and google, yahoo can I get rid of?

This computer has verizon internet, I'm afraid I might get rid of something important.
I also want to keep google earth.If you're okay with those being on your computer, then that's fine. You've just GOT a couple of toolbars that can sometimes cause lag in IE. But if you're not experiencing any problems, then I wouldn't worry about it.OK...all done.
Should the computer be in good shape...any tests I should run or that enough for today?


I had a few additional questions about CCleaner

1) When I Scan for Issues, I backup changes as told
-Once I have finished cleaning....is it ok to then delete the backups...I mean why keep this cluttering space?

2) How come when I Scan for issues
-I get usually many things popping up...even though I clean 1-2 times a week?
-Sometimes when I scan...and clean...I do a second scan right after...and new stuff POPS up...why is it this happens and is this odd?

Thanks.Quote
1) When I Scan for Issues, I backup changes as told
-Once I have finished cleaning....is it ok to then delete the backups...I mean why keep this cluttering space?

Personally I have stopped using the backups with CCleaner. (I'm not advising anybody to do this). I've come to trust the tool to be safe. The makers take great care in not removing too much, other more aggressive cleaners would likely find more junk, but the benefits performance wise of cleaning the Registry are not great enough to warrant such aggressive cleaning. If the PC restarts a few times with no problems then it is safe to delete the backups.

Quote
2) How come when I Scan for issues
-I get usually many things popping up...even though I clean 1-2 times a week?
-Sometimes when I scan...and clean...I do a second scan right after...and new stuff pops up...why is it this happens and is this odd?

There are many things you and Windows does that creates new registry entries, and just as many things leaves orphaned Registry keys. It's normal. Normally running the Registry cleaner a few times in succession is advised with CCleaner. It's along the lines of it not being too aggressive...

If you would like to clean even more with CCleaner check out the CCleaner winapp2.ini. It adds a hundred or so software applications under the CCleaner applications tab. All software creates some sort of junk that can be cleaned. The winapp2.ini file is an easy safe way to do so.



Thanks!As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3012.

Solve : Help with Trojan-Psw.onlinegames?

Answer»

As this issue appears to be RESOLVED, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any REASON, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, PLEASE start a New Topic with information about your computer and your problem.

3013.

Solve : Computer Doctor Needed!!?

Answer»

Here is the BDscan

[recovering disk space -- attachment deleted by admin]This is another log that will be huge. You may need to upload it to www.savefile.com then post the link to it back here.

Download to your desktop ISeeYouXP.exe by ShadowPuterDude
Next double-click on ISeeYouXP.exe, this should be on your desktop.

ISeeYouXP.exe will self-extract ISeeYouXP to C:\ISeeYouXP.

Using Windows Explorer (right click the Start button and select Explore to open Windows Explorer) navigate to C:\ISeeYouXP and locate:
ISeeYouXP.bat

Double-click ISeeYouXP.bat to run the script.

Post the following logs
ISeeYouXP

Upload the file to Savefile.com
There is no need to Register
Select Browse and locate the file.
Fill in the Title and Description and security code then click Upload
Copy the download link next to Your link to the file: and post the link back here.Ok, here you go.

http://www.savefile.com/files/1710177
Looks OK besides needing to tighten up a few security settings.

You can delete ISeeYouXP from C:\ISeeYouXP

----------

  • Start up IE then go to Tools > Internet Options > Security
  • Set the Security level for the Internet Zone to High. (If no slider is visible, click Default Level.)
  • Click the Trusted Sites icon.
  • Set the Security level for the this Zone to MEDIUM. (If no slider is visible, click Default Level.)
  • Click OK.
.
----------

Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

1. Double click OTMoveIt2.exe to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
5. Once complete exit out of OTMoveIt2

----------

Set a New Restore Point to PREVENT possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

----------

How is everything now?SWEET. So far everything seems good. I'm going to Microsoft to update the stuff i need updated. Also, is now a good time to update to sevice pack 3? Also, should i install my norton back on the computer?

When i go to my start button, the icon for IE is missing, looks just like a blank program file. Honestly I would leave Norton alone and stay with Avast! I also suggest installing a reliable firewall. Personally I use Comodo.

1) Comodo (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
2) Online Armor
3) Sunbelt/Kerio
4) Agnitum
5) PC Tools Firewall Plus

----------

You might wait a few days to be sure evrything is running OK before installing the SP3.

----------

Is the icon from the new IE 7 or is it there from IE 6?Should i reinstall Avast? When i click on it, it says that it's not a VALID Win32 application.

The icon is for IE7

Also, i still have a lot of icons on my deskstop from some of the .exe that we've ran. Would it be safe to delete?
Examples: Launch, dialafix, hostsxpert, iseeyouxp, fixpolicies, sdfix, CCleaner?

Also, should i continue to run Superantispyware, Malwarebytes and Spybot?

I will definitely take your advice for Comodo and Avast!! Oh, and with Avast and Comodo, should I purchase it or running the free verisions will be good enough? Keep CCleaner and use it to cleanup occasionally. Delete Launch, dialafix, hostsxpert, iseeyouxp, fixpolicies, sdfix.

Keep Superantispyware, Malwarebytes and Spybot and update then run them occasionally?

The free versions of Comodo and Avast are fine, try reinstalling Avast.

Install TweakUi - http://www.filehippo.com/download_tweakui/

There is a setting in there that says Rebuild Icons. Maybe that will fix the Icon problem.Ok, my icon is back and working. Could you send me a link to Avast? I did a search but it kept asking me to pay.

Glad the icon is FIXED.

Here is a link to Avast free - http://www.filehippo.com/download_avast_antivirus/Well, i have Comdo and Avast installed and running. Will i need to update Avast or will it do it on it's own whenever there are updates?

Also, on the system restore, should I have it checked for "Turned off" or have it unchecked?

Other than that, i think we've fixed it I appreciate your help so much, thanks a million times over. Avast will update on it's own. The only thing avast doesn't do on its own is automatic scans so if you want to scan you will need to open it and do one manually or follow this guide to set them automatically. Click here

Avast also has skins to change the appearance. http://www.avast.com/eng/skins.html

System Restore should be turned on, there should be no check mark. http://support.microsoft.com/kb/310405

As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3014.

Solve : Can't post logs?

Answer»

LOL. Strange.......

So all better?All over except for the splaining why that keyboard has been on since ever. Batteries aren't free ya know! lmao Yeah, we're all good. Thank you for everything.No prob. That's a strange but funny outcome! Weird things always happen with my computers. Back in ancient times when I had DSL, I could only ACESS email and a few websites. Naturally FIRST question from lvl 1 help desk, "Is it plugged in?" Duh! I'm online, sort of.

An hour into the conversation I noticed that the plug was only halfway plugged in. Sorta plugged in, sorta connected. I plugged the thing the rest of the way into the outlet, and my internet was restored to ALL it's glory. Well, all the glory that DSL is capable of.

When I told the poor help desk guy how I FIXED it, I thought he was gonna choke to death. Help desk dudes now run screaming from the room like they're on fire when I call.

That's enough out of me. I need some SLEEP. Goodnight.Goodnight to you too....
Be sure to call back if you have any more problems.

3015.

Solve : I got done by a nasty program?

Answer»

Hi

Found your site, whilst searching for a way to stop an Antivirus XP 2008 program from running.
It didn't allow me to go into control panel and delete (add remove programs).
It kept on putting up pops ups," running a scan and telling me I had 700+ viruses, it wouldn't let me open the internet browser (searched at work).

Followed your "remove this before requesting malware removal help"

Followed the instructions and the antivirus program has now stopped running, yippe, desktop page is a bit wonky, looks like an MS window is open and then has the desktop icons are overlayed. a little confusing.

So am now posting logs, forgive me if buggered up a little, not very comp literate



Look forward to hearing from you

Many thanks in advance

[recovering disk space -- attachment deleted by admin]You were infected with NewDotNet, so let's take care of that. MBAM found it and deleted the related files, but we should still look into it. First, download LSPFix.exe to a convenient LOCATION. Do NOT run this program yet. This is only to be used if you lose internet access after removing NewDotNet.

To get rid of NewDotNet, go to:

Start > Control Panel > Add or Remove Programs and remove the following:

NewDotNet or New.Net Applications or New.Net Domains (anything that says New.Net)

If it is not there, go here and follow Procedure 4: NewDotNet Removal Procedure 4.

In the event that you lose internet access after removing New.Net, please double-click LSPFix.exe that you downloaded earlier. You will see 2 panels. If there is any file listed in the "Remove" panel on the right-side, leave it as is and just click "Finish>>" then reboot your computer and you should now have access to the internet again. If nothing is listed under the "Remove" panel, do NOT do anything—just close the program.




While you're at it, download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls.



Post back with the ComboFix log and a new HijackThis log. Also, let me know how everything went with the New.Net instructions. MBAM may have removed it properly, but we need to make sure.Hello again

Followed your instructions and have the following to REPORT back.

No sign of newdotnet on control panel add/remove programs.
Hyperlink to removal program would not link.
Combofix when runs comes up with a date error and then stops.
So no log to post from that.

Did run Hijack again and the log is attached but not sure what use it'll be as not a lot has changed.

Cheers

[recovering disk space -- attachment deleted by admin]The time and date are off on the PC. HijackThis shows you ran the scan on 09/06/2008, which is 4 days ago. This probably means you haven't had any Windows updates for a while.

To change the time zone and enable automatic adjustment for DST

1. Right-click your system clock, and then click Adjust Date/Time.
2. Click the Time Zone tab. Click the list, and then click on your time zone.
3. SELECT the Automatically adjust clock for daylight saving changes check box, if your region uses daylight-saving time.
4. Click OK.

See here for details

Now try to run ComboFix again and post the log along with a new HijackThis log from after ComboFix has completed it's run.

3016.

Solve : looking for some trojan horse help?

Answer»

i reinstalled java, and flash, but still no pictures on ie5 if i right click and say show picture then they show up?Check here for possible solutions.

http://support.microsoft.com/default.aspx?kbid=283807thank you that fixed the picture issue, now the only issue i am finding is that while using IE5 or safari(XP version) pages will time out during loading much like when i try to SEND a reply on this site and it times out not sure what may be causing that.Download ATF Cleaner by Atribune to your Desktop.

Alternate download link

Note: Vista users must use Run As Administrator

  • Under Main: Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • Click Exit on the Main menu to close the program.
Note that your system will run slower for a reboot or two after having used this tool so don't panic.

Important: Restart the computer before continuing.

----------

Now delete ATF Cleaner. It isn't good for regular use.

Ant change?i am still timing out, and also how do i uninstall atf cleaner? just delete it? its on my desktop but i dont see a uninstall feature.Just delete it. It doesn't actually install.

Do you have an XP CD?

If so, PLACE it in your CD ROM drive and follow the instructions below:
  • Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
    • Let this run undisturbed until the window with the blue progress bar goes away
SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.

If you want to see what was replaced, right-click My Computer and click on Manage.
In the new window that appears, expand the Event Viewer (by clicking on the + SYMBOL next to it) and then click on System.
3017.

Solve : Infected by Trojan Horse??

Answer»

Hi, I've recently witnessed a trojan horse and Avast removed it. I am not sure if it really worked. Heres my log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:22:38 PM, on 8/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1218396901500
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0076101218394470) (0076101218394470mcinstcleanup) - Unknown owner - C:\DOCUME~1\Terry\LOCALS~1\Temp\007610~1.EXE (file MISSING)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

--
End of file - 6197 bytes



Malwarebytes' Anti-Malware 1.24
Database version: 1038
Windows 5.1.2600 Service Pack 3

7:21:32 PM 8/10/2008
mbam-log-8-10-2008 (19-21-32).txt

Scan type: Quick Scan
Objects scanned: 61364
Time elapsed: 15 MINUTE(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


uninstall list
Adobe AIR
Adobe AIR
Adobe Flash Player ActiveX
Adobe Reader 9
Adobe Shockwave Player
AIM 6
ATI - Software Uninstall Utility
ATI Display Driver
avast! Antivirus
CCleaner (remove only)
C-Media 3D Audio
C-Media WDM Audio Driver
Gunbound Revolution
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
ijji - Gunz
Intel(R) 537EP Modem
Java(TM) 6 Update 7
LimeWire PRO 4.12.4
Malwarebytes' Anti-Malware
McAfee SiteAdvisor
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft User-Mode Driver Framework Feature Pack 1.0
Mozilla Firefox (3.0.1)
Nero 7 Premium
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Spybot - Search & Destroy
SpywareBlaster 4.1
Update for Windows XP (KB942763)
VIA Platform Device Manager
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
WinPatrol 2008
WinRAR archiver

Looks good except for this.

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O23 - Service: McAfee Application Installer Cleanup (0076101218394470) (0076101218394470mcinstcleanup) - Unknown owner - C:\DOCUME~1\Terry\LOCALS~1\Temp\007610~1.EXE (file missing)

Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Is everything running OK now?THANKS a bunch. It is properly running. I've applied for schools in your topic and they haven't answered for a long time. Am i rejected?It can take some time for them to answer.

Use the Secunia Software Inspector to check for out of date software.

  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

----------

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
3018.

Solve : Shocking, Torjan Vundo help please... >:(?

Answer»

ComboFix 08-08-08.07 - Kenneth L. JAMES II 2008-08-09 7:31:33.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.340 [GMT -4:00]
Running from: C:\cf2332\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Kenneth L. James II\Application Data\inst.exe
C:\Documents and Settings\Kristin\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Program Files\Altnet
C:\WINDOWS\system32\aepeolid.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\bwmitnji.dll
C:\WINDOWS\system32\fmtujkfb.ini
C:\WINDOWS\system32\fvtqkihe.ini
C:\WINDOWS\system32\gpidridc.ini
C:\WINDOWS\system32\jpnnjm.dll
C:\WINDOWS\system32\khsshmnl.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\nkpejpgh.ini
C:\WINDOWS\system32\pekilt.dll
C:\WINDOWS\system32\pomoscds.dll
C:\WINDOWS\system32\prcnsz.dll
C:\WINDOWS\system32\pvskwykr.ini
C:\WINDOWS\system32\skhhfwwf.ini
C:\WINDOWS\system32\srylkl.dll
C:\WINDOWS\system32\tmrsqopu.dll
C:\WINDOWS\system32\yiwsmjmo.dll

.
((((((((((((((((((((((((( Files Created from 2008-07-09 to 2008-08-09 )))))))))))))))))))))))))))))))
.

2008-08-09 07:29 . 2008-08-09 07:29d--------C:\cf2332
2008-08-09 07:17 . 2008-08-09 07:17d--------C:\WINDOWS\LastGood
2008-08-08 08:25 . 2008-08-08 08:25d--------C:\WINDOWS\system32\scripting
2008-08-08 08:25 . 2008-08-08 08:25d--------C:\WINDOWS\system32\en
2008-08-08 08:25 . 2008-08-08 08:25d--------C:\WINDOWS\system32\bits
2008-08-08 08:25 . 2008-08-08 08:25d--------C:\WINDOWS\l2schemas
2008-08-08 08:22 . 2008-08-08 08:25d--------C:\WINDOWS\ServicePackFiles
2008-08-08 08:17 . 2008-08-08 08:441,355--a------C:\WINDOWS\imsins.BAK
2008-08-08 08:14 . 2008-08-08 08:14d--------C:\WINDOWS\EHome
2008-08-08 08:07 . 2008-04-13 20:121,737,856---------C:\WINDOWS\system32\mtxparhd.dll
2008-08-08 08:06 . 2008-04-13 20:111,888,992---------C:\WINDOWS\system32\ati3duag.dll
2008-08-08 08:05 . 2008-04-13 20:11136,192---------C:\WINDOWS\system32\aaclient.dll
2008-08-08 08:05 . 2008-04-13 20:114,255---------C:\WINDOWS\system32\drivers\adv01nt5.dll
2008-08-08 08:05 . 2008-04-13 20:113,967---------C:\WINDOWS\system32\drivers\adv02nt5.dll
2008-08-08 08:05 . 2008-04-13 20:113,775---------C:\WINDOWS\system32\drivers\adv11nt5.dll
2008-08-08 08:05 . 2008-04-13 20:113,711---------C:\WINDOWS\system32\drivers\adv09nt5.dll
2008-08-08 08:05 . 2008-04-13 20:113,647---------C:\WINDOWS\system32\drivers\adv07nt5.dll
2008-08-08 08:05 . 2008-04-13 20:113,615---------C:\WINDOWS\system32\drivers\adv05nt5.dll
2008-08-08 08:05 . 2008-04-13 20:113,135---------C:\WINDOWS\system32\drivers\adv08nt5.dll
2008-08-08 07:35 . 2008-08-08 07:35d--------C:\Program Files\Sun
2008-08-08 07:34 . 2008-06-10 02:3273,728--a------C:\WINDOWS\system32\javacpl.cpl
2008-08-08 07:32 . 2008-08-08 07:34d--------C:\Program Files\Java
2008-08-08 07:31 . 2008-08-08 07:31d--------C:\Program Files\Common Files\Java
2008-08-07 23:07 . 2008-08-07 23:07d--------C:\Program Files\Trend Micro
2008-08-07 22:36 . 2008-08-07 22:36d--------C:\Program Files\Malwarebytes' Anti-Malware
2008-08-07 22:36 . 2008-08-07 22:36d--------C:\Documents and Settings\Kenneth L. James II\Application Data\Malwarebytes
2008-08-07 22:36 . 2008-08-07 22:36d--------C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-07 22:36 . 2008-07-30 20:0738,472--a------C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-07 22:36 . 2008-07-30 20:0717,144--a------C:\WINDOWS\system32\drivers\mbam.sys
2008-08-07 17:25 . 2008-08-07 17:25d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-08-07 17:24 . 2008-08-07 17:24d--------C:\Program Files\SUPERAntiSpyware
2008-08-07 17:24 . 2008-08-07 17:24d--------C:\Documents and Settings\Kenneth L. James II\Application Data\SUPERAntiSpyware.com
2008-08-07 17:16 . 2008-08-07 17:16d--------C:\Program Files\CCleaner
2008-07-31 23:31 . 2008-07-31 23:31131--a------C:\Documents and Settings\Kenneth L. James II\reset.cmd
2008-07-29 09:59 . 2008-08-09 07:1410,837--a------C:\WINDOWS\system32\Config.MPF
2008-07-29 09:58 . 2006-03-03 08:07143,360--a------C:\WINDOWS\system32\dunzip32.dll
2008-07-29 09:54 . 2007-11-22 06:44201,320--a------C:\WINDOWS\system32\drivers\mfehidk.sys
2008-07-29 09:54 . 2007-07-13 06:20113,952--a------C:\WINDOWS\system32\drivers\Mpfp.sys
2008-07-29 09:54 . 2007-11-22 06:4479,304--a------C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-07-29 09:54 . 2007-12-02 12:5140,488--a------C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-07-29 09:54 . 2007-11-22 06:4435,240--a------C:\WINDOWS\system32\drivers\mfebopk.sys
2008-07-29 09:54 . 2007-11-22 06:4433,832--a------C:\WINDOWS\system32\drivers\mferkdk.sys
2008-07-29 09:09 . 2008-07-29 09:09d--------C:\Documents and Settings\Kenneth L. James II\Application Data\McAfee
2008-07-27 15:08 . 2008-07-27 15:08d--------C:\Documents and Settings\Kenneth L. James II\Application Data\MSNInstaller
2008-07-24 22:29 . 2008-07-24 22:29d--------C:\VundoFix Backups
2008-07-24 18:25 . 2008-07-24 18:25d--------C:\Program Files\Windows Defender
2008-07-24 17:20 . 2008-07-29 09:53d--------C:\Program Files\McAfee.com
2008-07-24 17:20 . 2008-07-24 17:26d--------C:\Program Files\McAfee
2008-07-24 17:20 . 2008-07-29 09:54d--------C:\Program Files\Common Files\McAfee
2008-07-22 10:59 . 2008-07-22 10:59d--------C:\WINDOWS\McAfee.com
2008-07-17 12:13 . 2008-07-17 12:14d--------C:\Program Files\Dell Support Center
2008-07-17 09:36 . 2008-07-17 09:3654,156--ah-----C:\WINDOWS\QTFont.qfn
2008-07-17 09:36 . 2008-07-17 09:361,409--a------C:\WINDOWS\QTFont.for
2008-07-17 08:05 . 2008-07-17 08:12d--------C:\WINDOWS\system32\aumsDK01
2008-07-17 08:05 . 2008-07-17 08:05d--------C:\Temp\zpv201
2008-07-17 08:05 . 2008-07-17 08:05d--------C:\Temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-09 11:19---------d-----wC:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-09 11:15---------d-----wC:\Program Files\YPOPs
2008-08-08 11:37---------d-----wC:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-08 11:36---------d-----wC:\Documents and Settings\Kenneth L. James II\Application Data\Lavasoft
2008-08-07 21:31---------d-----wC:\Program Files\Google
2008-08-07 21:23---------d-----wC:\Program Files\Common Files\Wise Installation Wizard
2008-08-07 21:12---------d-----wC:\Program Files\Common Files\SupportSoft
2008-08-07 21:12---------d-----wC:\Documents and Settings\All Users\Application Data\SupportSoft
2008-07-29 13:01---------d-----wC:\Program Files\Yahoo!
2008-07-29 13:01---------d-----wC:\Documents and Settings\All Users\Application Data\Yahoo!
2008-07-29 12:56---------d-----wC:\Program Files\Jasc Software Inc
2008-07-24 22:29---------d-----wC:\Documents and Settings\All Users\Application Data\Dell
2008-07-24 21:27---------d-----wC:\Documents and Settings\All Users\Application Data\McAfee
2008-07-24 21:00---------d-----wC:\Program Files\Symantec
2008-07-23 22:07---------d-----wC:\Program Files\Common Files\Symantec Shared
2008-07-23 22:03---------d--h--wC:\Program Files\InstallShield Installation Information
2008-07-22 15:04---------d-----wC:\Program Files\ComcastToolbar
2008-07-22 15:04---------d-----wC:\Documents and Settings\Kenneth L. James II\Application Data\ComcastToolbar
2008-07-05 12:59---------d-----wC:\Documents and Settings\All Users\Application Data\Comcast
2008-06-20 17:46245,248----a-wC:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46245,248------wC:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46147,968------wC:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51361,600----a-wC:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:51361,600------wC:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40138,496----a-wC:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:40138,496------wC:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08225,856----a-wC:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 11:08225,856------wC:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 12:19---------d-----wC:\Documents and Settings\Kristin\Application Data\COMCASTTOOLBAR
2008-06-13 12:18---------d-----wC:\Documents and Settings\Kristin\Application Data\Yahoo!
2008-06-13 11:05272,128----a-wC:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 11:05272,128------wC:\WINDOWS\system32\dllcache\bthport.sys
2008-06-01 13:3847,360----a-wC:\Documents and Settings\Kenneth L. James II\Application Data\pcouffin.sys
2008-05-09 23:23135,168----a-wC:\WINDOWS\system32\SET55.tmp
2008-05-09 10:5390,112----a-wC:\WINDOWS\system32\wshext.dll
2008-05-09 10:5390,112------wC:\WINDOWS\system32\dllcache\wshext.dll
2008-05-09 10:53512,000----a-wC:\WINDOWS\system32\SET5B.tmp
2008-05-09 10:53512,000------wC:\WINDOWS\system32\dllcache\jscript.dll
2008-05-09 10:53430,080----a-wC:\WINDOWS\system32\SET58.tmp
2008-05-09 10:53430,080------wC:\WINDOWS\system32\dllcache\vbscript.dll
2008-05-09 10:53180,224----a-wC:\WINDOWS\system32\scrobj.dll
2008-05-09 10:53180,224------wC:\WINDOWS\system32\dllcache\scrobj.dll
2008-05-09 10:53172,032----a-wC:\WINDOWS\system32\SET59.tmp
2008-05-09 10:53172,032------wC:\WINDOWS\system32\dllcache\scrrun.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-06-02 16:56160496--a------C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 07:03 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 07:03 81920]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36 114688]
"Auto EPSON Stylus CX3800 Series on DADS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE" [2005-02-07 15:00 98304]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-06-21 13:40 172032]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544]

C:\Documents and Settings\Kenneth L. James II\Start Menu\Programs\Startup\
YPOPs.lnk - C:\Program Files\YPOPs\YPOPs.exe [2008-07-28 23:03:26 1327104]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-08-29 16:33:24 499779]

[hkey_local_machine\software\microsoft\windows\currentversion\EXPLORER\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2007-03-15 11:09 460784 C:\Program Files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
--a------ 2007-11-15 09:23 202544 C:\Program Files\Dell Support Center\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
--a------ 2007-11-15 09:24 16384 C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2002-01-08 12:24 401496 C:\Program Files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component MANAGER]
--a--c--- 2004-05-12 15:18 241664 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a--c--- 2004-02-12 13:38 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
---hs---- 2008-04-13 20:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-08-23 11:42 98304 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2005-08-23 11:42 26112 C:\Program Files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2004-10-14 20:42 1404928 C:\Program Files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys [2006-08-20 16:20]
R3 uscsc108;uscsc108;C:\WINDOWS\system32\DRIVERS\uscsc108.sys [2003-03-09 19:41]

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-08-06 C:\WINDOWS\Tasks\dfrg.job
- C:\WINDOWS\system32\dfrg.msc [2004-08-04 06:00]

2008-07-24 C:\WINDOWS\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2008-08-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2008-08-09 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-OCAudioIni - C:\Program Files\One-click Audio Converter\OCAudioIni.exe
MSConfigStartUp-xloadnet - C:\Program Files\xloadnet\xloadnet.exe


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Kenneth L. James II\Application Data\Mozilla\Firefox\Profiles\jercr24b.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1172.2021\npCIDetect11.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-09 07:36:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-09 7:39:02
ComboFix-quarantined-files.txt 2008-08-09 11:38:15

Pre-Run: 5,340,323,840 bytes free
Post-Run: 5,661,806,592 bytes free

264--- E O F ---2008-08-09 11:27:30
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:46:54 AM, on 8/9/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\YPOPs\YPOPs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://v4.windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Auto EPSON Stylus CX3800 Series on DADS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P39 "Auto EPSON Stylus CX3800 Series on DADS" /O15 "\\DADS\EPSONSty" /M "Stylus CX3800"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: YPOPs.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) - http://webiq005.webiqonline.com/WebIQ/DataServer/Pub/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5348/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

--
End of file - 9391 bytes
Your HJT looks clean. I would run keep running the SUPERAntiSpyware and MBAM scans, but you should be okay.

To uninstall ComboFix, simply go to Start > Run and type in combofix /u (note the space between "combofix" and "/u") and click on OK. As for VundoFix and VirtumondoBeGone, you can simply delete them. You can also uninstall HijackThis if you'd like, but I would keep it.

Next, reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Restart your computer.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.

System Restore will now be active again.

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:

  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SpywareGuard to catch and block spyware before it can execute.
  • IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.
To keep your operating system up to date visit here monthly: And to keep your system clean run these free malware scanners weekly:
And be aware of what emails you open and websites you visit.

To learn more about how to protect yourself while on the internet, read this article by Tony Klein: So how did I get infected in the first place?Matt, thanks! cpu seems to be working well... i downloaded the programs you reccommended... should i remove mcafee (free with internet) and windows defender (downloaded it for XP)?That's up to you, really. I think McAfee is subpar, but if you want to keep it, then feel free. However, if you wish to remove McAfee, then you should follow the instructions on this page. As a replacement, Avast! and AVG are GOOD free programs.

As for Windows Defender...I would that SUPERAntiSpyware is a much better program, but it is okay to have both programs (just don't run them at the same time), so the decision is yours.
3019.

Solve : Computer is: Freezing, Slowing Down, Randomly Restarting (+Multiple Keyloggers)?

Answer»

Lately without warning I have been having issues where my computer gets a little slower. If I am playing an online game my latency skyrockets to the high 800's and sometimes low 1000. Then later I could be doing anything and suddenly my computer freezes and not knowing what to do I will press my "Turbo Reset" button located on the front of my tower. After the computer completely reboots I will notice my cursor "skips", just as a record does when scratched or warped, and it won't go away for awhile. Soon after that issue the cycle restarts and my computer freezes or on rare occasion it will restart itself but not without alerting me with a black screen that covers the screen.

-Following Step 1 of the "Malware Removal Steps", I looked through and saw a few programs I am familiar with and the rest I haven't a CLUE what they are. Here are two screen shots of the list, perhaps someone can help me identify them and determine if they are needed/malicious.
http://i211.photobucket.com/albums/bb221/sjn2009/AoRP1.jpg
http://i211.photobucket.com/albums/bb221/sjn2009/AoRP2.jpg
-I completed Step 2 without any problems.
-I completed Step 3 without any problems, it did find some files and removed them.
-I completed Step 4 and had a few problems. While it was running AVG kept giving me threat pop-ups about different keyloggers found such as "msni.exe" and some .delf thing. However MBAM did not detect anything.
-I completed Step 5 and my Java is the most recent.
-I completed Step 6 and have begun my own forum post.

SAS Log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/08/2008 at 01:38 PM

Application Version : 4.15.1000

Core Rules Database Version : 3530
Trace Rules Database Version: 1520

Scan type : Complete Scan
Total Scan Time : 01:08:51

Memory items scanned : 402
Memory threats detected : 0
Registry items scanned : 4906
Registry threats detected : 18
File items scanned : 48094
File threats detected : 2

Trojan.Media-Codec
HKU\S-1-5-21-117609710-492894223-1957994488-1003\Software\Internet Security

Malware.AntiVermins
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\aknDdscbo
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\bYjgwbahhrqi
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\cvttim
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\eyqjtbFqHs
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\HdNY
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\HpreavpflQXOj
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\InprocServer32
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\InprocServer32#ThreadingModel
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\jdqjcJgUclo
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\jttrLkEhnc
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\mdjtbncn
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\nyezeiA
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\qizBNmisxuqRd
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\uaLpi
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\vgummv
HKCR\CLSID\{663DE629-4FFD-A944-6F0A-64F98E925B62}\WczkzdtL

Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt

Trojan.Downloader-Gen/Suspicious
C:\PROGRAM FILES\WINRAR\SETUP&CABPACKER\FEWIZARD.EXE

MBAM log:
Malwarebytes' Anti-Malware 1.24
Database version: 1012
Windows 5.1.2600 Service Pack 2

3:01:22 PM 8/8/2008
mbam-log-8-8-2008 (15-01-22).txt

Scan type: Quick Scan
Objects scanned: 44073
Time elapsed: 16 minute(s), 13 SECOND(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:09:14 PM, on 8/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,[emailprotected]
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Wireless Connection Manager.lnk = C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: Fly - smart.dll (file missing)
O20 - Winlogon Notify: Love - LoveFly.dll (file missing)
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 6750 bytes


[recovering disk space -- attachment deleted by admin]After having my computer on for a few hours while doing the scans, cleaning up some old picutres/music and such I noticed my computer hadn't froze once... So I thought I could try to play my game but to my demise 4 minutes into the game my computer froze.

So it seems I only have the freezing problem when playing games, so perhaps malware isn't causing it but I don't want to rule that out until I get some help. Because it's apparent I have something on my computer or AVG wouldn't keep detecting things randomly.I'm assuming World of Warcraft is the one giving you the most trouble? One of your infections was designed to try to steal account information from WoW players. It should be gone, according to HJT, let's err on the side of caution here.

There are a few things that I want you to do...

1. Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file. Open HijackThis and scan again. Check the following entries, but don't do anything to them yet...

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O20 - Winlogon Notify: Fly - smart.dll (file missing)
O20 - Winlogon Notify: Love - LoveFly.dll (file missing)


Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and reboot into Safe Mode and enable hidden files and folders.

Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)...

Java(TM) 6 Update 5
Java(TM) 6 Update 3
Java(TM) SE Runtime Environment 6
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 8
J2SE Runtime Environment 5.0 Update 9


Note: These programs are safe, but old versions of Java should be deleted, as they may cause a security risk and they take up a lot of space. Do not remove Java(TM) 6 Update 7!

Navigate to and delete the following file(s) if present...

C:\WINDOWS\system32\smart.dll
C:\WINDOWS\system32\LoveFly.dll


Once you've done all of this, reboot into Normal Mode and follow the next step...



2. Download Dr.Web CureIt! & save it to your desktop.

  • Double-click on cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
  • Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the "Scan tab" and UNcheck "Heuristic analysis"
  • Back at the main window, click "Custom Scan", then "Select drives" (a red dot will show which drives have been chosen).
  • Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
  • When done, a message will be displayed at the bottom advising if any viruses were found.
  • Click "Yes to all" if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
    (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine FOLDER if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
You can use Notepad to open the DrWeb.cvs report by right clicking it and selecting Open with > Notepad
(Courtesy of evilfantasy.)



3. Download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls.




In your next post, I would like to see the logs from ComboFix and Dr. Web Cureit, along with a fresh new HijackThis log.Just a quick update and a side issue I'll need help with after I get these problems taken care of... The reason my computer "Freezes" during game play is because the fan on my graphics card isnt moving. So the card just overheats because of all the advanced graphics in the game. I assume this is very dangerous for me to play anything without repairing. So if someone could help me figure out that issue later that would be great.
The Dr.Web thing is taking forever but I will have the log soon.Ok finished all steps you have given me. Here are the logs.

DrWeb Log:
aolconnfix.exe;C:\;Trojan.PWS.Gamania.origin;Incurable.Moved.;
A0286869.exe;C:\ErdUndoCache\rp336;Program.mIRC.621;Moved.;
SpWizard.exe;C:\Program Files\WinRAR\Setup&CabPackerTrojan.Click.17167;Deleted.;

ComboFix Log:
ComboFix 08-08-09.03 - Dianne 2008-08-09 20:11:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.208 [GMT -5:00]
Running from: C:\Documents and Settings\Dianne\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Dianne\Application Data\inst.exe
C:\Documents and Settings\Dianne\Application Data\macromedia\Flash Player\#SharedObjects\8WYGXRH4\interclick.com
C:\Documents and Settings\Dianne\Application Data\macromedia\Flash Player\#SharedObjects\8WYGXRH4\interclick.com\ud.sol
C:\Documents and Settings\Dianne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Dianne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_000004_.tmp.dll
C:\WINDOWS\system32\disk.dll

.
((((((((((((((((((((((((( Files Created from 2008-07-10 to 2008-08-10 )))))))))))))))))))))))))))))))
.

2008-08-09 06:41 . 2008-08-09 06:58d--------C:\Documents and Settings\Dianne\DoctorWeb
2008-08-08 12:24 . 2008-08-08 12:24d--------C:\Program Files\SUPERAntiSpyware
2008-08-08 12:24 . 2008-08-08 12:24d--------C:\Documents and Settings\Dianne\Application Data\SUPERAntiSpyware.com
2008-08-08 12:24 . 2008-08-08 12:24d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-08-06 09:37 . 2008-07-30 20:0738,472--a------C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-25 21:44 . 2008-07-25 21:44d--------C:\Documents and Settings\All Users\Application Data\vsosdk
2008-07-25 21:42 . 2008-07-25 21:42d--------C:\Program Files\VSO
2008-07-25 21:42 . 2004-05-04 12:531,645,320--a------C:\WINDOWS\gdiplus.dll
2008-07-25 21:42 . 2006-05-20 17:161,184,984--a------C:\WINDOWS\system32\wvc1dmod.dll
2008-07-25 21:42 . 2006-05-11 20:21626,688--a------C:\WINDOWS\system32\vp7vfw.dll
2008-07-25 21:42 . 2006-09-29 13:24217,127--a------C:\WINDOWS\system32\drv43260.dll
2008-07-25 21:42 . 2006-09-29 13:25208,935--a------C:\WINDOWS\system32\drv33260.dll
2008-07-25 21:42 . 2006-09-29 13:26176,165--a------C:\WINDOWS\system32\drv23260.dll
2008-07-25 21:42 . 2007-03-18 21:3765,602--a------C:\WINDOWS\system32\cook3260.dll
2008-07-25 19:04 . 2008-07-25 19:04d--------C:\WINDOWS\WinAVI Video Converter 9.0
2008-07-25 19:04 . 2008-07-25 19:05d--------C:\Program Files\WinAVI Video Converter 9.0
2008-07-25 18:14 . 2008-07-25 21:03d--------C:\Program Files\Common Files\Nero
2008-07-24 20:23 . 2004-03-09 00:00212,240--a------C:\WINDOWS\system32\richtx32.ocx
2008-07-24 20:23 . 2000-05-19 17:5681,920--a------C:\WINDOWS\system32\mbmouse.ocx
2008-07-24 20:23 . 2007-08-31 18:3636,864--a------C:\WINDOWS\system32\trayicon_handler.ocx
2008-07-23 16:31 . 2008-07-23 16:31d--------C:\Program Files\Bonjour

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-10 01:10---------d-----wC:\Program Files\Trillian
2008-08-09 11:35---------d-----wC:\Program Files\Java
2008-08-08 17:23---------d-----wC:\Program Files\Common Files\Wise Installation Wizard
2008-08-08 15:18---------d-----wC:\Documents and Settings\Dianne\Application Data\Vso
2008-08-08 15:02---------d-----wC:\Program Files\World of Warcraft
2008-08-06 14:41---------d-----wC:\Program Files\Malwarebytes' Anti-Malware
2008-07-31 01:0717,144----a-wC:\WINDOWS\system32\drivers\mbam.sys
2008-07-26 02:4247,360----a-wC:\WINDOWS\system32\drivers\pcouffin.sys
2008-07-26 02:4247,360----a-wC:\Documents and Settings\Dianne\Application Data\pcouffin.sys
2008-07-23 21:33---------d-----wC:\Program Files\iTunes
2008-07-23 21:32---------d-----wC:\Program Files\iPod
2008-07-23 21:30---------d-----wC:\Program Files\QuickTime
2008-07-12 18:25---------d-----wC:\Documents and Settings\All Users\Application Data\Avg8
2008-07-09 03:32---------d-----wC:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-07 05:37---------d-----wC:\Documents and Settings\Dianne\Application Data\mIRC
2008-07-03 14:5476,040----a-wC:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-03 14:5396,520----a-wC:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-03 14:5310,520----a-wC:\WINDOWS\system32\avgrsstx.dll
2008-06-28 04:300---ha-wC:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-28 04:300---ha-wC:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-06-28 04:24---------d-----wC:\Program Files\Common Files\LogiShared
2008-06-28 04:24---------d-----wC:\Documents and Settings\Dianne\Application Data\Logitech
2008-06-28 04:22---------d-----wC:\Program Files\Common Files\Logitech
2008-06-28 04:21---------d--h--wC:\Program Files\InstallShield Installation Information
2008-06-28 04:21---------d-----wC:\Program Files\Logitech
2008-06-28 04:21---------d-----wC:\Documents and Settings\All Users\Application Data\Logitech
2008-06-28 04:20---------d-----wC:\Documents and Settings\All Users\Application Data\LogiShrd
2008-06-25 16:11---------d---a-wC:\Documents and Settings\All Users\Application Data\TEMP
2008-06-20 17:41245,248----a-wC:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45360,320----a-wC:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44138,368----a-wC:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52225,920----a-wC:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10272,128------wC:\WINDOWS\system32\drivers\bthport.sys
2008-06-03 00:5641,296----a-wC:\WINDOWS\system32\xfcodec.dll
2008-05-27 02:337,680----a-wC:\WINDOWS\system32\ff_vfw.dll
2008-05-27 02:3360,273----a-wC:\WINDOWS\system32\pthreadGC2.dll
2008-05-13 01:49161,096----a-wC:\WINDOWS\system32\DivXCodecVersionChecker.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-09 16:41 69632]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-03 09:54 1232152]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 09:01 437160]

C:\Documents and Settings\Dianne\Start Menu\Programs\Startup\
Trillian.lnk - C:\Program Files\Trillian\trillian.exe [2007-12-11 1222144]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-06-27 23:22:05 692224]
Wireless Connection Manager.lnk - C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe [2008-06-03 12:19:10 20525056]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
"VIDC.XFR1"= xfcodec.dll
"aux1"= ctwdm32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^traywc.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\traywc.exe
backup=C:\WINDOWS\pss\traywc.exeCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gnetmous]
--a------ 2002-11-26 15:30 153600 C:\Program Files\COMPAQ\Scroll Mouse\gnetmous.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-10 10:51 289064 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 02:41 8523776 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 02:41 81920 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-10-12 04:10 49263 C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"NVSvc"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"dlbt_device"=3 (0x3)
"AOL ACS"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe"
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" -hide

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\World of Warcraft\\Repair.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-03 09:53]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-03 09:54]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-03 09:53]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-03 09:54]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 02:56]
R3 JSWSCIMD;jswscimd Service;C:\WINDOWS\system32\DRIVERS\jswscimd.sys [2007-07-06 16:30]
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\Documents and Settings\Dianne\Desktop\misc\sex\IlvMoney1148.sys []
S3 rpqkfx;rpqkfx;C:\Documents and Settings\Dianne\Desktop\The Stuff\MMOGlider\rpqkfx.sys []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-04-19 09:56]
S3 WSIMD;wsimd Service;C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-07-03 11:46]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdxREG_MULTI_SZ sysagent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{30AC43C3-9F9B-C710-092B-0316EF1F69E4}]
C:\WINDOWS\system32\smsss.exe s

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
Contents of the 'Scheduled Tasks' folder

2008-08-10 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 14:24]

2008-08-03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

2008-08-10 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-MSMSGS - C:\Program Files\Messenger\msmsgs.exe
MSConfigStartUp-RealTray - C:\Program Files\Real\RealPlayer\RealPlay.exe
MSConfigStartUp-Steam - C:\Program Files\Steam\Steam.exe


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Dianne\Application Data\Mozilla\Firefox\Profiles\rkgflapl.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.aol.com/aolcom/search?invocationType=tbff50ie7&query=
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-09 20:15:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBTCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,[emailprotected]??

scanning hidden files ...


C:\WINDOWS\TEMP\b4cd3ab5-2b8a-4c86-995a-1bfd140f0f28.tmp 0 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2008-08-09 20:18:49
ComboFix-quarantined-files.txt 2008-08-10 01:18:20

Pre-Run: 18,452,893,696 bytes free
Post-Run: 18,448,756,736 bytes free

233--- E O F ---2008-08-05 18:00:14


[recovering disk space -- attachment deleted by admin]Also my brother gave me an unopened "Vcool" from Antec fan that fits where 2 normal PCI slots go so I'm hoping putting that in can help my over heat issue. However im still looking for ideas on how to fix the Graphics card built in fan. I went to a local computer store and they said they didnt have much to over for a "nVidia GeForce 6600 GT" other than a DIY Cooling system which to me looked like something I made in a welding class once.

Any thoughts there? But ofc the computers safety is priority to my game playing.Those scans should've helped. Go ahead and post a final HijackThis log so I can make sure you're clean.


As for your hardware issue, this is definitely a problem and you should resolve it as fast as you can. Installing that other fan should help out quite a bit. It may be possible to find the necessary parts on eBay, so you can also fix the fan for your graphics card. Unfortunately, my specialty is malware removal...I'm not much of a hardware wizard. You should go ahead and post about this in the Hardware section of our forum, and I'm sure somebody will be able to give you the help/advice you need.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:14 AM, on 8/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TuneUp Utilities 2008\RegistryCleaner.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,[emailprotected]
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Wireless Connection Manager.lnk = C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 6034 bytes



I unplugged my computer to install the new fan and when I came back AVG now says Anti-Virus and Anti-Spyware are out of date... So I tried to update and it said there are no new updates. Any idea whats wrong there?

[recovering disk space -- attachment deleted by admin]Your log looks clean...however, there is something that I just noticed. Before I give you the clean bill of health, I want to check for a CoolWebSearch infection...

Download CWShredder here to its own folder.

Update CWShredder
  • Open CWShredder and click I Agree
  • Click Check For Updates
  • Close CWShredder
Boot into Safe Mode:
Restart your computer and as soon as it starts booting up again, continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Now run CWShredder. Click I Agree, then Fix, and then Next. Let it fix everything it asks about. Reboot your computer back into Normal Mode.




Let me know how that goes and post yet another log (sorry, but I need to make sure). As for AVG, it's hard to say what the problem might be because the new AVG has a lot of issues. Do you have AVG 8 and AVG Anti-Spyware, or do you simply have the Anti-Spyware that comes bundled with AVG 8? If you have the two programs installed separately, that can cause a lot of problems. If that's not the case, then there's no telling what the problem might be. I would suggest stopping by the AVG forum to ask about that because they would have a better idea of what might be going on.The CWShredder link doesn't seem to be working. But I got it off http://www.intermute.com/products/cwshredder.html
But the AVG issue solved when I restarted my computer. I think it might have been due to the fact that the clock was an hour behind in the year 2088.I pressed Check for Update and it resulted with this in the text box above:
"Checking for a new version of CWShredder from Trend Micro.

Unable to check for updates."

--
So I did the rest of the steps anyways and heres the resulting log (It said no CoolWebSearch found):

**** Run Keys ****

RUN: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,[emailprotected]
RUN: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
RUN: [nwiz] nwiz.exe /install
RUN: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
RUN: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
RUN: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
RUN: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
RUN: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
RUN: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
RUN: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
RUN: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


**** Browser Helper Objects ****

BHO: [Adobe PDF Reader Link Helper] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: [AVG Safe Search] C:\Program Files\AVG\AVG8\avgssie.dll
BHO: [SSVHelper Class] C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll


**** IE Toolbars ****



**** IE Extensions ****

IEExt: []
IEExt: [Research]


**** Hosts File Entries ****

HOSTS: 127.0.0.1 localhost
HOSTS: 127.0.0.1 localhost


**** IE Settings ****

Default Page: http://go.microsoft.com/fwlink/?LinkId=69157
Default Search: http://go.microsoft.com/fwlink/?LinkId=54896
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch


**** IE Context Menu (Right click) ****



**** Layered Service Providers ****

LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3022AA27-72BA-479E-8D38-CF7DC5BE32DD}] SEQPACKET 7
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3022AA27-72BA-479E-8D38-CF7DC5BE32DD}] DATAGRAM 7
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A3E322ED-51B9-4CFA-BA13-D3960FB219DA}] SEQPACKET 6
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A3E322ED-51B9-4CFA-BA13-D3960FB219DA}] DATAGRAM 6
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{52C33D97-83FB-4B51-AF87-B1E3804A163A}] SEQPACKET 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{52C33D97-83FB-4B51-AF87-B1E3804A163A}] DATAGRAM 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{58B9E5FB-7425-4BEA-86B5-9A965B09BFD8}] SEQPACKET 5
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{58B9E5FB-7425-4BEA-86B5-9A965B09BFD8}] DATAGRAM 5
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{48705128-C97E-408F-B353-99BAEB681403}] SEQPACKET 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{48705128-C97E-408F-B353-99BAEB681403}] DATAGRAM 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CB3C7EBC-10FF-4032-8D6E-2A24C646477B}] SEQPACKET 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CB3C7EBC-10FF-4032-8D6E-2A24C646477B}] DATAGRAM 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{678844D3-0E3D-468E-804B-F88B29400ABD}] SEQPACKET 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{678844D3-0E3D-468E-804B-F88B29400ABD}] DATAGRAM 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F255E76C-879A-4D16-8AE4-3B2D23BBD775}] SEQPACKET 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F255E76C-879A-4D16-8AE4-3B2D23BBD775}] DATAGRAM 4


**** Blocked Control Panel Items ****

BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No


**** Downloaded Program Files ****

{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} [http://go.microsoft.com/fwlink/?linkid=67633] C:\WINDOWS\system32\OGACheckControl.DLL
{166B1BCA-3F9C-11CF-8075-444553540000} [http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab]
{17492023-C23A-453E-A040-C7C580BBF700} [http://go.microsoft.com/fwlink/?linkid=39204]
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} [C:\Program Files\Yahoo!\Common\yinsthelper.dll]
{67DABFBF-D0AB-41FA-9C46-CC0F21721616} [http://go.divx.com/plugin/DivXBrowserPlugin.cab]
{8AD9C840-044E-11D1-B3E9-00805F499D93} [http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab]
{A4639D2F-774E-11D3-A490-00C04F6843FB} [http://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab]
{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} [http://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab]
{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} [http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab]
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab]
{D27CDB6E-AE6D-11CF-96B8-444553540000} [http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab]


**** Windows Services ****

[ACS] C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe
[Alerter] %SystemRoot%\System32\svchost.exe -k LocalService
[ALG] %SystemRoot%\System32\alg.exe
[Apple Mobile Device] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"
[AppMgmt] %SystemRoot%\system32\svchost.exe -k netsvcs
[aspnet_state] %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
[AudioSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[BITS] %SystemRoot%\System32\svchost.exe -k netsvcs
[Browser] %SystemRoot%\System32\svchost.exe -k netsvcs
[cisvc] C:\WINDOWS\System32\cisvc.exe
[ClipSrv] %SystemRoot%\system32\clipsrv.exe
[clr_optimization_v2.0.50727_32] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[COMSysApp] C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
[CryptSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[DcomLaunch] %SystemRoot%\system32\svchost -k DcomLaunch
[Dhcp] %SystemRoot%\System32\svchost.exe -k netsvcs
[dlbt_device] C:\WINDOWS\system32\dlbtcoms.exe -service
[dmadmin] %SystemRoot%\System32\dmadmin.exe /com
[dmserver] %SystemRoot%\System32\svchost.exe -k netsvcs
[Dnscache] %SystemRoot%\System32\svchost.exe -k NetworkService
[ERSvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[Eventlog] %SystemRoot%\system32\services.exe
[EventSystem] C:\WINDOWS\System32\svchost.exe -k netsvcs
[FastUserSwitchingCompatibility] %SystemRoot%\System32\svchost.exe -k netsvcs
[FontCache3.0.0.0] C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
[helpsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[HidServ] %SystemRoot%\System32\svchost.exe -k netsvcs
[HTTPFilter] %SystemRoot%\System32\svchost.exe -k HTTPFilter
[IDriverT] "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
[idsvc] "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
[ImapiService] C:\WINDOWS\System32\imapi.exe
[iPod Service] "C:\Program Files\iPod\bin\iPodService.exe"
[lanmanserver] %SystemRoot%\System32\svchost.exe -k netsvcs
[lanmanworkstation] %SystemRoot%\System32\svchost.exe -k netsvcs
[LmHosts] %SystemRoot%\System32\svchost.exe -k LocalService
[Messenger] %SystemRoot%\System32\svchost.exe -k netsvcs
[mnmsrvc] C:\WINDOWS\System32\mnmsrvc.exe
[MSDTC] C:\WINDOWS\System32\msdtc.exe
[MSIServer] C:\WINDOWS\system32\msiexec.exe /V
[NetDDE] %SystemRoot%\system32\netdde.exe
[NetDDEdsdm] %SystemRoot%\system32\netdde.exe
[Netlogon] %SystemRoot%\System32\lsass.exe
[Netman] %SystemRoot%\System32\svchost.exe -k netsvcs
[NetTcpPortSharing] "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
[Nla] %SystemRoot%\System32\svchost.exe -k netsvcs
[NtLmSsp] %SystemRoot%\System32\lsass.exe
[NtmsSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[NVSvc] %SystemRoot%\system32\nvsvc32.exe
[PlugPlay] %SystemRoot%\system32\services.exe
[PnkBstrA] C:\WINDOWS\system32\PnkBstrA.exe
[PolicyAgent] %SystemRoot%\System32\lsass.exe
[ProtectedStorage] %SystemRoot%\system32\lsass.exe
[RasAuto] %SystemRoot%\System32\svchost.exe -k netsvcs
[RasMan] %SystemRoot%\System32\svchost.exe -k netsvcs
[RDSessMgr] C:\WINDOWS\system32\sessmgr.exe
[RemoteAccess] %SystemRoot%\System32\svchost.exe -k netsvcs
[RemoteRegistry] %SystemRoot%\system32\svchost.exe -k LocalService
[RpcLocator] %SystemRoot%\System32\locator.exe
[RpcSs] %SystemRoot%\system32\svchost -k rpcss
[RSVP] %SystemRoot%\System32\rsvp.exe
[SamSs] %SystemRoot%\system32\lsass.exe
[SCardSvr] %SystemRoot%\System32\SCardSvr.exe
[Schedule] %SystemRoot%\System32\svchost.exe -k netsvcs
[seclogon] %SystemRoot%\System32\svchost.exe -k netsvcs
[SENS] %SystemRoot%\system32\svchost.exe -k netsvcs
[SharedAccess] %SystemRoot%\System32\svchost.exe -k netsvcs
[ShellHWDetection] %SystemRoot%\System32\svchost.exe -k netsvcs
[Spooler] %SystemRoot%\system32\spoolsv.exe
[srservice] %SystemRoot%\System32\svchost.exe -k netsvcs
[SSDPSRV] %SystemRoot%\System32\svchost.exe -k LocalService
[stisvc] %SystemRoot%\System32\svchost.exe -k imgsvc
[SwPrv] C:\WINDOWS\System32\dllhost.exe /Processid:{4E077276-404A-4FFD-893B-12574A08FB76}
[SysmonLog] %SystemRoot%\system32\smlogsvc.exe
[TapiSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[TermService] %SystemRoot%\System32\svchost -k DComLaunch
[Themes] %SystemRoot%\System32\svchost.exe -k netsvcs
[TlntSvr] C:\WINDOWS\System32\tlntsvr.exe
[trkWks] %SystemRoot%\system32\svchost.exe -k netsvcs
[TuneUp.Defrag] %SystemRoot%\System32\TuneUpDefragService.exe
[upnphost] %SystemRoot%\System32\svchost.exe -k LocalService
[UPS] %SystemRoot%\System32\ups.exe
[usprserv] %SystemRoot%\System32\svchost.exe -k netsvcs
[UxTuneUp] %SystemRoot%\System32\svchost.exe -k netsvcs
[VSS] %SystemRoot%\System32\vssvc.exe
[W32Time] %SystemRoot%\System32\svchost.exe -k netsvcs
[WebClient] %SystemRoot%\System32\svchost.exe -k LocalService
[WinDefend] "C:\Program Files\Windows Defender\MsMpEng.exe"
[winmgmt] %systemroot%\system32\svchost.exe -k netsvcs
[WmdmPmSN] %SystemRoot%\System32\svchost.exe -k netsvcs
[Wmi] %SystemRoot%\System32\svchost.exe -k netsvcs
[WmiApSrv] C:\WINDOWS\System32\wbem\wmiapsrv.exe
[WMPNetworkSvc] "C:\Program Files\Windows Media Player\WMPNetwk.exe"
[wscsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[wuauserv] %SystemRoot%\system32\svchost.exe -k netsvcs
[WudfSvc] %SystemRoot%\system32\svchost.exe -k WudfServiceGroup
[WZCSVC] %SystemRoot%\System32\svchost.exe -k netsvcs
[xmlprov] %SystemRoot%\System32\svchost.exe -k netsvcs


**** Custom IE Search Items ****

SEARCH: [SearchAssistant] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
SEARCH: [Default_Search_URL] http://www.google.com/ie
SEARCH: [CustomSearch] http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr8/*http://www.yahoo.com/ext/search/search.html


**** Complete IE Options ****

IEOPT: [NoUpdateCheck]
IEOPT: [NoJITSetup]
IEOPT: [Disable Script Debugger] yes
IEOPT: [Show_ChannelBand] No
IEOPT: [Anchor Underline] yes
IEOPT: [Cache_Update_Frequency] Once_Per_Session
IEOPT: [Display Inline Images] yes
IEOPT: [Do404Search]
IEOPT: [Local Page] C:\WINDOWS\system32\blank.htm
IEOPT: [Save_Session_History_On_Exit] no
IEOPT: [Show_FullURL] no
IEOPT: [Show_StatusBar] yes
IEOPT: [Show_ToolBar] yes
IEOPT: [Show_URLinStatusBar] yes
IEOPT: [Show_URLToolBar] yes
IEOPT: [Start Page] http://www.google.com/
IEOPT: [Use_DlgBox_Colors] yes
IEOPT: [Search Page] http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IEOPT: [Check_Associations] No
IEOPT: [FullScreen] no
IEOPT: [NotifyDownloadComplete] no
IEOPT: [Window_Placement] ,
IEOPT: [Error Dlg Displayed On Every Error] no
IEOPT: [Use FormSuggest] no
IEOPT: [AddToFavoritesExpanded]
IEOPT: [FormSuggest PW Ask] no
IEOPT: [Use Search Asst] no
IEOPT: [Enable Browser Extensions] yes
IEOPT: [FormSuggest Passwords] yes
IEOPT: [Use Custom Search URL]
IEOPT: [AutoSearch]
IEOPT: [ShowedCheckBrowser] Yes
IEOPT: [Default_Page_URL] http://go.microsoft.com/fwlink/?LinkId=69157
IEOPT: [Default_Search_URL] http://go.microsoft.com/fwlink/?LinkId=54896
IEOPT: [Search Page] http://go.microsoft.com/fwlink/?LinkId=54896
IEOPT: [Enable_Disk_Cache] yes
IEOPT: [Cache_Percent_of_Disk]
IEOPT: [Delete_Temp_Files_On_Exit] yes
IEOPT: [Local Page] %SystemRoot%\system32\blank.htm
IEOPT: [Anchor_Visitation_Horizon]
IEOPT: [Use_Async_DNS] yes
IEOPT: [Placeholder_Width]
IEOPT: [Placeholder_Height]
IEOPT: [Start Page] http://www.yahoo.com/
IEOPT: [CompanyName] Microsoft Corporation
IEOPT: [Custom_Key] MICROSO
IEOPT: [Wizard_Version] 6.0.2600.0000
IEOPT: [FullScreen] no
IEOPT: [Search Bar] http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
Quote from: sjn2009 on August 11, 2008, 11:29:07 AM
The CWShredder link doesn't seem to be working. But I got it off http://www.intermute.com/products/cwshredder.html
Sorry, I haven't had to use that program in quite awhile. Looks like I'll have to update my link!

Quote
But the AVG issue solved when I restarted my computer. I think it might have been due to the fact that the clock was an hour behind in the year 2088.
Ah, yes, ALTHOUGH incorrect dates are easy to spot, incorrect times can slip by because I'm not viewing the logs live, so I really don't know if the times are right or not. In any case, you are right about that being the problem; AVG is very PICKY about your clock having the correct settings. If it's off by a certain amount, AVG is unable to update like it should.




As for the log...everything seems fairly normal. I'm just concerned because of this line of your HJT log: MSIE: Unable to get Internet Explorer version! In every case I have seen this, it has been related to CoolWebSearch. You don't show any other symptoms, however, and your log is clean. So, I have to admit that I'm not quite sure what could be causing this to happen.

I have heard that it can sometimes be related to Messenger Plus. You have MSN Messenger, but I don't see Messenger Plus anywhere on your computer. You can check your Add/Remove Programs, though, and if it's there, try uninstalling it and posting a new HJT log. If it's not there, then simply skip this.

It's also possible that your IE has managed to become corrupted and needs to be repaired...
http://support.microsoft.com/kb/318378



I would try performing a repair install and then posting a new HJT log to see if that issue has been fixed. But as far as actual infections, your computer looks clean. However, you're vulnerable without a decent firewall, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo. They're all good free firewalls. Just be sure you only have one installed at a time! Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.
3020.

Solve : Screwed up computer?

Answer»

This computer got a virus or something and is all outa whack. I've tried running drweb's cureit, windows live one care, and spybot but it's still whacked. Could someone help me out and tell me what's goin on here? Thanks a million.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:11:10 PM, on 8/11/2008
Platform: Windows XP SP3, v.3311 (WinNT 5.01.2600)
MSIE: Internet EXPLORER v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\Program Files\Common Files\AOL\1205879913\ee\AOLSoftware.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Common Files\Winferno\WSS\WSS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Common Files\AOL\1205879913\EE\AOLDesktop.exe
c:\program files\common files\aol\1205879913\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1205879913\EE\aolsoftware.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Adobe PDF READER Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no FILE)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1205879913\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [SMrhc3v4j0e9bn] C:\Program Files\rhc3v4j0e9bn\rhc3v4j0e9bn.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: AOL Desktop.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Search - ?p=ZUxdm486YYUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1206127276182
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Winferno Subscription Service - Capital Intellect Inc - C:\Program Files\Common Files\Winferno\WSS\WSS.exe

--
End of file - 6698 bytes




Aren't you a member at Computer Juice?

Download Malwarebytes' Anti-Malware (MBAM)

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by CLICKING the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

    ----------

    Now run a new HijackThis scan and post that log also.
    3021.

    Solve : Desktop Hijacked.?

    Answer»

    Hi.
    I've been asked to look at my brother in laws PC, as I normally fix these, however this ones BEYOND me. Here's the story.

    When you turn his PC on, you can't access DOS, safe mode, anything, the screen is just black until it comes to Windows is now loading up. He's the only user on the PC so it goes straight into windows...
    As soon as this loads up a blue screen comes up with:
    "Warning, Spyware DETECTED on your computer" in a yellow box. then:
    "INSTALL an antivirus or spyware remover to clean your computer."
    Written underneath.

    He's running windows XP on quite an old system, and thinks he got htis from MSN

    I can't access window's, so can't do any virus or spyware sweeps, a hijack this LOG or anything. Can't access DOS to go through this way.

    I'm hoping there's another way other then a complete format, but can't see one.

    Anyone have any ideas?You can try to connect it as a slave DRIVE on another machine and try to clean it with antivius software

    SOUNDS LIKE YOURE GOING TO HAVE TO PURCHASE A DISK VERSION OF A SPYWARE/VIRUS CLEANING PROGRAM AND CLEAN IT THAT WAY. IT SOUNDS LIKE A VIRUS AND REFORMATTING IS A SAFER WAY TO ENSURE IT IS GONE FOREVER GOOD LUCKPlease turn your Caps Lock key off...Sounds like "Antivirus 2008" this is a virus we have seen many times where I work. If you can get a copy of Super Anti-Spyware this works well to get rid of it. It's a free scanner, but we usually keep it on a external drive. Following up on Spoiler's suggestion, do you have another computer available?

    3022.

    Solve : Imbedded virus problems?

    Answer»

    Here is the log for Eset.

    [recovering disk space -- attachment deleted by admin]
    Set a New Restore Point to prevent possible reinfection from an old one
    Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.

    • Go to START > Programs > ACCESSORIES > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More Options Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    You can find instructions on how to enable and re-enable system restore here:

    Windows XP System Restore Guide or Windows Vista System Restore Guide
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the MALWARE and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

    If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

    ----------

    Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

    Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

    Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

    To prevent unknown applications from being installed on your computer install WinPatrol 2008
    * Using Winpatrol to protect your computer from malicious software

    I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

    How is everything now?I created a new restore point and cleaned out the old ones. I attempted to use Secunia and got this error message:

    CiceroUIWndFrame: iexplore.exe - Application Error

    The instruction at "0x0303418e" referneced memory at "0x0332ec30". The memory could not be "read".

    Click on OK to terminate.

    When I clicked on OK another error message came up with new numbers. If I clicked on OK again it went back to the original message and they just keep repeating themselves. I have to logout to get rid of them.

    I probably will not use IE much anymore as a browser. I am using Flock, which is a newer version of Firefox. Will the programs you suggested to use with Firefox work with Flock?

    One more question: Is the Microsoft Security program strong enough to use, if updated regularly, or is it better to disable that and use other security programs such as you suggested and/or the ones I already use. I currently have Security Shield 2008, Superantispyware, will reload Spybot and I also have PC Registry Cleaner. I understand to use only one primary of each at a time.

    I will also LOOK at the programs you suggested and download them. I really want to thank you for your time, help and suggestions. I know it must be a job to sit there and analyze and suggest remedies for all the people who are using this forum. Kudos to you. Quote
    Will the programs you suggested to use with Firefox work with Flock?

    No. Most programs will work only with IE and FF.

    Quote
    Is the Microsoft Security program strong enough to use

    What program?

    Quote
    I also have PC Registry Cleaner.

    Where did you download this from?

    Quote
    I understand to use only one primary of each at a time.

    One firewall, one antivirus and one real time antispyware. Spyware Blaster will work with all of them as it doesn't run in real time.


    The Microsoft Security program I was referring to is Windows Security center found when you use Control Panel.

    My registry cleaner is PC Tools Registry Mechanic.

    Sorry for not being more precise.Leave the Windows Security center as it is.

    PC Tools Registry Mechanic is fine to keep although the functions in CCleaner are much safer in my opinion. It's your choice.Right now I have the Windows Security Center firewall off since I have Security Shield on. Same with the antivirus.

    I will use CCleaner since I have it downloaded. I'll look at the other programs you suggested also.

    Thanks again for all the help.Just tried to get into my EMAILS. G mail will not load at all and Yahoo mails are all blank.Run the F-Secure Online Scanner for Viruses, Spyware and RootKits.

    Note: This Scanner is for Internet Explorer Only!
    • Click on Online Services and then Online Scanner
    • Accept the License Agreement.
    • Once the ActiveX installs,Click Full System Scan
    • Once the download completes,the scan will begin automatically.
    • The scan will take some time to finish,so please be patient.
    • When the scan completes, click the Automatic cleaning (recommended) button.
    • Click the Show Report button and Copy&Paste the entire report in your next reply.
    3023.

    Solve : Re: unidentified malware still running?

    Answer»

    Hi,

    Sorry to high jack topic. I recently got this page keeps popping out. http://www.sedoparking.com
    I used adware, malware to delete but it keeps coming back.
    Please HELP. Thanks alot.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:06:51 PM, on 8/11/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Winamp\winampa.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\IC\Card Reader DRIVER v1.9e2\Disk_Monitor.exe
    C:\WINDOWS\system32\pctspk.exe
    C:\WINDOWS\system32\PV92Tray.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\Sniper.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

    http://www.defaulthomepage.info
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

    Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

    Files\Java\jre1.6.0_07\bin\ssv.dll
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Disk Monitor] C:\Program Files\IC\Card Reader Driver v1.9e2

    \Disk_Monitor.exe
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"

    -osboot
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common

    Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy

    Package\dapcleanerie.htm
    O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
    O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2

    \OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

    Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

    C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2

    \OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

    Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

    C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

    Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

    C:\Program Files\Messenger\msmsgs.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{12D9302D-AA03-4949-8045-44470AD7F841}: NameServer =

    202.134.0.155,202.134.2.5
    O17 - HKLM\System\CS1\Services\Tcpip\..\{12D9302D-AA03-4949-8045-44470AD7F841}: NameServer =

    202.134.0.155,202.134.2.5
    O17 - HKLM\System\CS2\Services\Tcpip\..\{12D9302D-AA03-4949-8045-44470AD7F841}: NameServer =

    202.134.0.155,202.134.2.5
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program

    Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common

    Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program

    Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4

    \ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil

    Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4

    \ashWebSv.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32

    \ZoneLabs\vsmon.exe

    --
    End of file - 5394 bytes
    Download Malwarebytes' Anti-Malware (MBAM)

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
      • Then click Finish.
      • If an update is found, it will download and install the latest version.
      • Once the program has loaded, select Perform quick scan, then click Scan.
      • When the scan is complete, click OK, then Show Results to view the results.
      • Be sure that everything is checked, and click Remove Selected.
      • When disinfection is COMPLETED, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
      • Copy and Paste the entire report in your next reply.
      Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

      ----------

      Now run a new HijackThis scan and post the log along with the MBAM log.

      This time before copying the HijackThis log, in Notepad select Edit &GT; and click Word Wrap. Anti malware indicate all ok. but sedoparking still show up sometimes.

      inside cookies got these files name ad.yieldmanager, adrevolver. i suspect these caused the problem.

      thanks


      log
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 5:03:04 PM, on 8/13/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Winamp\winampa.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\IC\Card Reader Driver v1.9e2\Disk_Monitor.exe
      C:\WINDOWS\system32\pctspk.exe
      C:\WINDOWS\system32\PV92Tray.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\WgaTray.exe
      D:\David\Software\Torrent\utorrent.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Trend Micro\HijackThis\Sniper.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.defaulthomepage.info
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [Disk Monitor] C:\Program Files\IC\Card Reader Driver v1.9e2\Disk_Monitor.exe
      O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
      O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
      O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
      O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O17 - HKLM\System\CCS\Services\Tcpip\..\{12D9302D-AA03-4949-8045-44470AD7F841}: NameServer = 202.134.0.155,202.134.2.5
      O17 - HKLM\System\CS1\Services\Tcpip\..\{12D9302D-AA03-4949-8045-44470AD7F841}: NameServer = 202.134.0.155,202.134.2.5
      O17 - HKLM\System\CS2\Services\Tcpip\..\{12D9302D-AA03-4949-8045-44470AD7F841}: NameServer = 202.134.0.155,202.134.2.5
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

      --
      End of file - 5380 bytes



      Can you post the MBAM log. Open MBAM then select the Logs tab and it can be found there.

      Also how is the computer now?Malwarebytes' Anti-Malware 1.24
      Database version: 1045
      Windows 5.1.2600 Service Pack 2

      5:01:15 PM 8/13/2008
      mbam-log-8-13-2008 (17-01-15).txt

      Scan type: Full Scan (C:\|D:\|I:\|)
      Objects scanned: 107229
      Time elapsed: 30 minute(s), 59 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Computer is ok but connection is slow. need to restart computer and modem once awhile.

      Thanks.



      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)
      I don't THINK it is malware.

      Try posting in the Windows forum for some advice from people in there.
      3024.

      Solve : Very bad virus: computer completely frozen!?

      Answer»

      Hi,

      I got infected with a very bad virus. HOT SEX, Error CLEANER, Privacy Protector, Spyware&Malware Protection icons appeared on my desktop while some windows were opening/closing from nowhere. I panicked and pushed the Restart button, and from now on, 10 seconds after the computer's startup, it freezes completely; I even HEAR the fan/HDD inside the computer case slow down. The mouse still works, but that's all.

      Even if I try to boot in safe mode, when it comes the time to choose the safe mode, the KEYBOARD no longer responds; enter, arrows, I cannot choose the mode.

      Now, I'm on my Mac (thank god Macs exists) and still SEARCHING how to get rid of this ****.

      I can't even run HijackThis! : (

      I have Windows XP Home, Core2Duo, 1024 RAM.



      Thank you for your answersCan you get online with it?Hmm no, it freezes before I can go online. Any ideas about how I could bypass this freeze?

      ThanksYou mentioned the keyboard doesn't work to choose the Boot Mode.
      Do you have a PS/2 keyboard anywhere? (with the round plug)

      3025.

      Solve : Antivirus XP 2008 virus?

      Answer»

      Hello again,

      I have been infected with this ANTIVIRUS XP 2008 nonsense. It appears as a program in my add/REMOVE control panel, but I cannot uninstall it. I attempted to remove it using your guide but encountered the following problem:

      When I run SUPERAntiSpyware, it finds around 10 infected files, but then crashes during the scan and I get a blue screen of death (BOOT_STRAP error I think).

      I have run CCleaner and MBAM (log below) but to no avail.

      Please help!!

      Iain

      PS. I have backed up some files from my infected computer onto my pen drive. Can I now safely transport them on to my clean computer or could they infect it? (they are just word documents).Malwarebytes' Anti-Malware 1.14
      Database version: 800

      16:47:09 15/08/2008
      mbam-log-8-15-2008 (16-47-09).txt

      Scan type: Quick Scan
      Objects scanned: 61291
      Time elapsed: 14 minute(s), 47 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 1
      Registry Values Infected: 1
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 1

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      C:\WINDOWS\system32\drivers\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      I need the HijackThis log. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 18:45:08, on 15/08/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\McAfee.com\Agent\mcagent.exe
      C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
      C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\WINDOWS\system32\lphce9fj0e19v.exe
      C:\Program Files\rhca9fj0e19v\rhca9fj0e19v.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
      C:\WINDOWS\System32\WScript.exe
      C:\WINDOWS\system32\pphce9fj0e19v.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe
      C:\WINDOWS\system32\lxdicoms.exe
      C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      c:\program files\common files\mcafee\mna\mcnasvc.exe
      c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      C:\Program Files\McAfee\MPF\MPFSrv.exe
      C:\Program Files\McAfee\MSK\MskSrver.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\svchost.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: McAfee Phishing Filter - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
      O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
      O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
      O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [RRT-Auto] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 1 for RRT.zip\RRT.exe auto
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [lphce9fj0e19v] C:\WINDOWS\system32\lphce9fj0e19v.exe
      O4 - HKLM\..\Run: [SMrhca9fj0e19v] C:\Program Files\rhca9fj0e19v\rhca9fj0e19v.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-21-1935655697-1682526488-839522115-1007\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'postgres')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra BUTTON: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet1\UltimateBet.exe
      O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet1\UltimateBet.exe
      O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Iain\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
      O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Iain\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
      O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1205523236343
      O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O21 - SSODL: KernelCD - {ed9f547e-7725-46f4-a938-95c4abb21edf} - C:\WINDOWS\Resources\KernelCD.dll (file missing)
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
      O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe
      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
      O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
      O23 - Service: PostgreSQL Database Server 8.2 (pgsql-8.2) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.2\bin\pg_ctl.exe
      O23 - Service: ThreatFire - Unknown owner - C:\Program Files\ThreatFire\TFService.exe (file missing)

      --
      End of file - 9772 bytes
      Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

      Link #1
      Link #2

      **Note: It is important that it is saved directly to your Desktop

      Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

      Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

      Double click combofix.exe & follow the prompts.
      When finished ComboFix will produce a log for you.
      Post the ComboFix log and a new HijackThis log in your next reply.

      Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

      Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

      If you have problems with ComboFix usage, see How to use ComboFix

      ----------

      Next post add
      ComboFix log
      New HijackThis log
      Done that. It has removed the Antivirus XP 2008 program. Here are the logs:


      ComboFix 08-08-14.05 - Iain 2008-08-15 19:15:56.1 - NTFSx86
      Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1547 [GMT 1:00]
      Running from: C:\Documents and Settings\Iain\Desktop\ComboFix.exe
      * Created a new restore point

      WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
      C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
      C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
      C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
      C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
      C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
      C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
      C:\Documents and Settings\Iain\Application Data\rhca9fj0e19v
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Kirsty\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\#SharedObjects\XMT9YWLM\interclick.com
      C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\#SharedObjects\XMT9YWLM\interclick.com\ud.sol
      C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
      C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Susanne\Cookies\[emailprotected][1].txt
      C:\Program Files\rhca9fj0e19v
      C:\WINDOWS\system32\blphce9fj0e19v.scr
      C:\WINDOWS\system32\ffsfmpnc.ini
      C:\WINDOWS\system32\lphce9fj0e19v.exe
      C:\WINDOWS\system32\mcrh.tmp
      C:\WINDOWS\system32\phce9fj0e19v.bmp
      C:\WINDOWS\system32\pphce9fj0e19v.exe
      C:\WINDOWS\system32\PYIllUvw.ini
      C:\WINDOWS\system32\PYIllUvw.ini2
      C:\WINDOWS\system32\wimllcoh.ini

      .
      ((((((((((((((((((((((((( Files Created from 2008-07-15 to 2008-08-15 )))))))))))))))))))))))))))))))
      .

      2008-07-21 01:29 . 2008-07-22 01:05d--------C:\Program Files\PokerTracker 3
      2008-07-18 15:15 . 2008-07-18 15:16d--------C:\nav_update
      2008-07-18 15:01 . 2008-07-18 15:01d--------C:\Program Files\AvantGo Connect
      2008-07-18 15:01 . 2008-07-18 15:012,464--a------C:\WINDOWS\$_hpcst$.hpc
      2008-07-18 14:59 . 2008-07-18 14:59d--hs----C:\WINDOWS\ftpcache
      2008-07-18 13:02 . 2004-12-06 14:07104,064--a------C:\WINDOWS\system32\drivers\wceusbsh.sys
      2008-07-18 13:02 . 2004-12-06 14:07104,064--a--c---C:\WINDOWS\system32\dllcache\wceusbsh.sys
      2008-07-18 12:21 . 2004-08-03 22:5814,848--a------C:\WINDOWS\system32\drivers\kbdhid.sys
      2008-07-18 12:21 . 2004-08-03 22:5814,848--a--c---C:\WINDOWS\system32\dllcache\kbdhid.sys

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-08-15 01:03---------d-----wC:\Program Files\McAfee
      2008-08-10 21:40---------d---a-wC:\Documents and Settings\All Users\Application Data\TEMP
      2008-08-10 21:39---------d-----wC:\Program Files\Full Tilt Poker
      2008-08-10 21:30---------d-----wC:\Program Files\PokerStars
      2008-08-07 18:57---------d-----wC:\Program Files\UltimateBet1
      2008-08-05 23:17---------d-----wC:\Documents and Settings\Iain\Application Data\LimeWire
      2008-07-19 17:31---------d-----wC:\Program Files\Java
      2008-07-18 16:44---------d-----wC:\Program Files\Poker Tracker V2
      2008-07-18 14:01---------d-----wC:\Program Files\Microsoft ActiveSync
      2008-07-14 03:31---------d-----wC:\Documents and Settings\Iain\Application Data\Microgaming
      2008-07-09 21:11---------d-----wC:\Program Files\Absolute Poker
      2008-07-07 20:32253,952----a-wC:\WINDOWS\system32\es.dll
      2008-07-05 18:58---------d-----wC:\Program Files\TryMedia
      2008-07-05 15:51---------d-----wC:\Documents and Settings\Iain\Application Data\SpinTop
      2008-07-03 18:26---------d-----wC:\Program Files\_uninstallation_info
      2008-07-03 18:10---------d-----wC:\Program Files\Bodog Poker
      2008-07-03 18:04---------d-----wC:\Program Files\MGS FF Helper
      2008-06-24 16:2374,240----a-wC:\WINDOWS\system32\mscms.dll
      2008-06-23 16:57826,368----a-wC:\WINDOWS\system32\wininet.dll
      2008-06-22 19:06---------d-----wC:\Program Files\MSN Messenger
      2008-06-20 17:41245,248----a-wC:\WINDOWS\system32\mswsock.dll
      2008-06-20 10:45360,320----a-wC:\WINDOWS\system32\drivers\tcpip.sys
      2008-06-20 10:44138,368----a-wC:\WINDOWS\system32\drivers\afd.sys
      2008-06-20 09:52225,920----a-wC:\WINDOWS\system32\drivers\tcpip6.sys
      .

      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 14:56 15360]
      "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-04 11:50 405583]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-11-30 05:42 1164576]
      "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
      "lxdimon.exe"="C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 17:54 434864]
      "lxdiamon"="C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 17:54 25264]
      "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 15:42 1404928]
      "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-09 22:05 344064]
      "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
      "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
      "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-07 19:37 185632]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-12 14:56 15360]

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
      2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "MSACM.CEGSM"= mobilev.acm

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusDisableNotify"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
      "C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
      "C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
      "C:\\WINDOWS\\system32\\lxdicfg.exe"=
      "C:\\WINDOWS\\system32\\lxdicoms.exe"=
      "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
      "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
      "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "C:\\Program Files\\Messenger\\msmsgs.exe"=
      "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
      "C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
      "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdiwbgw.exe"=
      "C:\\Program Files\\iTunes\\iTunes.exe"=
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
      "C:\\Program Files\\MSN Messenger\\livecall.exe"=

      R2 lxdi_device;lxdi_device;C:\WINDOWS\system32\lxdicoms.exe [2007-06-11 15:14]
      R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe [2007-06-11 15:14]
      R2 pgsql-8.2;PostgreSQL Database Server 8.2;C:\Program Files\PostgreSQL\8.2\bin\pg_ctl.exe runservice -w -N pgsql-8.2 -D C:\Program Files\PostgreSQL\8.2\data\ []
      S0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys []
      S0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys []
      S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
      S3 MBAMCatchMe;MBAMCatchMe;C:\WINDOWS\system32\drivers\mbamcatchme.sys [2008-05-30 01:06]
      S3 TfNetMon;TfNetMon;C:\WINDOWS\system32\drivers\TfNetMon.sys []
      .
      Contents of the 'Scheduled Tasks' folder

      2008-06-15 C:\WINDOWS\Tasks\McDefragTask.job
      - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

      2008-08-01 C:\WINDOWS\Tasks\McQcTask.job
      - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
      .
      - - - - ORPHANS REMOVED - - - -

      HKLM-Run-RRT-Auto - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 1 for RRT.zip\RRT.exe
      HKLM-Run-lphce9fj0e19v - C:\WINDOWS\system32\lphce9fj0e19v.exe
      HKLM-Run-SMrhca9fj0e19v - C:\Program Files\rhca9fj0e19v\rhca9fj0e19v.exe
      SSODL-KernelCD-{ed9f547e-7725-46f4-a938-95c4abb21edf} - C:\WINDOWS\Resources\KernelCD.dll


      .
      ------- Supplementary Scan -------
      .
      FireFox -: Profile - C:\Documents and Settings\Iain\Application Data\Mozilla\Firefox\Profiles\s6en2zv2.default\
      FireFox -: prefs.js - STARTUP.HOMEPAGE - www.yahoo.co.uk


      **************************************************************************

      catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-08-15 19:19:49
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      ------------------------ Other Running Processes ------------------------
      .
      C:\WINDOWS\system32\ati2evxx.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdiserv.exe
      C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
      C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
      C:\Program Files\McAfee\MPF\MpfSrv.exe
      C:\Program Files\McAfee\MSK\msksrver.exe
      C:\Program Files\PostgreSQL\8.2\bin\pg_ctl.exe
      C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
      C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
      C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
      C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
      C:\Program Files\iPod\bin\iPodService.exe
      .
      **************************************************************************
      .
      Completion time: 2008-08-15 19:21:38 - machine was rebooted
      ComboFix-quarantined-files.txt 2008-08-15 18:21:31

      Pre-Run: 225,899,708,416 bytes free
      Post-Run: 226,272,829,440 bytes free

      213--- E O F ---2008-08-13 17:11:02
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:23:10, on 15/08/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe
      C:\WINDOWS\system32\lxdicoms.exe
      C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      c:\program files\common files\mcafee\mna\mcnasvc.exe
      c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      C:\Program Files\McAfee\MPF\MPFSrv.exe
      C:\Program Files\McAfee\MSK\MskSrver.exe
      C:\Program Files\McAfee.com\Agent\mcagent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
      C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\system32\notepad.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: McAfee Phishing Filter - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
      O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
      O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
      O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-21-1935655697-1682526488-839522115-1007\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'postgres')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet1\UltimateBet.exe
      O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet1\UltimateBet.exe
      O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Iain\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
      O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Iain\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
      O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1205523236343
      O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
      O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe
      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
      O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
      O23 - Service: PostgreSQL Database Server 8.2 (pgsql-8.2) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.2\bin\pg_ctl.exe
      O23 - Service: ThreatFire - Unknown owner - C:\Program Files\ThreatFire\TFService.exe (file missing)

      --
      End of file - 9351 bytes
      Download OTMoveIt2 by OldTimer

      • Save it to your desktop.
      Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

      • Double-click OTMoveIt2.exe to run it.
      • Copy the lines in the codebox below.
      Code: [Select][kill explorer]
      C:\nav_update
      EmptyTemp
      [start explorer]
      • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
      • Click the red Moveit! button.
      • Copy everything in the Results window (under the GREEN bar) and paste it in your next reply.
      • Close OTMoveIt2
      .
      ----------

      Open HijackThis and select Do a system scan only.

      Place a check mark next to the following entries: (if there)

      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

      Important: Close all windows except for HijackThis and then click Fix checked.

      Exit HijackThis.

      ----------

      How is everything now?I couldn't post what was in the results window because it prompted me to restart my machine when it was finished.

      Here is the log instead, hope it is just as useful.



      Explorer killed successfully
      C:\nav_update moved successfully.
      < EmptyTemp >
      File delete failed. C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001 scheduled to be deleted on reboot.
      File delete failed. C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001.dir.0000\~df394b.tmp scheduled to be deleted on reboot.
      File delete failed. C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001.dir.0000\~efe2.tmp scheduled to be deleted on reboot.
      File delete failed. C:\WINDOWS\temp\mcmsc_bPa1pLJOTHzUaHL scheduled to be deleted on reboot.
      File delete failed. C:\WINDOWS\temp\sqlite_bxIthif21ZvxxEe scheduled to be deleted on reboot.
      File delete failed. C:\WINDOWS\temp\sqlite_ye11UkYmj0yULdM scheduled to be deleted on reboot.
      Temp folders emptied.
      IE temp folders emptied.
      Explorer started successfully

      OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08152008_195429

      Files moved on Reboot...
      C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001 moved successfully.
      C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001.dir.0000\~df394b.tmp moved successfully.
      C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001.dir.0000\~efe2.tmp moved successfully.
      File C:\WINDOWS\temp\mcmsc_bPa1pLJOTHzUaHL not found!
      C:\WINDOWS\temp\sqlite_bxIthif21ZvxxEe moved successfully.
      C:\WINDOWS\temp\sqlite_ye11UkYmj0yULdM moved successfully.

      My computer seems to be back to normal again.

      Thanks for all your help,

      IainLet's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
      .
      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      .
      The above procedure will:
      • Delete:
        • ComboFix and its associated files and folders.
        • VundoFix backups, if present
        • The C:\Deckard folder, if present
        • The C:_OtMoveIt folder, if present
        • Reset the clock settings.
        • Hide file extensions, if required.
        • Hide System/Hidden files, if required.
        • Set a new, clean Restore Point.
        .
        ----------

        1. Double click OTMoveIt2.exe to launch it.
        Vista users right click and choose Run As Administrator
        2. Click on the CleanUp! button.
        3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
        4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
        5. Once complete exit out of OTMoveIt2

        ----------

        Set a New Restore Point to prevent possible reinfection from an old one
        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
        • Go to Start > Programs > Accessories > System Tools and click System Restore
        • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
        • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
        • Next go to Start > Run and type Cleanmgr
        • Click OK
        • Click the More Options Tab.
        • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
        You can find instructions on how to enable and re-enable system restore here:

        Windows XP System Restore Guide or Windows Vista System Restore Guide
        .
        ----------

        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

        If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

        ----------

        Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

        Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

        Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

        To prevent unknown applications from being installed on your computer install WinPatrol 2008
        * Using Winpatrol to protect your computer from malicious software

        I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
        3026.

        Solve : Newbie here with trojans/malware/rogues, Oh my!?

        Answer»

        Hi all. I am glad to be here. As the subject reads, I acquired all of these things on my HP pavilion laptop while surfing the net. I am running XP SP2. I have read the sticky and performed the initial steps outlined there and have created the appropriate logs. My question is: What do I do from here? I appreciate any help/advice offered.


        [recovering disk space -- attachment deleted by admin]Welcome to CH.

        Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

        Link #1
        Link #2

        **Note: It is important that it is saved directly to your Desktop

        Close any open Web BROWSERS. (Firefox, Internet Explorer, etc) before starting Combofix.

        Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

        Double click combofix.exe & follow the prompts.
        When finished ComboFix will produce a log for you.
        Post the ComboFix log and a new HijackThis log in your next reply.

        Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

        Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

        If you have problems with Combofix usage, see hereFirst of all, thank you for your timely response to my problem and help. I have done what you recommended and here are my results.

        [recovering disk space -- attachment deleted by admin]

          Open HijackThis and select
        Do a system scan only.

        Place a check mark next to the following entries: (if there)

        O24 - Desktop Component 0: Privacy Protection - (no file)

        Important: Close all windows except for HijackThis and then click Fix checked.

        Exit HijackThis and restart the computer to register the changes made by HijackThis.

        ----------

        • Click START then RUN
        • Now type Combofix /u in the runbox
        • Make sure there's a space between Combofix and /u
        • Then hit Enter.
        • The above procedure will:
        • Delete the following:
        • ComboFix and its associated files and folders.
        • Reset the clock settings.
        • Hide file extensions, if required.
        • Hide System/Hidden files, if required.
        • Set a new, clean Restore Point.
        .

        ----------

        Use the Kaspersky Online Scanner

        In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon and choose Run as Administrator.

        Click on SCAN NOW
        Click on the Accept button and install any components it needs.
        • The program will install and then begin downloading the latest definition files.
        • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
        • This will start the program and scan your system.
        • The scan will take a while, so be patient and let it run.
        • Once the scan is complete, click on View scan report
        • Now, click on the Save Report as button.
        • In Save as type: click the drop arrow and select: Text file [*.txt]
        • Then, click: Save
        • Save the file to your desktop.
        Post the Kaspersky log in your next reply.

        Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.Alright, moving right along. Here it is:

        [recovering disk space -- attachment deleted by admin]
          Download
        OTMoveIt2 by OldTimer
        • Save it to your desktop.
        Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

        • Double-click OTMoveIt2.exe to run it.
        • Copy the lines in the codebox below.
        Code: [Select][kill explorer]
        C:\Documents and Settings\andy\Incomplete\CORRUPT-0-Linkin Park - Given up.mp3
        EmptyTemp
        [start explorer]
        • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
        • Click the red Moveit! button.
        • Copy everything in the Results window (under the green bar) and paste it in your next reply.
        • Close OTMoveIt2
        Explorer killed successfully
        C:\Documents and Settings\andy\Incomplete\CORRUPT-0-Linkin Park - Given up.mp3 moved successfully.
        < EmptyTemp >
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\synchronize.log scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\hsperfdata_andy\2664 scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\Arj.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\avlib.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\Avp1.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\AvpMgr.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\btimages.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\CAB.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\dmap.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\dtreg.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\FsDrvPlg.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\FSSync.dll scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\HashCont.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\HashMD5.PPL scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\HCCMP.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\ichk2.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\iChkSA.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\Inflate.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\IWGen.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\kave.dll scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\kosglue-7.0.25.0.dll scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\lha.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\L_llio.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\mdb.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\MDMAP.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\MemModSc.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\MemScan.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\minizip.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\MKavIO.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\msoe.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\nfio.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\NTFSstrm.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\prKernel.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\prLoader.dll scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\prseqio.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\PrUtil.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\Quantum.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\rar.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\ScanningProcess.exe scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\sfdb.PPL scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\TempFile.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\thpimpl.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\UniArc.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\UnLZX.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\UnStored.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\andy\LOCALS~1\Temp\jkos-andy\binaries\WDiskIO.ppl scheduled to be deleted on reboot.
        File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_58c.dat scheduled to be deleted on reboot.
        Temp folders emptied.
        IE temp folders emptied.
        Explorer started successfully1. Double click OTMoveIt2.exe to launch it.
        Vista users right click and choose Run As Administrator
        2. Click on the CleanUp! button.
        3. OTMoveIt2 will download a list from the Internet, if your FIREWALL or other defensive programs alerts you, allow it access.
        4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
        5. Once complete exit out of OTMoveIt2

        ----------

        Set a New Restore Point to prevent possible reinfection from an old one
        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
        • Go to Start > Programs > Accessories > System Tools and click System Restore
        • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
        • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
        • Next go to Start > Run and type Cleanmgr
        • Click OK
        • Click the More Options Tab.
        • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
        You can find instructions on how to enable and re-enable system restore here:

        Windows XP System Restore Guide or Windows Vista System Restore Guide
        .
        ----------

        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

        If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

        ----------

        Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

        Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

        Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

        To prevent unknown applications from being installed on your computer install WinPatrol 2008
        * Using Winpatrol to protect your computer from malicious software

        I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thanks for all the help, Kevin. That was quite a process but i think everything is running okay.

        I do continue to have a solid white background on my desktop despite changing the picture via control panel> display> background tab. Don't know what that is all about.

        Try this.

        Fixing a Locked Desktop
        • Right click on your Desktop and select Properties
        • Then click the Desktop tab.
        • Next click the Customize Desktop button.
        • Now in the next window that comes up click the Web tab.
          • Make sure at the bottom that Lock desktop items is unchecked.
          • Then in the Web pages box delete all items but My Current Home Page and make sure it is unchecked too.
          • Then click OK.
          • Click Apply. And click OK.
          .


          Run a new HijackThis scan and post the log if that doesn't work.Dang you're good! That FIXED it. I now have the background I have chosen.
          Thanks again.No problem. Glad it worked.I know this wasn't for me but have FOLLOWED the thread - am well impressed with the degree of help - quite awesome.

          Kudos to evil.
          3027.

          Solve : So it seems like my computer is running too muh....?

          Answer»

          So I have cleaned it out f any viruses/syware/malware, but I looked at performane in task manager, and this is what it says for physical memory:
          Total: 1917
          Cached: 1475
          Free: 19

          Is that good? It seems like i should have more free....Do you mean here?

          yes....Straight from the Microsoft WEBSITE:



          Quote from: iamtonsoffun247 on June 02, 2008, 07:12:40 AM

          Total: 1917
          Cached: 1475
          Free: 19

          Is that good? It seems like i should have more free....
          That seems very odd....
          How much RAM do you have?Ive got 2 GB of ramIt's perfectly normal.
          This is how MINE looks:

          Explanation: http://articles.techrepublic.com.com/5100-10878_11-6162525.html
          Quote
          Total entry shows the amount of RAM installed in the system.
          The Cached entry indicates the amount of physical memory used recently for system RESOURCES. This memory will REMAIN in the cache in case the system resources are needed again, but it's available should other operations need it.
          The Free entry indicates the amount of memory that is currently not being used or does not CONTAIN useful information.

          As you can see, adding up the numbers here isn't exactly a straightforward proposition. The system actually has 1 GB of RAM which comes out to 1024 MB and the onboard video has access to 128 MB of that memory, yet the Total entry indicates that 958 MB is available and the bar chart shows that 702 MB is being used.
          so then im fine? thank you broni! as usual lolYou're perfectly fine
          3028.

          Solve : Super Winspy?

          Answer»

          I'm a mother of five kids, including four boys. The OLDEST two are teenagers. I'd like to monitor their computer usage more closely. I've RUN across a program called Super Winspy that claims to allow me to CHECK everything they do on the computer. Is this a safe program to use?Never heard of it, freeware, less than 1MB. Not SURE if it's safe or not but I think you could give it a try.
          However, if your kids are very good with computers, it's possible they will FIND it.Name: Adware.Win32.Super Winspy

          Risklevel: High Risk

          Company: AceSoft

          http://www.emsisoft.com/en/malware/?Adware.Win32.Super+Winspy

          3029.

          Solve : system aministrator?(Need Help)?

          Answer»

          Ok I got a problem every time LIKE I want to go CHANGE like my PERSONAL setting s on my computer a little bar comes up on the left top corner it says restrictions and a big x and inside the box it say (This OPERATION has been cancelled due to restrictions in effect on this computer. Please contact you system administrator.) Can someone like tell what SHELL I do thanks.Click below...

          3030.

          Solve : backdoor.trojan?

          Answer»

          So I recently came under ATTACK from a backdoor.trojan, and had to pay the COMPANY that runs my antivirus program (Symantec) $100 to fix it. (Maybe to some this might not seem like much, but I'm still a student, without a job) I'm not really sure how I got it, but I have a strong suspicion it might be from downloading a video file, but I'm not sure. To tell the truth, I use bittorrent, and it's from this that I think I might have gotten it. But to be sure, is it actually possible to get this virus from downloading files? If not, then how exactly does it get onto a computer? Also, I read some articles about how it gives the attacker access to your computer, but what I want to know is how exactly does it work, is it only when your computer is on that the attacker is able to look through your private files, history, etc. or is it once you have the virus, does it make a copy of all the things on your computer for the attacker to look through? Lastly, was there some easier/cheaper way to take care of it? I was talking to a live assistant over at Symantec, and they just said the best option is to let them take care of it since they have to deal with the computer's registry keys or something, but that could've been just a ploy to make money. I'm really not computer-literate, if you haven't guess already, so your help would be appreciated, especially if it's not too cluttered with technical jargon. Quote

          is it actually possible to get this virus from downloading files?
          Yes. It's one of the most common ways of getting infected.
          Whenever you download any file of questionable source, it has to be scanned with your antivirus, before you do anything else with that file.
          More info: So how did I get infected in the first place?: http://www.castlecops.com/postlite7736-.html

          Quote
          Lastly, was there some easier/cheaper way to take care of it?
          Absolutely. If you came to our forum while infected, we'd fix your computer for free.

          Welcome aboard Torrents are the new Malware! I understand that money may be tight but downloading copywrite protected material is illegal. Free in many instances comes at a price. Many torrents will install malware designed to steal your banking and private information, software license keys (including Windows) and some just go for plain old PC destruction. I could go on, but I think you get the point.

          Symantec (or any live help) have to charge to keep the bottom line alive. There are many free replacements out there that actually do a superior job to the paid products. If you do get a virus/trojan then start HERE and we can help you get cleaned up.

          Check out these two articles. If you have any questions feel free to ask.

          So how did I get infected in the first place? by Tony Klien.

          How to prevent Malware by Miekiemoes.Quote
          Torrents are the new Malware! I understand that money may be tight but downloading copywrite protected material is illegal.
          I'll have to disagree.
          1. "Torrents are the new Malware" is a misleading statement, because torrent itself is a small harmless file, UNLESS it leads to a download, which contain malware. I've been using torrents for a long time, and never got infected.
          There are many aspects of using internet, which are dangerous, but if you play safe, you'll stay safe.
          A torrent, definitely cannot be defined as a malware. It would be the same to call an email a malware, because it happened to include infected attachment.
          2. Using torrents doesn't mean, someone is automatically breaking a law by downloading copyrighted material. Torrents can be used to download legal material as well. We're not gonna ban email, because some people are sending copyrighted, or terrorist materials through it.

          Nobody is guilty, until proven to be.
          Quote
          Nobody is guilty, until proven to be.

          Which is the reason so many people don't care what they download.

          Save the innocent speech for someone else. My response is justified.

          Quote
          I'm not really sure how I got it, but I have a strong suspicion it might be from downloading a video file, but I'm not sure. To tell the truth, I use bittorrent
          I'm sorry. Maybe it's late, but I'm not getting your point....OK, many torrents are malicious, just like many email attachments and codecs are malicious.

          Illegal is illegal if it is copywrited. Torrents are the new malware (Malicious Software) is something that I feel strongly about. They are used to distribute virus/trojans to the unsuspecting user. When someone says I think it was from a torrent then it most likely was.

          Even "safe" clients can be exploited.

          ADVISORY: Malicious torrent files can execute arbitrary CODE in Opera

          Stop Downloading Fakes and Junk From BitTorrent

          Dodgy torrent - beware
          3031.

          Solve : General Hijack/Malware/unknown problems?

          Answer» LET's START with #4. FIND it.
          3032.

          Solve : Korean Attack | Spy-/Ad-ware?

          Answer» WELL my other pc SOMETIMES get a grey BOX with chinese or japanise TEXT, Does anyone know what it is ?
          Click below...Quote
          chinese or japanise text
          Then what's with KOREAN?
          3033.

          Solve : Infection, desktop background unavailable?

          Answer»

          Hi,

          I have a Dell laptop with a virus infection. I have scanned it, and attached the logs. Since scanning and removing the infections that were found, it seems to be running a lot better.
          Before removing the infected FILES, the desktop was displaying 'Active Desktop Recovery' with VARIOUS options and a white background. I managed to get rid of the desktop recovery message by opening desktop properties > customize desktop > restore defaults.
          I still can't change the desktop background though. When I OPEN desktop properties, all the backgrounds are listed, but I can't select them.

          Any ideas?

          Thanks

          Nick

          [recovering space - attachment deleted by admin]HJT log is clean.

          1. Download, and install CCleaner: HTTP://www.ccleaner.com/download/builds. Get "Slim" version.
          Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
          Run CCleaner.

          2. Turn off System Restore:

          - Windows XP:
          1. Click Start.
          2. Right-click the My Computer icon, and then click Properties.
          3. Click the System Restore tab.
          4. Check "Turn off System Restore".
          5. Click Apply.
          6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
          7. Click OK.
          - Windows Vista:
          1. Click Start.
          2. Right-click the Computer icon, and then click Properties.
          3. Click on System Protection under the Tasks column on the left side
          4. Click on Continue on the "User Account Control" window that pops up
          5. Under the System Protection tab, find Available Disks
          6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
          7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
          8. Click OK

          3. Restart computer.

          4. Turn System Restore on.

          As for your desktop ISSUE, try here: http://www.bleepingcomputer.com/forums/topic43064.html
          Hi,

          Thanks for your advice. I following the advice in the link re the desktop issue, but still have the same problem. Any other ideas?

          Cheers
          NickTry here: http://www.bleepingcomputer.com/forums/topic82723.html, post #2

          3034.

          Solve : Possible Nasty from Hijack this decoder.?

          Answer»

          I have been going to this site to check my Hijack this loggs, http://www.hijackthis.de/ . They say I have possible Nastys, Could you guys be so kind to check this out? Hijack this logg.....Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 9:13:03 AM, on 6/1/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Network ASSOCIATES\VirusScan\SHSTAT.EXE
          C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
          C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\Program Files\Messenger\msmsgs.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
          C:\Program Files\Network Associates\VirusScan\Mcshield.exe
          C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
          C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\PnkBstrA.exe
          C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Trend Micro\Sniper.exe\Sniper.exe.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R3 - URLSearchHook: Yahoo! TOOLBAR - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
          O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
          O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe resetprofile
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
          O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
          O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
          O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
          O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
          O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
          O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
          O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
          O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe

          --
          End of file - 5751 bytes
          I REALLY don't see anything out of the ordinary...except for maybe sniper.exe.exe...

          This seems to be EBAY related...so I assume you have a program installed that may be monitoring eBay ITEMS and/or auctions.

          I'm not a malware specialist, so I'll leave that up to them.

          In the interim...I've found a nice little program on the net...that scans your system processes and gives you a detailed analysis of each one...along with recommendations to any that may be known threats.

          Here's the link...and I hope you find it useful...I know I have.Sniper.exe is hiajckthis.exe renamed by srtony1946 for security reasons.
          Some malwares can sniff hijackthis.exe running, so sometimes, it's a good idea to rename.

          srtony1946
          HJT log is clean, except for this:
          - O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          No biggy, just Realtek "call home" crap.
          You can fix it with HJT, and remove ALCMTR.EXE file from C:\Windows. You may need Safe Mode to do this.

          3035.

          Solve : What is the significance of a "warning"?

          Answer»

          I have just done a full system scan with Avira Antivirus. The only item LISTED is a "warning' and it specifically is "G:\pagefile.sys" . The reference of the scan to it is "could not scan FILE". I do understand the literal statement--but what is it's significance? thank you, truenorth
          O/S win xp-pro sp2You should probably set the AV to ignore that file.

          http://www.castlecops.com/t38769-pagefile_sys.htmlevilfantasy,thank you for your REPLIES on both my posts re Avira.While it is far too early for me to comment on it's functioning i can say i am very impressed with it's download/install efficiency. I really like the way it looks. It seems to really aggressively update it's virus definitions ( multi times daily). Seems much more user friendly compared to Avast and AVG.Took about 25-30 minutes for a full scan on 4 hdd--which i think is very good.truenorth

          3036.

          Solve : I think I have a Keylogger?

          Answer»

          Hey guys I joined here hoping to get some help as I think my computer is infected with a Keylogger. I have followed all of the steps in the "Read this before requesting malware removal help" thread. Thanks My logs are as follows:

          [recovering space - attachment deleted by admin]I don't see any evidence of a keylogger or any other malware for that matter. Are you having any problems or just suspicious?Ok thank you very much. I was suspicious as my account on an online game was locked as they believed that someone knew my password. I did everything I could to search for a keylogger and I decided to post my log just to be sure and have an expert check too. Thanks again, I can now sleep easy Quote

          I was suspicious as my account on an online game was locked as they believed that someone knew my password.
          It doesn't mean someone does know your password. You could have logged on at once place and maybe logged on at another computer right afterwards. This may have been detected as SIMULTANEOUS log in which may AROUSE suspicion.

          I suggest changing your password at least once every month.Quote
          It doesn't mean someone does know your password.

          I agree.

          Since SUPERAntiSpyware didn't turn up anything then I would think you are safe.

          Here is a program to help monitor suspicious activities and a great addition to any PC.

          To prevent unknown applications from being installed on your computer install WinPatrol 2008
          Using Winpatrol to protect your computer from malicious software

          ---------

          Then some final cleanup steps.

          Use the Secunia Software Inspector to check for out of date software.
          • Click Start Now
          • Check the box next to Enable thorough system inspection.
          • Click Start
          • Allow the scan to finish and scroll down to see if any updates are needed.
          • Update anything listed.
          .
          So how did I get infected in the first place? by TONY Klien.

          How to prevent Malware by Miekiemoes.Nice read(s), Evilfantasy Thanks Evilfantasy. I can honestly say that I wish I had half the knowledge of computers you do Heh, a LOT of it is first HAND experience.....
          3037.

          Solve : what can viruses do??

          Answer»

          can virsues copies DIRECTORIES from PLACES to other places on the same pc?Depends what is COPIED. Why? Do you suspect a virus?*.tif FILES....!Viruses can ruin your entire life. You're a man of a few WORDS, aren't you, Hi?

          3038.

          Solve : Computer full of crap?

          Answer»

          Sup. My IE likes to freeze alot, and so many of my programs, so I THINK may have alot of crap on my computer. Recently I ACCIDENTALLY installed some spyware while searching for video codecs and I'm getting alot of popup boxes with "Your cpomputer is infected with dangerous virus" messages and many IE links forward to a malware scanner site. Ran both AVG and SUPERantispyware programs.

          Wanted to post my Hijack Log and would appreciate if someone could quickly point out some items to fix.

          Much appreciated!

          -Jason




          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 2:20:50 PM, on 1/06/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          C:\Program Files\Corporate Backup\BackupScheduler\BackupScheduler.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
          C:\Program Files\Norton AntiVirus\navapsvc.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZipm12.exe
          C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\UltraVNC\winvnc.exe
          C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\RunDll32.exe
          C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
          C:\Program Files\Microsoft IntelliType Pro\type32.exe
          C:\Program Files\Microsoft IntelliPoint\point32.exe
          C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
          C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\Program Files\PowerISO\PWRISOVM.EXE
          C:\PROGRA~1\AVG\AVG8\avgtray.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\DAEMON Tools\daemon.exe
          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
          C:\PROGRA~1\MICROS~3\rapimgr.exe
          C:\Program Files\Skype\Phone\Skype.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          C:\Program Files\Skype\Plugin Manager\skypePM.exe
          C:\Program Files\Mozilla Thunderbird\thunderbird.exe
          C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
          C:\Program Files\MSN Messenger\msnmsgr.exe
          C:\Program Files\MSN Messenger\usnsvc.exe
          C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe
          C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\AVG\AVG8\avgui.exe
          C:\Program Files\AVG\AVG8\avgscanx.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.0.0.1:3128
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
          O2 - BHO: SVC plugin - {AAF635CA-04C2-4EBA-B022-3A2F95A05A62} - C:\WINDOWS\iksaxu.dll
          O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
          O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
          O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar6.dll
          O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
          O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
          O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
          O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
          O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
          O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /STARTUP
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\winvnc.exe" -servicehelper
          O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [imjpmig] C:\IME\IMJP\imjpmig.exe /RemAdvDef /AIMEREG /Migration /SetPreload
          O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
          O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
          O4 - HKCU\..\Run: [Synconizer] C:\Program Files\Synconizer\Synconizer.exe /autorun
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
          O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_9 -reboot 1
          O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
          O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
          O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
          O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
          O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
          O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=http://dsl.optusnet.com.au/
          O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
          O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.truedoc.com/activex/tdserver.cab
          O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
          O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MusicAccess/ie/bridge-c5.cab
          O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126258891281
          O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
          O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
          O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
          O16 - DPF: {FE8400F2-C848-4379-989F-DF2ED39040BE} (Eyeball Instant Messaging Control) - http://www.rsvp.com.au/chat/RSVPChat.cab
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
          O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          O23 - Service: BackupScheduler - Unknown owner - C:\Program Files\Corporate Backup\BackupScheduler\BackupScheduler.exe
          O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
          O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZipm12.exe
          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
          O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
          O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
          O23 - Service: VNC Server (winvnc) - UltraVNC - C:\Program Files\UltraVNC\winvnc.exe

          --
          End of file - 16120 bytes
          Are you running more than one antivirus program?

          I saw entries for Symantec / Norton and for AVG.

          Running two antivirus programs will cause conflicts that affect system performance, for starters.

          My recommendation is based upon the general consensus you'll receive here. Remove Norton Antivirus and continue with AVG.

          I'm not terribly experienced with reading the rest, but my impression is that you have a lot of programs/applications running "resident" and taking up Random Access Memory space.

          Please be patient, as there are several members of this forum who are EXPERT at reading the Hijack This Log and interpreting what's going on. One or more will be more than HAPPY to respond.

          Welcome to the CH forum!
          ^ Done. Thanks All right. See if that helps, and check this thread again. There are others here who are more experienced and may have more recommendations for you.What's the situation with Norton, and AVG?
          As Aegis said, you can't run two AV programs. Which one do you decide to keep?I kept AVG. I never like Norton anyway.

          I eventually found an antispyware program that got rid of the malware - Malwarebyte's Anti-Malware.

          This was the only one that got rid of it. Others, including AVG and SuperAntiSpyware did not. However AVG is great it preventing further infections.

          I would look for an new virus scanner I hear complaints about the avg 8. Even thought you dont need it you'll end up updating too it sooner or later.I'd like to see Malwarebytes log, and fresh HJT log, just to make sure, all is fine.Quote

          I hear complaints about the avg 8
          If AVG installed, and works fine, no reason to touch it.
          3039.

          Solve : What causes the spread of the ctfomon [ forgot the spelling ] virus??

          Answer»

          I'm looking through the forum and see a lot of people that EITHER have the problem or had it [ I'm even a VICTIM myself ].

          I'm just WONDERING what COULD have caused us to get this infection?

          BAD downloading?

          Most likely a dodgey download.

          http://www.prevx.com/filenames/X2371345958929863758-X1/CTFMONA.EXE.html

          3040.

          Solve : Shared documents ate its self...?

          Answer»

          It all started yesterday while I wasn't around, so I don't know if I'm getting the full story, but oh well.

          My YOUNGER brother was here on this PC, he was listening to a mp3 from shared documents... next track goes to play, file not found. Even the file he was listening to before is gone, and oh my god... everything in shared documents is gone! All of it... I never even backed that stuff up.. Dunno if there's a way to get that back.. :/

          But anyway, there's more.. after this over the phone I tell my sister to try rebooting... she does and well, windows wouldn't start up, I had to do a repair install to get it back again.
          I'm to scared to even turn the PC off now. I'm doing a virus scan with Prevx... wanted to try AVG as well but it keeps locking up on install plus a few other things are acting a bit strange to... like how I can't seem to view the system propertys, it takes a long TIME to load..

          But seriously... I had 29GB remaining on my C drive before this, now it's 75GB... did it get so fed up with being over filled. How rude of it...

          EDIT: I ALSO appear to have no sound, this is turning out to be a bad day.
          Edit2: Just had a Blue screen of death.. trying to load in safe mode, but the Administrator account is taking a very long time to open.Try doing a search for your mp3's to see if you can locate any.Can't.. they are gone... the space they took up has been freed up and it was more then just mp3s in there.. there was also videos and things. Did you check your recycle bin? If someone accidently deleted them you may be able to get them back with System Restore but before doing that the best route would be to eliminate the possibility that you are infected. If you're clean then System restore might get them back. You should download hijack this, run and post the log on your next post. I'm sure one of the malware experts can check it. The big question here is were they deleted or removed by some infection. After restoring windows by having to do a recovery install, all old system restore points have gone. It SUCKS..

          They also aren't in the recycle bin...
          I'm starting to think I should save what remains (As my documents are fine) and reformat..Sorry for the double post...
          Update, installed SP3 again, seems better now... but I'm still a little on edge, spybot finds nothing, hm.. I have something of a personal experience to share.

          I used to keep a lot of homework, music, ect in my shared folder with one of my other computers and I accidentally disconnected the shared folder, getting rid of everything inside.

          I suspect something similar happened here...How do you disconnect the shared folder?
          It's on the same drive as everything else, so I don't know what you mean... also why would windows screw up after as well?

          3041.

          Solve : Nothing seems to work?

          Answer»

          Hi there,

          My PROGRAMS on my laptop aren't working. I click repeatedly on links but to no avail. Also, I have the sound turned on at the moment, but would like to switch it on but I can't due to the fact that the window will not pop up.
          I have a suspicion it's because I visited some new websites yesterday as since then, nothing seems to work. Anyone know why this might be? I've tried loading up Nortons Antivirus but like everything else, it won't load up

          ThanksYou're infected. You need to boot into Safe Mode with networking / update your Norton and run a scan. Then follow Broni's advice here...

          1. Download SUPERAntiSpyware Free for Home Users:
          http://www.superantispyware.com/
          * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
          * An icon will be created on your desktop. Double-click that icon to launch the program.
          * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
          * Close SUPERAntiSpyware.
          Restart COMPUTER in Safe Mode.
          To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen
          * Open SUPERAntiSpyware.
          * Under "Configuration and Preferences", click the Preferences button.
          * Click the Scanning Control tab.
          * Under Scanner Options make sure the following are checked (leave all others UNCHECKED):
          o Close browsers before scanning.
          o Scan for tracking cookies.
          o Terminate memory threats before quarantining.
          * Click the "Close" button to leave the control center screen.
          * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
          * On the left, make sure you check C:\Fixed Drive.
          * On the right, under "COMPLETE Scan", choose Perform Complete Scan.
          * Click "Next" to start the scan. Please be patient while it scans your computer.
          * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
          * Make sure everything has a checkmark next to it and click "Next".
          * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
          * If asked if you want to reboot, click "Yes".
          * To retrieve the removal INFORMATION after reboot, launch SUPERAntispyware again.
          o Click Preferences, then click the Statistics/Logs tab.
          o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
          o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
          o Please copy and paste the Scan Log results in your next reply with a new HijackThis log.
          * Click Close to exit the program.
          Post SUPERAntiSpyware log.
          RESTART COMPUTER!
          2. Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) to your desktop.
          * Double-click mbam-setup.exe and follow the prompts to install the program.
          * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
          * If an update is found, it will download and install the latest version.
          * Once the program has loaded, select Perform full scan, then click Scan.
          * When the scan is complete, click OK, then Show Results to view the results.
          * Be sure that everything is checked, and click Remove Selected.
          * When completed, a log will open in Notepad.
          * Post the log back here.
          The log can also be found here:
          C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
          Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

          RESTART COMPUTER!

          3. Post new HijackThis log.

          Alan <>< Thanks for the reply - i've booted into safe mode, restored the system to yesterday and everything is fine now. It turns out I had a trojan called 'Trojan.Gpcoder.E'.
          On my Nortons 360 software however, it doesn't seem to be able to carry out a virus scan, it says that an error has occured and when I click on a link 'Files Removed by Virus and Spyware Scan' it justs lists the name of the trojan.

          Thanks againIf your computer is infected, System Restore won't remove infection.

          Let me edit ale52's post a little...

          Print these instructions out.

          1. Download SUPERAntiSpyware Free for Home Users:
          http://www.superantispyware.com/

          * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
          * An icon will be created on your desktop. Double-click that icon to launch the program.
          * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
          * Close SUPERAntiSpyware.

          PHYSICALLY DISCONNECT FROM THE INTERNET

          Restart computer in Safe Mode.
          To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

          * Open SUPERAntiSpyware.
          * Under "Configuration and Preferences", click the Preferences button.
          * Click the Scanning Control tab.
          * Under Scanner Options make sure the following are checked (leave all others unchecked):
          o Close browsers before scanning.
          o Scan for tracking cookies.
          o Terminate memory threats before quarantining.
          * Click the "Close" button to leave the control center screen.
          * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
          * On the left, make sure you check C:\Fixed Drive.
          * On the right, under "Complete Scan", choose Perform Complete Scan.
          * Click "Next" to start the scan. Please be patient while it scans your computer.
          * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
          * Make sure everything has a checkmark next to it and click "Next".
          * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
          * If asked if you want to reboot, click "Yes".
          * To retrieve the removal information after reboot, launch SUPERAntispyware again.
          o Click Preferences, then click the Statistics/Logs tab.
          o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
          o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
          o Please copy and paste the Scan Log results in your next reply.
          * Click Close to exit the program.
          Post SUPERAntiSpyware log.

          RECONNECT TO THE INTERNET

          RESTART COMPUTER!

          2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

          * Double-click mbam-setup.exe and follow the prompts to install the program.
          * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
          * If an update is found, it will download and install the latest version.
          * Once the program has loaded, select Perform full scan, then click Scan.
          * When the scan is complete, click OK, then Show Results to view the results.
          * Be sure that everything is checked, and click Remove Selected.
          * When completed, a log will open in Notepad.
          * Post the log back here.

          The log can also be found here:
          C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
          Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

          RESTART COMPUTER!

          3. Download HijackThis:
          http://www.snapfiles.com/get/hijackthis.html
          Post HijackThis log.

          3042.

          Solve : Unknown virus removal/recommended non-lagging virus protection?

          Answer»

          Well, here it is

          A little STRANGE though. The moment I stopped Avast!, the computer was...fine...huh
          May have been the fact that I torrented it

          [recovering space - attachment DELETED by admin]There is absolutely no reason to torrent a free product.

          This PC is so infected there is little choice but to reformat and start over. I won't help fix over and over what shouldn't be there to start with. Every step I TAKE FORWARD is negated by careless actions.

          I'm done.

          3043.

          Solve : Bugs eating background, background changed to blue with spyware warning ...?

          Answer» THANKS and GOOD LUCK!!!!
          3044.

          Solve : Avira antivirus software?

          Answer»

          Greetings,Recently uninstalled AVG 8.01,Had some problems with Avast. Anyone tried and have opinions on "AVIRA" Thank you,truenorthAvira is a very good AV and I have heard it has made some good improvements recently. Many swear by it.With reference to Avira--while i am far from an expert on it and due to only very recently have installed it i cannot with credibility comment on it's efficacy. I will say the following;when you download the file you automatically get a licence key that is generated without your input. However it may be your experience (as it was mine) that the key installed is already out of date (mine was for May 31st and i didn't download the program until June 2ND).The result of this is that you will not be able to "update" the virus definitions. Without a valid key you cannot interact with their site. In ORDER to find out how to get a valid key i found it NECESSARY to join the forum for Avira. It TOOK a bit of back and forthing before that issue got solved. All this to say it looks like a good program but if you try to get it on your computer it may take a bit of EFFORT. truenorth

          3045.

          Solve : Illusory and Hidden folders out of the blue plz help?

          Answer»

          I wrote this post in the wrong section... So I post it again;


          Hi there,

          Thanx for your effort to help poor people like me

          I've got the following problem:

          I've Vista and a brand new laptop which is protected by authentic norton anti-virus and I run automatic Windows update. (I am highly protective girl) However i ve got a virus from a flash memory. Now my Windows is creating illusory folders out of the blue ( i dunno if it is properly stated) . These folders such as( recycle.bin, system volume info and some repeated folders) are empty and most are shortcuts. Some are said to be dat files, thumbs and desktop.ini (system files) and it is said that their deletion can harm my computer. But once i DELETE them they are back again. They are on drivers and documents. I run a full scan but it seems Norton unable to see them and state that my computor is secured.

          Sorry for this prolonged post. I am in great need for your help.

          Thanx in advance You're supposed to run some scans, and post appropriate logs...Quote

          i ve got a virus from a flash memory

          Download Flash_Disinfector.exe by sUBs and save it to your desktop:

          • Double-click Flash_Disinfector.exe to run it.
          • Your desktop and icons may disappear. This is normal.
          • Follow any prompts that may appear.
          • The utility may ask you to insert your flash drive and/or other removable drives INCLUDING your mobile phone. Please do so and allow the utility to clean up those drives as well.
          • Wait until it has finished scanning and then exit the program.
          • Reboot your computer when done.
          Note: Flash Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from FUTURE infection.Running sUBs Flash Disinfector will target ALOT of auto run infections and create a hidden folder named autorun.inf on each partition and any USB drive you plug in, these dummy autorun.inf files will help protect your PC from reinfection because if the infected flash drive is then inserted, autorun looks for autorun.inf which would normally run the worm but its then prevented by the dummy autorun.inf that is in place. If you have any USB drives please insert them when prompted when running the tool.
          I did run some scans but it's said my computer is secure!? yet these empty and system folders are everywhere.

          Concerning the Flash_Disinfector.exe, is it compatible with Vista? coz when to install, it's said it's unknown publisher and it may cause harm to the computer... SHALL I run it anyway?


          Thanks again
          I am much obliged You will get that warning from a lot of programs that aren't Microsoft approved.

          It is a reliable program. That said nothing we suggest can be used against us But I have used it myself and suggested it's use many times with no bad results.
          3046.

          Solve : Stuck with CoolWebSearch virus and it pieces?

          Answer»

          File 1

          [recovering space - attachment deleted by admin]2nd file

          [recovering space - attachment deleted by admin]3rd file

          [recovering space - attachment deleted by admin]4th and final - sorry I didn'tknow how else to do thisoops 4th

          [recovering space - attachment deleted by admin]Looks good, how is everything now?

          ----------

          Let's clear out the programs we've been using to clean up your computer, they are not suitable for
          general malware removal and could CAUSE damage if launched accidentally. These steps will also HELP secure the work you have done.
          .

          • Click START then RUN
          • Now type Combofix /u in the runbox
          • Make sure there's a space between Combofix and /u
          • Then hit Enter.
          .
          .
          The above procedure will:
          • Delete:
            • ComboFix and its associated files and folders.
            • VundoFix backups, if present
            • The C:\Deckard FOLDER, if present
            • The C:_OtMoveIt folder, if present
            • RESET the clock settings.
            • Hide file extensions, if required.
            • Hide System/Hidden files, if required.
            • Set a new, clean Restore Point.
            .
            ---------

            Set a New Restore Point to prevent possible reinfection from an old one
            Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
            • Go to Start > Programs > Accessories > System Tools and click System Restore
            • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
            • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
            • Next go to Start > Run and type Cleanmgr
            • Click OK
            • Click the More Options Tab.
            • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
            .
            ----------

            Use the Secunia Software Inspector to check for out of date software.
            • Click Start Now
            • Check the box next to Enable thorough system inspection.
            • Click Start
            • Allow the scan to finish and scroll down to see if any updates are needed.
            • Update anything listed.
            .
            ----------

            Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

            To prevent unknown applications from being installed on your computer install WinPatrol 2008
            Using Winpatrol to protect your computer from malicious software

            Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

            SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
            Using SpywareBlaster to protect your computer from Spyware and Malware

            Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

            Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

            Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!
            3047.

            Solve : Rundll system error system32/rhdfmahd.dll (please help)?

            Answer»

            Go Start>Run, type in:
            regedit
            Click OK.

            Navigate to:
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
            You'll see following sub-key:
            opnnnLbC
            Right click on it, click Delete. Confirm.

            Restart computer. Post new HJT log.Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:17:04 AM, on 6/4/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\PROGRA~1\SYMANT~1\VPTray.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
            C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
            C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
            C:\Program Files\Symantec AntiVirus\DoScan.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            C:\Program Files\Symantec AntiVirus\DefWatch.exe
            C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Symantec AntiVirus\Rtvscan.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\Program Files\Trend Micro\HijackThis\sniper.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(DEFAULT) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
            O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: Flashget Catch Url Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
            O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
            O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
            O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
            O2 - BHO: Camfrog Toolbar - {AF2A1C5A-1AED-4E92-8BA8-D708EB79537E} - C:\Program Files\Camfrog\CamfrogBar\CamfrogBar.dll
            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
            O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
            O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
            O3 - Toolbar: Camfrog Toolbar - {AF2A1C5A-1AED-4E92-8BA8-D708EB79537E} - C:\Program Files\Camfrog\CamfrogBar\CamfrogBar.dll
            O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
            O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
            O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
            O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
            O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
            O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
            O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
            O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
            O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
            O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
            O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
            O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-id\msntabres.dll.mui/229?2a6106fb2b394737aa57cbbcecf95a6b
            O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-id\msntabres.dll.mui/230?2a6106fb2b394737aa57cbbcecf95a6b
            O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
            O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
            O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O21 - SSODL: VolumeRom - {f3d24e24-e4f6-4b23-b413-6abfa5715e0b} - C:\WINDOWS\Resources\VolumeRom.dll (file missing)
            O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - F:\yopi\Ares\chatServer.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: Bluetooth Service (btwdins) - BROADCOM Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
            O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
            O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
            O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

            --
            End of file - 11194 bytes
            Very good

            Your computer is clean

            1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
            Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
            Run CCleaner.

            2. Turn off System Restore:

            - Windows XP:
            1. Click Start.
            2. Right-click the My Computer icon, and then click Properties.
            3. Click the System Restore tab.
            4. Check "Turn off System Restore".
            5. Click Apply.
            6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
            7. Click OK.
            - Windows Vista:
            1. Click Start.
            2. Right-click the Computer icon, and then click Properties.
            3. Click on System Protection under the Tasks column on the left side
            4. Click on Continue on the "User Account Control" window that pops up
            5. Under the System Protection tab, find Available Disks
            6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
            7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
            8. Click OK

            3. Restart computer.

            4. Turn System Restore on.

            5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

            6. Read So how did I get infected in the FIRST place?: http://www.castlecops.com/postlite7736-.html

            7. Let me KNOW, how your computer is doing.

            I think my computer is doing good.....thanks a lot for your (Broni) help Very well, then.
            Happy surfing

            3048.

            Solve : deleting WgaTray.exe?

            Answer»

            I have XP Pro. I did a google on WgaTray.exe and The Inquirer came up, with directions on how to delete it permanently, but I wondered if you have an easier way?
            The directions are as follows:

            There are 2 parts to this spyware popup: WGAtray.exe and wgalogon.dll. Killing the WGAtray.exe process causes it to reappear in 1 second. With it present, WGAlogon cannot be deleted. And you can't delete it while it's running. Seem impossible? Nah.
            First, you need to have an Explorer window open and pointing ( ) to the C:windowssystem32 folder, where the spyware resides (interestingly, doing a hard drive search for "wgatray" turns up nothing- clever spyware, this is!). And you have to have Task Manager open, right beside the Explorer window. This is TRICKY, and must be done fast- you kill the process in Task Manager, and before the spyware can reopen itself, you must delete WGAtray.exe in the Explorer window. You only have a split second, but it is possible. Once the spyware .exe is gone, you must reboot your computer.
            Yes, now you will see the spyware's nag screen. No problem, it's the last time. When you DO finally get to the desktop, do a search "for WGAlogon.dll" You will find 2 copies, one in system32 and one in the dllcache folder. Without the WGAtray spyware to protect them (did you notice it was gone? YAY!), you can rename and then delete both these spyware .dll's. Your system may hang when you reboot it the first time, but when it is brought back up, THE SPYWARE IS ALL GONE.
            Whew. Man, I may have to stop using Windows Update. It installs spyware!WGATray.exe - Genuine Windows Advantage (WGA)

            First, it's not spyware. I KNOW anything that monitors your PC is considered spyware by many but let's not go over board and have anybody reading this think their PC is infected.

            Quote

            wgatray.exe is a process which belongs to the Microsoft Windows Operating System and provides a notification system for Windows Genuine Advantage product validation software. This program is a non-essential process, but should not be terminated unless SUSPECTED to be causing problems.

            wgatray.exe - What is wgatray.exe?

            How to disable Microsofts new Anti-Piracy Program UpdateAs they say I'm counterfeit anyway, I was just tired of it wasting CPU. It's all the memory usage going out THRU svchosts I need to concentrate on.
            Thank you for saving me from further complicating myself!

            [recovering space - attachment deleted by admin]Try this > http://www.mlin.net/StartupCPL.shtmlThanks, evilfantasy.
            I feel guilty downloading stuff and GETTING info from ppl when I'm too broke to donate for all they've done.
            3049.

            Solve : Unknown applications evil??

            Answer»
            I have XP Pro, with BITDEFENDER. In BD Firewall section, in the traffic list, I see some applications with no names, some of them with tcp, some udp protocol, all say "any" under source address, source PORT, and destination address, destination ports are: 135(I read that's never good), 386, or 88. No path listed on any. I also have some of the anonymous app's that do have a destination port OR source port. Are these evil?
            PC issues causing me to study all I can. Nearest computer class is about 50 miles away.


            [recovering space - attachment DELETED by admin]
            3050.

            Solve : Screensaver Virus with Bugs Maybe Others?

            Answer»

            Screensaver shows bugs eatign a retarded jpg file that the desktop pic was change into saying I (friends pc) had spyware. Which ironically is true lol..
            KK here is HJT Log

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:22:51 AM, on 6/3/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Viewpoint\Common\ViewpointService.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
            C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
            C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            O2 - BHO: (no name) - {32341E7E-C319-46DE-91D0-E30BB1A3CABA} - C:\WINDOWS\system32\vtUolMEu.dll (file missing)
            O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
            O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
            O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
            O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
            O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm128MGUS
            O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Haley\Start Menu\Programs\IMVU\Run IMVU.lnk
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O12 - PLUGIN for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/ZwinkyInitialSetup1.0.0.15-3.cab
            O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/SP.cab
            O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
            O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
            O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft EXTERNAL Control) - http://connect.comcast.com/dl/Comcast%20Activation%20Controls.cab
            O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1174761884390
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1174763175624
            O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_activex/en-US/TSEasyInstallX.CAB
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O20 - Winlogon Notify: vtUolMEu - vtUolMEu.dll (file missing)
            O20 - Winlogon Notify: __c00845E6 - C:\WINDOWS\system32\__c00845E6.dat
            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            O23 - Service: PIXMA Extended SURVEY Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
            O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

            --
            End of file - 9227 bytes
            You are infected.

            Prior to posting a HJT log, we ask that you please read and follow all instructions in the pinned topic titled Please read this before requesting malware removal help. Following the steps in the Guide will allow for us to quickly help you with specific fixes for what may remain on your system.

            When you have completed those steps post the logs in the Computer Viruses and Spyware forum as outlined in the Please read this thread.

            Thanks - CH Staff Currently runnin malwarebytes, Ran SuperAntiSpyware remover and got AVG running passively.Sounds good. Once the logs are posted we will go from there.SUPERAntiSpyware Scan Log
            http://www.superantispyware.com

            Generated 06/03/2008 at 10:09 AM

            Application Version : 4.15.1000

            Core Rules Database Version : 3473
            Trace Rules Database Version: 1464

            Scan type : Quick Scan
            Total Scan Time : 00:26:23

            Memory items scanned : 495
            Memory threats detected : 3
            Registry items scanned : 391
            Registry threats detected : 185
            File items scanned : 19615
            File threats detected : 133

            Adware.Vundo Variant/Resident
            C:\WINDOWS\SYSTEM32\YAYVSJDT.DLL
            C:\WINDOWS\SYSTEM32\YAYVSJDT.DLL

            Trojan.Vundo-Variant/Small
            C:\WINDOWS\SYSTEM32\BAYNWBLM.DLL
            C:\WINDOWS\SYSTEM32\BAYNWBLM.DLL
            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1A62B230-32EF-4483-AB2F-AE70143901CB}
            HKCR\CLSID\{1A62B230-32EF-4483-AB2F-AE70143901CB}
            HKCR\CLSID\{1A62B230-32EF-4483-AB2F-AE70143901CB}\InprocServer32
            HKCR\CLSID\{1A62B230-32EF-4483-AB2F-AE70143901CB}\InprocServer32#ThreadingModel
            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8799a095-949c-44fc-968a-a7b2ad5f826d}
            HKCR\CLSID\{8799A095-949C-44FC-968A-A7B2AD5F826D}
            HKCR\CLSID\{8799A095-949C-44FC-968A-A7B2AD5F826D}\InprocServer32
            HKCR\CLSID\{8799A095-949C-44FC-968A-A7B2AD5F826D}\InprocServer32#ThreadingModel
            C:\WINDOWS\SYSTEM32\GTYLGKRE.DLL
            C:\WINDOWS\SYSTEM32\IIFGGGGE.DLL
            C:\WINDOWS\SYSTEM32\OPNMJYPQ.DLL
            C:\WINDOWS\SYSTEM32\WUSSAVON.DLL
            C:\WINDOWS\SYSTEM32\YAYXYYAA.DLL

            Trojan.Downloader-NewJuan/VM
            C:\WINDOWS\SYSTEM32\ANINQJMM.DLL
            C:\WINDOWS\SYSTEM32\ANINQJMM.DLL

            Trojan.Unclassified/SysRest32
            [sysrest32.exe] C:\WINDOWS\SYSTEM32\SYSREST32.EXE
            C:\WINDOWS\SYSTEM32\SYSREST32.EXE
            C:\WINDOWS\Prefetch\SYSREST32.EXE-2FA2622A.pf

            Adware.Zango/ShoppingReport
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B2}
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B3}
            HKCR\CLSID\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}
            HKCR\CLSID\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}\Implemented Categories
            HKCR\CLSID\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
            HKCR\CLSID\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}\InprocServer32
            HKCR\CLSID\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}\InprocServer32#ThreadingModel
            HKCR\CLSID\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}\ProgID
            HKCR\CLSID\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}\TypeLib
            HKCR\CLSID\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}\VersionIndependentProgID
            HKCR\ShoppingReport.HbAx
            HKCR\ShoppingReport.HbAx\CLSID
            HKCR\ShoppingReport.HbAx\CurVer
            HKCR\ShoppingReport.HbAx.1
            HKCR\ShoppingReport.HbAx.1\CLSID
            HKCR\ShoppingReport.HbInfoBand
            HKCR\ShoppingReport.HbInfoBand\CLSID
            HKCR\ShoppingReport.HbInfoBand\CurVer
            HKCR\ShoppingReport.HbInfoBand.1
            HKCR\ShoppingReport.HbInfoBand.1\CLSID
            HKCR\ShoppingReport.IEButton
            HKCR\ShoppingReport.IEButton\CLSID
            HKCR\ShoppingReport.IEButton\CurVer
            HKCR\ShoppingReport.IEButton.1
            HKCR\ShoppingReport.IEButton.1\CLSID
            HKCR\ShoppingReport.IEButtonA
            HKCR\ShoppingReport.IEButtonA\CLSID
            HKCR\ShoppingReport.IEButtonA\CurVer
            HKCR\ShoppingReport.IEButtonA.1
            HKCR\ShoppingReport.IEButtonA.1\CLSID
            HKCR\ShoppingReport.RprtCtrl
            HKCR\ShoppingReport.RprtCtrl\CLSID
            HKCR\ShoppingReport.RprtCtrl\CurVer
            HKCR\ShoppingReport.RprtCtrl.1
            HKCR\ShoppingReport.RprtCtrl.1\CLSID
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\Control
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\Implemented Categories
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\InprocServer32
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\InprocServer32#ThreadingModel
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\ProgID
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\Programmable
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\ToolboxBitmap32
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\TypeLib
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\Version
            HKCR\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}\VersionIndependentProgID
            HKCR\CLSID\{A16AD1E9-F69A-45AF-9462-B1C286708842}
            HKCR\CLSID\{A16AD1E9-F69A-45AF-9462-B1C286708842}\InprocServer32
            HKCR\CLSID\{A16AD1E9-F69A-45AF-9462-B1C286708842}\InprocServer32#ThreadingModel
            HKCR\CLSID\{A16AD1E9-F69A-45AF-9462-B1C286708842}\ProgID
            HKCR\CLSID\{A16AD1E9-F69A-45AF-9462-B1C286708842}\Programmable
            HKCR\CLSID\{A16AD1E9-F69A-45AF-9462-B1C286708842}\TypeLib
            HKCR\CLSID\{A16AD1E9-F69A-45AF-9462-B1C286708842}\VersionIndependentProgID
            HKCR\CLSID\{C9CCBB35-D123-4A31-AFFC-9B2933132116}
            HKCR\CLSID\{C9CCBB35-D123-4A31-AFFC-9B2933132116}\InprocServer32
            HKCR\CLSID\{C9CCBB35-D123-4A31-AFFC-9B2933132116}\InprocServer32#ThreadingModel
            HKCR\CLSID\{C9CCBB35-D123-4A31-AFFC-9B2933132116}\ProgID
            HKCR\CLSID\{C9CCBB35-D123-4A31-AFFC-9B2933132116}\Programmable
            HKCR\CLSID\{C9CCBB35-D123-4A31-AFFC-9B2933132116}\TypeLib
            HKCR\CLSID\{C9CCBB35-D123-4A31-AFFC-9B2933132116}\VersionIndependentProgID
            HKCR\TypeLib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2}
            HKCR\TypeLib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2}\1.0
            HKCR\TypeLib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2}\1.0\0
            HKCR\TypeLib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2}\1.0\0\win32
            HKCR\TypeLib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2}\1.0\FLAGS
            HKCR\TypeLib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2}\1.0\HELPDIR
            HKCR\TypeLib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF}
            HKCR\TypeLib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF}\1.0
            HKCR\TypeLib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF}\1.0\0
            HKCR\TypeLib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF}\1.0\0\win32
            HKCR\TypeLib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF}\1.0\FLAGS
            HKCR\TypeLib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF}\1.0\HELPDIR
            HKCR\TypeLib\{E343EDFC-1E6C-4CB5-AA29-E9C922641C80}
            HKCR\TypeLib\{E343EDFC-1E6C-4CB5-AA29-E9C922641C80}\1.0
            HKCR\TypeLib\{E343EDFC-1E6C-4CB5-AA29-E9C922641C80}\1.0\0
            HKCR\TypeLib\{E343EDFC-1E6C-4CB5-AA29-E9C922641C80}\1.0\0\win32
            HKCR\TypeLib\{E343EDFC-1E6C-4CB5-AA29-E9C922641C80}\1.0\FLAGS
            HKCR\TypeLib\{E343EDFC-1E6C-4CB5-AA29-E9C922641C80}\1.0\HELPDIR
            HKCR\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB}
            HKCR\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB}\ProxyStubClsid
            HKCR\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB}\ProxyStubClsid32
            HKCR\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB}\TypeLib
            HKCR\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB}\TypeLib#Version
            HKCR\Interface\{AEBF09E2-0C15-43C8-99BF-928C645D98A0}
            HKCR\Interface\{AEBF09E2-0C15-43C8-99BF-928C645D98A0}\ProxyStubClsid
            HKCR\Interface\{AEBF09E2-0C15-43C8-99BF-928C645D98A0}\ProxyStubClsid32
            HKCR\Interface\{AEBF09E2-0C15-43C8-99BF-928C645D98A0}\TypeLib
            HKCR\Interface\{AEBF09E2-0C15-43C8-99BF-928C645D98A0}\TypeLib#Version
            HKCR\Interface\{D8560AC2-21B5-4C1A-BDD4-BD12BC83B082}
            HKCR\Interface\{D8560AC2-21B5-4C1A-BDD4-BD12BC83B082}\ProxyStubClsid
            HKCR\Interface\{D8560AC2-21B5-4C1A-BDD4-BD12BC83B082}\ProxyStubClsid32
            HKCR\Interface\{D8560AC2-21B5-4C1A-BDD4-BD12BC83B082}\TypeLib
            HKCR\Interface\{D8560AC2-21B5-4C1A-BDD4-BD12BC83B082}\TypeLib#Version
            HKU\S-1-5-21-1645522239-162531612-725345543-1004\Software\ShoppingReport
            HKLM\Software\ShoppingReport
            HKLM\Software\ShoppingReport#affid
            HKLM\Software\ShoppingReport#Version
            HKLM\Software\ShoppingReport#ProductName
            HKLM\Software\ShoppingReport#requestor
            HKLM\Software\ShoppingReport#SG_Not_Set
            HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport
            HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport#DisplayIcon
            HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport#DisplayName
            HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport#UninstallString
            HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport#DisplayVersion
            HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport#URLInfoAbout
            HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport#Publisher
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B2}#Default Visible
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B2}#ButtonText
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B2}#HotIcon
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B2}#Icon
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B2}#CLSID
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B2}#ClsidExtension
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B3}#Default Visible
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B3}#ButtonText
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B3}#HotIcon
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B3}#Icon
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B3}#CLSID
            HKLM\Software\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B3}#ClsidExtension
            C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
            C:\Program Files\ShoppingReport\Bin\2.5.0
            C:\Program Files\ShoppingReport\Bin
            C:\Program Files\ShoppingReport\Uninst.exe
            C:\Program Files\ShoppingReport
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\Config.xml
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\db\Aliases.dbs
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\db\Sites.dbs
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\db
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\dwld
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\report\aggr_storage.xml
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\report\send_storage.xml
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\report
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs\res1
            C:\Documents and Settings\shandaros\Application Data\ShoppingReport\cs
            C:\Documents and Settings\shandaros\Application Data\ShoppingReportAdware.Tracking Cookie
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][3].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][3].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][1].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][2].txt
            C:\Documents and Settings\shandaros\Cookies\[emailprotected][5].txt

            Rogue.AdvancedXPDefender
            HKLM\Software\AXPDefender
            HKLM\Software\AXPDefender#MGuid
            HKLM\Software\AXPDefender\AXPDefender
            HKLM\Software\AXPDefender\AXPDefender#RegistrationUrl
            HKLM\Software\AXPDefender\AXPDefender#RegistrationDiscUrl
            HKLM\Software\AXPDefender\AXPDefender#ADVid
            HKLM\Software\AXPDefender\AXPDefender#InstallDir
            HKLM\Software\AXPDefender\AXPDefender#domain
            HKLM\Software\AXPDefender\AXPDefender#SoftID
            HKLM\Software\AXPDefender\AXPDefender#DatabaseVersion
            HKLM\Software\AXPDefender\AXPDefender#ProgramVersion
            HKLM\Software\AXPDefender\AXPDefender#EngineVersion
            HKLM\Software\AXPDefender\AXPDefender#GuiVersion
            HKLM\Software\AXPDefender\AXPDefender#ProxyName
            HKLM\Software\AXPDefender\AXPDefender#ProxyPort
            HKLM\Software\AXPDefender\AXPDefender#ScanPriority
            HKLM\Software\AXPDefender\AXPDefender#DaysInterval
            HKLM\Software\AXPDefender\AXPDefender#ScanDepth
            HKLM\Software\AXPDefender\AXPDefender#ScanSystemOnStartup
            HKLM\Software\AXPDefender\AXPDefender#AutomaticallyUpdates
            HKLM\Software\AXPDefender\AXPDefender#MinimizeOnStart
            HKLM\Software\AXPDefender\AXPDefender#BackgroundScan
            HKLM\Software\AXPDefender\AXPDefender#BackgroundScanTimeout
            HKLM\Software\AXPDefender\AXPDefender#InstallationID
            HKLM\Software\AXPDefender\AXPDefender#LastTimeStamp
            HKLM\Software\AXPDefender\AXPDefender#LastUpdateDate
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\HKCU\RunOnce
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\HKCU
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\HKLM\RunOnce
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\HKLM
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\StartMenuAllUsers
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\StartMenuCurrentUser
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender\Quarantine\BrowserObjects
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender\Quarantine\Packages
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender\Quarantine
            C:\Documents and Settings\shandaros\Application Data\AXPDefender\AXPDefender
            C:\Documents and Settings\shandaros\Application Data\AXPDefender

            Rogue.AdvancedXPFixer
            HKLM\Software\AXPFixer
            HKLM\Software\AXPFixer#MGuid
            HKLM\Software\AXPFixer\AXPFixer
            HKLM\Software\AXPFixer\AXPFixer#RegistrationUrl
            HKLM\Software\AXPFixer\AXPFixer#RegistrationDiscUrl
            HKLM\Software\AXPFixer\AXPFixer#ADVid
            HKLM\Software\AXPFixer\AXPFixer#InstallDir
            HKLM\Software\AXPFixer\AXPFixer#domain
            HKLM\Software\AXPFixer\AXPFixer#SoftID
            HKLM\Software\AXPFixer\AXPFixer#DatabaseVersion
            HKLM\Software\AXPFixer\AXPFixer#ProgramVersion
            HKLM\Software\AXPFixer\AXPFixer#EngineVersion
            HKLM\Software\AXPFixer\AXPFixer#GuiVersion
            HKLM\Software\AXPFixer\AXPFixer#ProxyName
            HKLM\Software\AXPFixer\AXPFixer#ProxyPort
            HKLM\Software\AXPFixer\AXPFixer#ScanPriority
            HKLM\Software\AXPFixer\AXPFixer#DaysInterval
            HKLM\Software\AXPFixer\AXPFixer#ScanDepth
            HKLM\Software\AXPFixer\AXPFixer#ScanSystemOnStartup
            HKLM\Software\AXPFixer\AXPFixer#AutomaticallyUpdates
            HKLM\Software\AXPFixer\AXPFixer#MinimizeOnStart
            HKLM\Software\AXPFixer\AXPFixer#BackgroundScan
            HKLM\Software\AXPFixer\AXPFixer#BackgroundScanTimeout
            HKLM\Software\AXPFixer\AXPFixer#InstallationID
            HKLM\Software\AXPFixer\AXPFixer#LastTimeStamp
            HKLM\Software\AXPFixer\AXPFixer#LastUpdateDate
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer\Quarantine\Autorun\HKCU\RunOnce
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer\Quarantine\Autorun\HKCU
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer\Quarantine\Autorun\HKLM\RunOnce
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer\Quarantine\Autorun\HKLM
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer\Quarantine\Autorun\StartMenuAllUsers
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer\Quarantine\Autorun\StartMenuCurrentUser
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer\Quarantine\Autorun
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer\Quarantine\BrowserObjects
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer\Quarantine\Packages
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer\Quarantine
            C:\Documents and Settings\shandaros\Application Data\AXPFixer\AXPFixer
            C:\Documents and Settings\shandaros\Application Data\AXPFixer

            Adware.Vundo Variant/Rel
            HKLM\SOFTWARE\Microsoft\aoprndtws
            HKLM\SOFTWARE\Microsoft\FCOVM
            HKLM\SOFTWARE\Microsoft\RemoveRP
            HKU\S-1-5-21-1645522239-162531612-725345543-1004\Software\Microsoft\rdfa

            Trojan.Unclassified/WinBx
            C:\DOCUMENTS AND SETTINGS\NEAL CHAPMAN\LOCAL SETTINGS\TEMP\SETUP_J22Q5.EXE

            Trojan.Unknown Origin
            C:\WINDOWS\SYSTEM32\CTFMONB.BMP

            Trojan.Downloader-Gen/Multi
            C:\WINDOWS\SYSTEM32\~.EXE

            Malware Scan sure is time consuming, only 30gb used on this HD and its taken over an hour. Glad this is MY PC lol.

            160,000 files
            1.5hours and counting, pc is only 1300ghz single core, kinda got some age on it.Malware log, after reboot I ran HJT and posting log again now. All Attached

            [recovering space - attachment deleted by admin]Looks good so far.

            You have Viewpoint installed.

            Viewpoint Media Player/Manager/Toolbar is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". See Viewpoint to Plunge Into Adware

            It is suggested to remove the program now.
            Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.

            • Viewpoint
            • Viewpoint Manager
            • Viewpoint Media Player
            • Viewpoint Toolbar
            • Viewpoint Experience Technology
            If you have trouble removing Viewpoint, I suggest that you use ViewpointKiller

            Once you have downloaded ViewpointKiller, unzip it to a convenient location such as your desktop.
            Run ViewpointKiller, and select File > Do All Killings
            Follow the prompts, selecting Yes or No, depending on which selection you are most comfortable with.

            ----------

            Open Hijackthis and select Do a system scan only.

            Place a check mark next to the following entries: (if there)

            - O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            - 020 - Winlogon Notify: vtUolMEu - vtUolMEu.dll (file missing)


            Important: Close all windows except for Hijackthis and then click Fix checked.

            Exit Hijackthis.

            ----------

            Run CCleaner.

            How is everything now?Will be back at pc (belongs to a friend) and will continue with your last advice in about 24hours from this post. <3 thx for everything up til nowAm using a different login user this time. here is a HJT log after I removed the 2 files you advised, and am about to run Superanti again for a quick search on this alt user.

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 8:16:25 PM, on 6/4/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\wscntfy.exe
            C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
            C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
            C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
            R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
            R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
            R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
            O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
            O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
            O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
            O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
            O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Zango\bin\10.3.36.0\Weather.exe" -auto
            O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
            O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
            O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
            O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm128MGUS
            O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
            O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Haley\Start Menu\Programs\IMVU\Run IMVU.lnk
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/SP.cab
            O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
            O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
            O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - http://connect.comcast.com/dl/Comcast%20Activation%20Controls.cab
            O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1174761884390
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1174763175624
            O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_activex/en-US/TSEasyInstallX.CAB
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

            --
            End of file - 9309 bytes
            Open Hijackthis and select Do a system scan only.

            Place a check mark next to the following entries: (if there)

            - R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
            - O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Zango\bin\10.3.36.0\Weather.exe" -auto
            - O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm128MGUS


            Important: Close all windows except for Hijackthis and then click Fix checked.

            Exit Hijackthis.

            ----------

            Create An Uninstall List
            • Start HijackThis
            • Click on the Open the Misc Tools section
            • Click on the Open Uninstall Manager button.
            • Click on the Save list button and specify where you would like to save this file and click Save.
              • When you press Save button a notepad will open with the contents of that file.
            • Copy and paste that list in your reply.
            kk thx again man, count not find the HKCU-weather.exe one, but removed the other 2 plus one for ctmond? or w/e thatw as changing the backdrop + one for aol toolbar, which this pc shouldn't EVEN have.

            NEW HJT LOG

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 8:55:37 PM, on 6/4/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
            C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
            C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
            C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\WINDOWS\system32\notepad.exe
            C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
            R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
            R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
            O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
            O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
            O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
            O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
            O4 - HKUS\S-1-5-21-1645522239-162531612-725345543-1010\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Haley')
            O4 - HKUS\S-1-5-21-1645522239-162531612-725345543-1010\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Haley')
            O4 - HKUS\S-1-5-21-1645522239-162531612-725345543-1010\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (User 'Haley')
            O4 - HKUS\S-1-5-21-1645522239-162531612-725345543-1010\..\Run: [A00F5467D96.exe] C:\DOCUME~1\Haley\LOCALS~1\Temp\_A00F5467D96.exe (User 'Haley')
            O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
            O4 - S-1-5-21-1645522239-162531612-725345543-1010 Startup: IMVU.lnk = C:\Documents and Settings\Haley\My Documents\IMVU\IMVUClient.exe (User 'Haley')
            O4 - S-1-5-21-1645522239-162531612-725345543-1010 User Startup: IMVU.lnk = C:\Documents and Settings\Haley\My Documents\IMVU\IMVUClient.exe (User 'Haley')
            O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
            O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Haley\Start Menu\Programs\IMVU\Run IMVU.lnk
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/SP.cab
            O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
            O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
            O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - http://connect.comcast.com/dl/Comcast%20Activation%20Controls.cab
            O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1174761884390
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1174763175624
            O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_activex/en-US/TSEasyInstallX.CAB
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

            --
            End of file - 9737 bytes

            I was needing an uninstall list.

            Create An Uninstall List
            • Start HijackThis
            • Click on the Open the Misc Tools section
            • Click on the Open Uninstall Manager button.
            • Click on the Save list button and specify where you would like to save this file and click Save.
              • When you press Save button a notepad will open with the contents of that file.
            • Copy and paste that list in your reply.