1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Overrun with Viruses/Malware

Discussion in 'Virus & Other Malware Removal' started by matabao, Nov 5, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. matabao

    matabao Thread Starter

    Joined:
    Nov 5, 2007
    Messages:
    23
    I've got tons of viruses and other bad things that none of my antispyware programs can get rid of (though several of them find them; they just can't remove them). I've tried everything I can think of (which isn't much maybe) and the problem keeps getting worse, maybe because there's a virus downloader in there too. I would greatly appreciate your help in cleaning my system. I've posted a HijackThis log below. If you need anything else, please let me know. Thanks! -Brian

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 8:09:32 AM, on 11/5/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    C:\PROGRA~1\Webshots\webshots.scr
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
    C:\Documents and Settings\HP_Owner\Desktop\HiJackThis_v2.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=pavilion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>;*.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Pictures - {8E929F51-5914-11D6-971F-0050FC3F9161} - C:\Program Files\Pictures Toolbar\Pictures.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\ondlrnkk.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
    O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe"
    O4 - HKLM\..\Run: [SBCSTray] "C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe"
    O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
    O4 - HKLM\..\Run: [ThreatFire] "C:\Program Files\ThreatFire\TFTray.exe"
    O4 - HKLM\..\Run: [b4fe43bd] "rundll32.exe" "C:\WINDOWS\system32\yqpqcqsf.dll",b
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O8 - Extra context menu item: &Search - ?p=ZK
    O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
    O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/SP.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128758963578
    O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.38/ttinst.cab
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712...amai.com/6712/player/install3.0/installer.exe
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712....akamai.com/6712/player/install/installer.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca04.rightnowtech.com/7020-b369h/rnl/java/RntX.cab
    O20 - Winlogon Notify: gebawvs - gebawvs.dll (file missing)
    O20 - Winlogon Notify: ljjjihi - C:\WINDOWS\SYSTEM32\ljjjihi.dll
    O20 - Winlogon Notify: ondlrnkk - ondlrnkk.dll (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    O24 - Desktop Component 0: (no name) - http://www.cartoonnetwork.com/tools/img/homepage/bkgd_gradient.jpg

    --
    End of file - 14083 bytes
     
  2. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Hi and welcome

    Download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    --------------------------------------------------------------------
    1. Close any open browsers.

    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • ...
    --------------------------------------------------------------------

    Double click on combofix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
     
  3. matabao

    matabao Thread Starter

    Joined:
    Nov 5, 2007
    Messages:
    23
    Thank you!

    (It's getting very dicey just getting the machine up now...)

    I hope the ComboFix report is the correct one. I'm not entirely sure it worked correctly, simply because it said it would restore the clock settings, but did not.

    ComboFix:

    ComboFix 07-11-01.1** - HP_Owner 2007-11-05 23:45:21.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.525 [GMT -6:00]
    Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\All Users\Application Data.\salesmonitor
    C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
    C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
    C:\Documents and Settings\HP_Owner\Desktop\Live Safety Center.lnk
    C:\Documents and Settings\HP_Owner\err.log
    C:\Documents and Settings\HP_Owner\My Documents\SSTEM3~1
    C:\Program Files\Common Files\icroso~1
    C:\Program Files\poolsv
    C:\Program Files\svhost
    C:\temp\0b9
    C:\temp\0b9\tmpTF.log
    C:\Temp\1cb
    C:\Temp\1cb\syscheck.log
    C:\temp\iee
    C:\temp\iee\tmpZTF.log
    C:\temp\tn3
    C:\WINDOWS\cookies.ini
    C:\WINDOWS\cs_cache.ini
    C:\WINDOWS\system32\A1
    C:\WINDOWS\system32\a13
    C:\WINDOWS\system32\A3
    C:\WINDOWS\system32\a4
    C:\WINDOWS\system32\A5
    C:\WINDOWS\system32\awtqn.dll
    C:\WINDOWS\system32\awtqp.dll
    C:\WINDOWS\system32\awtsr.dll
    C:\WINDOWS\system32\awvtr.dll
    C:\WINDOWS\system32\e2
    C:\WINDOWS\system32\ecjunssp.exe
    C:\WINDOWS\system32\g1
    C:\WINDOWS\system32\gebca.dll
    C:\WINDOWS\system32\geedc.dll
    C:\WINDOWS\system32\hjllm.ini
    C:\WINDOWS\system32\i8
    C:\WINDOWS\system32\ilnmp.bak1
    C:\WINDOWS\system32\ilnmp.ini
    C:\WINDOWS\system32\ilnmp.tmp
    C:\WINDOWS\system32\jkhfd.dll
    C:\WINDOWS\system32\ljjjihi.dll
    C:\WINDOWS\system32\mljgg.dll
    C:\WINDOWS\system32\mljgh.dll
    C:\WINDOWS\system32\mlljh.dll
    C:\WINDOWS\system32\o09PrEz
    C:\WINDOWS\system32\ondlrnkk.dllbox
    C:\WINDOWS\system32\pac.txt
    C:\WINDOWS\system32\pmkhh.dll
    C:\WINDOWS\system32\pmnnl.dll
    C:\WINDOWS\system32\rtstv.bak1
    C:\WINDOWS\system32\rtstv.ini
    C:\WINDOWS\system32\rtstv.ini2
    C:\WINDOWS\system32\rtstv.tmp
    C:\WINDOWS\system32\ssqpp.dll
    C:\WINDOWS\system32\ssqro.dll
    C:\WINDOWS\system32\ssttr.dll
    C:\WINDOWS\system32\vtuts.dll
    C:\WINDOWS\system32\vtutu.dll
    C:\WINDOWS\system32\win
    C:\WINDOWS\system32\wnstsicomsv32.exe
    C:\WINDOWS\system32\x22
    C:\WINDOWS\winshow.exe
    D:\Autorun.inf

    .
    ((((((((((((((((((((((((( Files Created from 2007-10-06 to 2007-11-06 )))))))))))))))))))))))))))))))
    .

    2007-11-06 00:08 34,360 --a------ C:\WINDOWS\system32\drivers\sbapifs.sys
    2007-11-05 23:39 51,200 --a------ C:\WINDOWS\NirCmd.exe
    2007-11-04 23:46 <DIR> d-------- C:\Program Files\ThreatFire
    2007-11-04 23:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
    2007-11-04 23:46 52,032 --a------ C:\WINDOWS\system32\drivers\TfFsMon.sys
    2007-11-04 23:46 38,720 --a------ C:\WINDOWS\system32\drivers\TfSysMon.sys
    2007-11-04 23:46 34,624 --a------ C:\WINDOWS\system32\drivers\TfNetMon.sys
    2007-11-04 23:46 12,608 --a------ C:\WINDOWS\system32\drivers\TfKbMon.sys
    2007-11-04 21:55 78,912 --a------ C:\WINDOWS\system32\yscdaqpp.dll
    2007-11-04 21:34 78,912 --a------ C:\WINDOWS\system32\oryqxnoa.dll
    2007-11-04 21:31 <DIR> d-------- C:\Program Files\Common Files\Scanner
    2007-11-04 21:22 340,032 --a------ C:\WINDOWS\system32\ynuuqmuo.dll
    2007-11-04 14:26 78,912 --a------ C:\WINDOWS\system32\bpncokoa.dll
    2007-11-04 12:57 78,912 --a------ C:\WINDOWS\system32\yukjbxfb.dll
    2007-11-04 09:15 78,912 --a------ C:\WINDOWS\system32\gckywedl.dll
    2007-11-04 01:03 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys
    2007-11-04 00:10 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\Sunbelt Software
    2007-11-03 09:13 81,472 --a------ C:\WINDOWS\system32\qnlhpsio.dll
    2007-11-02 22:08 <DIR> d-------- C:\Program Files\Enigma Software Group
    2007-11-01 07:22 413,009 --ahs---- C:\WINDOWS\system32\ijllm.bak2
    2007-10-30 07:43 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\MySpace
    2007-10-30 07:07 <DIR> d-------- C:\WINDOWS\system32\Mz08r
    2007-10-30 07:07 <DIR> d-------- C:\temp\mZOr
    2007-10-19 07:25 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
    2007-10-14 15:59 <DIR> d-------- C:\Program Files\Imikimi
    2007-10-14 15:55 1,068,216 --a------ C:\Documents and Settings\FDM Downloads\imikimi_installer.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-11-06 06:08 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2007-11-05 05:40 --------- d-----w C:\Program Files\TrojanHunter 5.0
    2007-11-05 03:30 --------- d-----w C:\Program Files\Yahoo!
    2007-11-05 03:15 264 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
    2007-11-04 20:00 --------- d-----w C:\Program Files\Google
    2007-11-04 13:40 --------- d-----w C:\Program Files\MSN Messenger
    2007-11-04 06:06 --------- d-----w C:\Program Files\Sunbelt Software
    2007-11-03 15:45 --------- d-----w C:\Program Files\Minilyrics
    2007-11-03 04:52 --------- d-----w C:\Program Files\TuxPaint
    2007-11-03 04:25 --------- d-----w C:\Program Files\SpywareBlaster
    2007-10-31 22:08 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2007-10-30 21:52 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
    2007-10-28 05:15 --------- d-----w C:\Program Files\EA GAMES
    2007-10-19 13:24 164 ----a-w C:\install.dat
    2007-10-14 22:13 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Free Download Manager
    2007-10-05 07:10 436,360 ----a-w C:\Documents and Settings\FDM Downloads\msgr8us.exe
    2007-10-03 13:36 4,129 ----a-w C:\WINDOWS\viassary-hp.reg
    2007-10-01 21:40 1,526,072 ----a-w C:\WINDOWS\WRSetup.dll
    2007-10-01 21:24 23,864 ----a-w C:\WINDOWS\system32\drivers\sskbfd.sys
    2007-10-01 21:24 21,816 ----a-w C:\WINDOWS\system32\drivers\sshrmd.sys
    2007-10-01 21:24 163,640 ----a-w C:\WINDOWS\system32\drivers\ssidrv.sys
    2007-10-01 05:27 --------- d-----w C:\Program Files\Kodak
    2007-10-01 05:25 --------- d-----w C:\Program Files\Common Files\Kodak
    2007-10-01 05:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
    2007-09-30 13:38 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Yahoo!
    2007-09-30 08:21 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Apple Computer
    2007-09-30 08:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2007-09-30 08:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
    2007-09-19 01:40 --------- d-----w C:\Program Files\RegCure
    2007-09-18 03:22 --------- d-----w C:\Program Files\SecondLife
    2007-09-18 03:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2007-09-18 02:38 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\TrojanHunter
    2007-09-17 13:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sophos
    2007-09-15 18:28 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\SecondLife
    2007-09-12 01:19 --------- d--h--r C:\Documents and Settings\HP_Owner\Application Data\SecuROM
    2007-08-27 16:26 27,120 ----a-w C:\WINDOWS\system32\SBBD.exe
    2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
    2005-10-29 10:21 4,649,080 ----a-w C:\Program Files\ezcardsbdayfree.exe
    2005-10-25 22:12 1,531,437 ----a-w C:\Program Files\OneTouch.exe
    2005-10-25 21:47 621,200 ----a-w C:\Program Files\install_easyshare.exe
    1998-07-27 22:03 1,359,339 ----a-w C:\Program Files\BluesABCTime.(b)
    2005-10-01 17:34:04 423,048 --sha-w C:\WINDOWS\system32\gfhkj.bak1
    2005-10-08 03:19:57 341,023 --sha-w C:\WINDOWS\system32\gfhkj.bak2
    2007-06-25 19:25:22 2,104,913 --sha-w C:\WINDOWS\system32\xybeg.bak1
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-08-07 13:36]
    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04]
    "KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 21:02]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-08-07 15:03]
    "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 21:43]
    "VTTimer"="VTTimer.exe" [2005-03-08 03:33 C:\WINDOWS\system32\VTTimer.exe]
    "AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 11:01 C:\WINDOWS\AGRSMMSG.exe]
    "PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 17:57]
    "AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
    "Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-09-13 21:36]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-12-27 13:37]
    "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-12-28 18:18]
    "NvCplDaemon"="RUNDLL32.exe" [2004-08-04 13:00 C:\WINDOWS\system32\rundll32.exe]
    "nwiz"="nwiz.exe" [2005-07-20 19:07 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="RUNDLL32.exe" [2004-08-04 13:00 C:\WINDOWS\system32\rundll32.exe]
    "ClientGW"="" []
    "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 07:38]
    "IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 19:09]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 08:14]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
    "SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-08-27 11:09]
    "ThreatFire"="C:\Program Files\ThreatFire\TFTray.exe" [2007-10-12 09:49]
    "b4fe43bd"="rundll32.exe" [2004-08-04 13:00 C:\WINDOWS\system32\rundll32.exe]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 13:45]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebawvs]
    gebawvs.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ondlrnkk]
    ondlrnkk.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"= msv1_0 C:\WINDOWS\system32\mlljh.dll

    R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys
    R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\WINDOWS\system32\Drivers\SSFS0BB9.SYS
    R0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys
    R0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys
    R2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service
    R3 SBAPIFS;SBAPIFS;\??\C:\WINDOWS\system32\drivers\sbapifs.sys
    R3 TfNetMon;TfNetMon;\??\C:\WINDOWS\system32\drivers\TfNetMon.sys

    *Newly Created Service* - SBAPIFS
    .
    Contents of the 'Scheduled Tasks' folder
    "2007-10-24 23:50:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    "2007-02-03 01:01:06 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
    - C:\Program Files\Easy Internet signup\HPSdpApp.exe
    "2007-10-29 05:15:00 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
    "2007-11-03 01:01:30 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - HP_Owner.job"
    - C:\PROGRA~1\NORTON~1\NAVW32.EXE
    "2007-11-06 06:11:44 C:\WINDOWS\Tasks\RegCure Program Check.job"
    - C:\Program Files\RegCure\RegCure.exe
    "2007-10-25 08:20:21 C:\WINDOWS\Tasks\RegCure.job"
    "2007-10-30 14:00:00 C:\WINDOWS\Tasks\rpc.job"
    - C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
    .
    **************************************************************************

    catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-11-06 00:09:03
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...




    Hijack This:

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 00:32, on 2007-11-06
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
    C:\Program Files\ThreatFire\TFTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    C:\PROGRA~1\Webshots\webshots.scr
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\HP_Owner\Desktop\HiJackThis_v2.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>;*.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Pictures - {8E929F51-5914-11D6-971F-0050FC3F9161} - C:\Program Files\Pictures Toolbar\Pictures.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
    O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SBCSTray] "C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe"
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKLM\..\Run: [b4fe43bd] "rundll32.exe" "C:\WINDOWS\system32\yqpqcqsf.dll",b
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O8 - Extra context menu item: &Search - ?p=ZK
    O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
    O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/SP.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128758963578
    O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.38/ttinst.cab
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712...amai.com/6712/player/install3.0/installer.exe
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712....akamai.com/6712/player/install/installer.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca04.rightnowtech.com/7020-b369h/rnl/java/RntX.cab
    O20 - Winlogon Notify: gebawvs - gebawvs.dll (file missing)
    O20 - Winlogon Notify: ondlrnkk - ondlrnkk.dll (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    O24 - Desktop Component 0: (no name) - http://www.cartoonnetwork.com/tools/img/homepage/bkgd_gradient.jpg

    --
    End of file - 13942 bytes
     
  4. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Download the Trial version of Superantispyware Pro (SAS):
    http://www.superantispyware.com/superantispyware.html?rid=3132


    Install it and double-click the icon on your desktop to run it.
    · It will ask if you want to update the program definitions, click Yes.
    · Under Configuration and Preferences, click the Preferences button.
    · Click the Scanning Control tab.
    · Under Scanner Options make sure the following are checked:
    o Close browsers before scanning
    o Scan for tracking cookies
    o Terminate memory threats before quarantining.
    o Please leave the others unchecked.
    o Click the Close button to leave the control center screen.
    · On the main screen, under Scan for Harmful Software click Scan your computer.
    · On the left check C:\Fixed Drive.
    · On the right, under Complete Scan, choose Perform Complete Scan.
    · Click Next to start the scan. Please be patient while it scans your computer.
    · After the scan is complete a summary box will appear. Click OK.
    · Make sure everything in the white box has a check next to it, then click Next.
    · It will quarantine what it found and if it asks if you want to reboot, click Yes.
    · To retrieve the removal information for me please do the following:
    o After reboot, double-click the SUPERAntispyware icon on your desktop.
    o Click Preferences. Click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o It will open in your default text editor (such as Notepad/Wordpad).
    o Please highlight everything in the notepad, then right-click and choose copy.
    · Click close and close again to exit the program.
    · Please paste that information here for me with a new Hijack This log.
     
  5. matabao

    matabao Thread Starter

    Joined:
    Nov 5, 2007
    Messages:
    23
    Ok, here are the new reports. I had to split them because together they exceed the character limit.

    As always, thanks very much!


    SAS:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 11/07/2007 at 00:03 AM

    Application Version : 3.9.1008

    Core Rules Database Version : 3339
    Trace Rules Database Version: 1340

    Scan type : Complete Scan
    Total Scan Time : 03:26:22

    Memory items scanned : 572
    Memory threats detected : 0
    Registry items scanned : 6982
    Registry threats detected : 8
    File items scanned : 203883
    File threats detected : 258

    Adware.Vundo Variant
    HKLM\Software\Classes\CLSID\{5F6B34D7-1C02-409D-9AC0-CFD7448057E1}
    HKCR\CLSID\{5F6B34D7-1C02-409D-9AC0-CFD7448057E1}
    HKCR\CLSID\{5F6B34D7-1C02-409D-9AC0-CFD7448057E1}\InprocServer32
    HKCR\CLSID\{5F6B34D7-1C02-409D-9AC0-CFD7448057E1}\InprocServer32#ThreadingModel
    C:\WINDOWS\SYSTEM32\MLLJH.DLL

    Trojan.WinFixer
    HKLM\Software\Classes\CLSID\{DB3BEBB6-CB44-4CA2-99B6-8FD294940749}
    HKCR\CLSID\{DB3BEBB6-CB44-4CA2-99B6-8FD294940749}
    HKCR\CLSID\{DB3BEBB6-CB44-4CA2-99B6-8FD294940749}\InprocServer32
    HKCR\CLSID\{DB3BEBB6-CB44-4CA2-99B6-8FD294940749}\InprocServer32#ThreadingModel
    C:\WINDOWS\SYSTEM32\VTSTR.DLL

    Adware.Tracking Cookie
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][9].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][6].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][6].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][8].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][6].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][6].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][7].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][7].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][6].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][7].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][8].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][6].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][6].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][7].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][8].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][6].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][10].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][11].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][6].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][7].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][8].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][9].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][3].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][4].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][5].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][7].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][8].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\HP_Owner\Cookies\[email protected][2].txt

    Adware.eZula
    C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\ECJUNSSP.EXE.VIR
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP581\A0395184.EXE

    Trojan.Unknown Origin
    C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WNSTSICOMSV32.EXE.VIR
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP568\A0384721.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP569\A0385843.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP581\A0395183.EXE

    Adware.WINSHOW
    C:\QOOBOX\QUARANTINE\C\WINDOWS\WINSHOW.EXE.VIR
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP581\A0395205.EXE

    Trojan.Downloader-Gen/TStamp
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP525\A0330266.EXE

    Adware.Vundo-Variant
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP565\A0380534.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP567\A0384626.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP567\A0384628.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP577\A0391083.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP580\A0393171.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP580\A0393173.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP580\A0393174.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP580\A0393181.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP580\A0393183.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP580\A0393186.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP581\A0395188.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP581\A0395194.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP581\A0395199.DLL
    C:\WINDOWS\SYSTEM32\BPNCOKOA.DLL
    C:\WINDOWS\SYSTEM32\GCKYWEDL.DLL
    C:\WINDOWS\SYSTEM32\ORYQXNOA.DLL
    C:\WINDOWS\SYSTEM32\QNLHPSIO.DLL
    C:\WINDOWS\SYSTEM32\YSCDAQPP.DLL
    C:\WINDOWS\SYSTEM32\YUKJBXFB.DLL

    Adware.ClickSpring
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP568\A0384720.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP569\A0385841.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP569\A0385842.DLL

    Trojan.Download-Gen/Untraceable
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP569\A0385801.DLL

    Adware.Vundo Variant/Rel
    C:\WINDOWS\SYSTEM32\GFHKJ.BAK1
    C:\WINDOWS\SYSTEM32\GFHKJ.INI
    C:\WINDOWS\SYSTEM32\XYBEG.BAK1
    C:\WINDOWS\SYSTEM32\XYBEG.INI

    Trojan.Downloader-Gen/Hammer
    C:\WINDOWS\SYSTEM32\YNUUQMUO.DLL
     
  6. matabao

    matabao Thread Starter

    Joined:
    Nov 5, 2007
    Messages:
    23
    HJT:

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 00:21, on 2007-11-07
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
    C:\Program Files\ThreatFire\TFTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    C:\PROGRA~1\Webshots\webshots.scr
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\HP_Owner\Desktop\HiJackThis_v2.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>;*.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Pictures - {8E929F51-5914-11D6-971F-0050FC3F9161} - C:\Program Files\Pictures Toolbar\Pictures.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
    O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SBCSTray] "C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe"
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O8 - Extra context menu item: &Search - ?p=ZK
    O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
    O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/SP.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128758963578
    O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.38/ttinst.cab
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712...amai.com/6712/player/install3.0/installer.exe
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712....akamai.com/6712/player/install/installer.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca04.rightnowtech.com/7020-b369h/rnl/java/RntX.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: gebawvs - gebawvs.dll (file missing)
    O20 - Winlogon Notify: ondlrnkk - ondlrnkk.dll (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    O24 - Desktop Component 0: (no name) - http://www.cartoonnetwork.com/tools/img/homepage/bkgd_gradient.jpg

    --
    End of file - 14095 bytes
     
  7. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Now rerun Combofix and post the results please.
     
  8. matabao

    matabao Thread Starter

    Joined:
    Nov 5, 2007
    Messages:
    23
    I shut down the spyware programs I had running, including SAS, then double-clicked the ComboFix icon and I got this message:

    Some files could not be created.
    Please close all applications, reboot Windows and restart this installation.

    I didn't have any applications open (so far as I know), but I tried rebooting (more than once) and got the same message.

    I tried deleting ComboFix and re-downloading it. Still got the same message.

    Then I ran out of ideas.

    (By the way, after I clicked OK to the error message, a pop-up appears showing a pane with a lot of filenames above a progress bar that is all green, but the only options are Close and Cancel. Whichever one I click on leaves me with the ComboFix window and the title bar says "ComboFix - pause")

    Any suggestions?

    -Brian
     
  9. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Will it work in Safe Mode?
     
  10. matabao

    matabao Thread Starter

    Joined:
    Nov 5, 2007
    Messages:
    23
    Running it in Safe Mode worked.

    Here's the new log.

    ComboFix 07-11-08.1 - HP_Owner 2007-11-08 23:35:41.2 - NTFSx86 MINIMAL
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.750 [GMT -6:00]
    Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ---- Previous Run -------
    .
    C:\Documents and Settings\All Users\Application Data.\salesmonitor
    C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
    C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
    C:\Documents and Settings\HP_Owner\Desktop\Live Safety Center.lnk
    C:\Documents and Settings\HP_Owner\err.log
    C:\Documents and Settings\HP_Owner\My Documents\SSTEM3~1
    C:\Program Files\Common Files\icroso~1
    C:\Program Files\poolsv
    C:\Program Files\svhost
    C:\temp\0b9
    C:\temp\0b9\tmpTF.log
    C:\Temp\1cb
    C:\Temp\1cb\syscheck.log
    C:\temp\iee
    C:\temp\iee\tmpZTF.log
    C:\temp\tn3
    C:\WINDOWS\cookies.ini
    C:\WINDOWS\cs_cache.ini
    C:\WINDOWS\system32\A1
    C:\WINDOWS\system32\a13
    C:\WINDOWS\system32\A3
    C:\WINDOWS\system32\a4
    C:\WINDOWS\system32\A5
    C:\WINDOWS\system32\awtqn.dll
    C:\WINDOWS\system32\awtqp.dll
    C:\WINDOWS\system32\awtsr.dll
    C:\WINDOWS\system32\awvtr.dll
    C:\WINDOWS\system32\e2
    C:\WINDOWS\system32\ecjunssp.exe
    C:\WINDOWS\system32\g1
    C:\WINDOWS\system32\gebca.dll
    C:\WINDOWS\system32\geedc.dll
    C:\WINDOWS\system32\hjllm.ini
    C:\WINDOWS\system32\i8
    C:\WINDOWS\system32\ilnmp.bak1
    C:\WINDOWS\system32\ilnmp.ini
    C:\WINDOWS\system32\ilnmp.tmp
    C:\WINDOWS\system32\jkhfd.dll
    C:\WINDOWS\system32\ljjjihi.dll
    C:\WINDOWS\system32\mljgg.dll
    C:\WINDOWS\system32\mljgh.dll
    C:\WINDOWS\system32\mlljh.dll
    C:\WINDOWS\system32\o09PrEz
    C:\WINDOWS\system32\ondlrnkk.dllbox
    C:\WINDOWS\system32\pac.txt
    C:\WINDOWS\system32\pmkhh.dll
    C:\WINDOWS\system32\pmnnl.dll
    C:\WINDOWS\system32\rtstv.bak1
    C:\WINDOWS\system32\rtstv.ini
    C:\WINDOWS\system32\rtstv.ini2
    C:\WINDOWS\system32\rtstv.tmp
    C:\WINDOWS\system32\ssqpp.dll
    C:\WINDOWS\system32\ssqro.dll
    C:\WINDOWS\system32\ssttr.dll
    C:\WINDOWS\system32\vtuts.dll
    C:\WINDOWS\system32\vtutu.dll
    C:\WINDOWS\system32\win
    C:\WINDOWS\system32\wnstsicomsv32.exe
    C:\WINDOWS\system32\x22
    C:\WINDOWS\winshow.exe
    D:\Autorun.inf

    .
    ((((((((((((((((((((((((( Files Created from 2007-10-09 to 2007-11-09 )))))))))))))))))))))))))))))))
    .

    2007-11-06 20:33 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\SUPERAntiSpyware.com
    2007-11-05 23:39 <DIR> d-------- C:\ComboFix1
    2007-11-05 23:39 51,200 --a------ C:\WINDOWS\NirCmd.exe
    2007-11-04 23:46 <DIR> d-------- C:\Program Files\ThreatFire
    2007-11-04 23:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
    2007-11-04 23:46 52,032 --a------ C:\WINDOWS\system32\drivers\TfFsMon.sys
    2007-11-04 23:46 38,720 --a------ C:\WINDOWS\system32\drivers\TfSysMon.sys
    2007-11-04 23:46 34,624 --a------ C:\WINDOWS\system32\drivers\TfNetMon.sys
    2007-11-04 23:46 12,608 --a------ C:\WINDOWS\system32\drivers\TfKbMon.sys
    2007-11-04 21:31 <DIR> d-------- C:\Program Files\Common Files\Scanner
    2007-11-04 01:03 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys
    2007-11-04 00:10 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\Sunbelt Software
    2007-11-02 22:08 <DIR> d-------- C:\Program Files\Enigma Software Group
    2007-11-01 07:22 413,009 --ahs---- C:\WINDOWS\system32\ijllm.bak2
    2007-10-30 07:43 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\MySpace
    2007-10-30 07:07 <DIR> d-------- C:\WINDOWS\system32\Mz08r
    2007-10-30 07:07 <DIR> d-------- C:\temp\mZOr
    2007-10-19 07:25 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
    2007-10-14 15:59 <DIR> d-------- C:\Program Files\Imikimi
    2007-10-14 15:55 1,068,216 --a------ C:\Documents and Settings\FDM Downloads\imikimi_installer.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-11-08 20:38 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2007-11-08 06:33 --------- d-----w C:\Program Files\Minilyrics
    2007-11-08 02:11 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2007-11-07 06:15 --------- d-----w C:\Program Files\SUPERAntiSpyware
    2007-11-07 02:31 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2007-11-05 05:40 --------- d-----w C:\Program Files\TrojanHunter 5.0
    2007-11-05 03:30 --------- d-----w C:\Program Files\Yahoo!
    2007-11-05 03:15 264 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
    2007-11-04 20:00 --------- d-----w C:\Program Files\Google
    2007-11-04 13:40 --------- d-----w C:\Program Files\MSN Messenger
    2007-11-04 06:06 --------- d-----w C:\Program Files\Sunbelt Software
    2007-11-03 04:52 --------- d-----w C:\Program Files\TuxPaint
    2007-11-03 04:25 --------- d-----w C:\Program Files\SpywareBlaster
    2007-10-30 21:52 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
    2007-10-28 05:15 --------- d-----w C:\Program Files\EA GAMES
    2007-10-19 13:24 164 ----a-w C:\install.dat
    2007-10-14 22:13 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Free Download Manager
    2007-10-05 07:10 436,360 ----a-w C:\Documents and Settings\FDM Downloads\msgr8us.exe
    2007-10-03 13:36 4,129 ----a-w C:\WINDOWS\viassary-hp.reg
    2007-10-01 21:40 1,526,072 ----a-w C:\WINDOWS\WRSetup.dll
    2007-10-01 21:24 23,864 ----a-w C:\WINDOWS\system32\drivers\sskbfd.sys
    2007-10-01 21:24 21,816 ----a-w C:\WINDOWS\system32\drivers\sshrmd.sys
    2007-10-01 21:24 163,640 ----a-w C:\WINDOWS\system32\drivers\ssidrv.sys
    2007-10-01 05:27 --------- d-----w C:\Program Files\Kodak
    2007-10-01 05:25 --------- d-----w C:\Program Files\Common Files\Kodak
    2007-10-01 05:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
    2007-09-30 13:38 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Yahoo!
    2007-09-30 08:21 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Apple Computer
    2007-09-30 08:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2007-09-30 08:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
    2007-09-19 01:40 --------- d-----w C:\Program Files\RegCure
    2007-09-18 03:22 --------- d-----w C:\Program Files\SecondLife
    2007-09-18 03:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2007-09-18 02:38 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\TrojanHunter
    2007-09-17 13:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sophos
    2007-09-15 18:28 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\SecondLife
    2007-09-12 01:19 --------- d--h--r C:\Documents and Settings\HP_Owner\Application Data\SecuROM
    2007-08-27 16:26 27,120 ----a-w C:\WINDOWS\system32\SBBD.exe
    2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
    2005-10-29 10:21 4,649,080 ----a-w C:\Program Files\ezcardsbdayfree.exe
    2005-10-25 22:12 1,531,437 ----a-w C:\Program Files\OneTouch.exe
    2005-10-25 21:47 621,200 ----a-w C:\Program Files\install_easyshare.exe
    1998-07-27 22:03 1,359,339 ----a-w C:\Program Files\BluesABCTime.(b)
    2005-10-08 03:19:57 341,023 --sha-w C:\WINDOWS\system32\gfhkj.bak2
    .

    ((((((((((((((((((((((((((((( [email protected]_ 0.12.44.70 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2007-11-07 02:33:31 34,304 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF1.exe
    + 2007-11-07 02:33:31 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
    - 2007-04-02 20:21:27 139,776 ----a-w C:\WINDOWS\system32\swreg.exe
    + 2007-07-23 00:39:27 279,552 ----a-w C:\WINDOWS\system32\swreg.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5F6B34D7-1C02-409D-9AC0-CFD7448057E1}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-08-07 13:36]
    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04]
    "KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 21:02]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-08-07 15:03]
    "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 21:43]
    "VTTimer"="VTTimer.exe" [2005-03-08 03:33 C:\WINDOWS\system32\VTTimer.exe]
    "AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 11:01 C:\WINDOWS\AGRSMMSG.exe]
    "PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 17:57]
    "AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
    "Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-09-13 21:36]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-12-27 13:37]
    "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-12-28 18:18]
    "NvCplDaemon"="RUNDLL32.exe" [2004-08-04 13:00 C:\WINDOWS\system32\rundll32.exe]
    "nwiz"="nwiz.exe" [2005-07-20 19:07 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="RUNDLL32.exe" [2004-08-04 13:00 C:\WINDOWS\system32\rundll32.exe]
    "ClientGW"="" []
    "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 07:38]
    "IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 19:09]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 08:14]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
    "SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-08-27 11:09]
    "ThreatFire"="C:\Program Files\ThreatFire\TFTray.exe" [2007-10-12 09:49]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 13:45]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

    C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
    Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2005-08-13 12:55:53]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 06:31:38]
    Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 03:33:46]
    Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2004-08-07 15:33:32]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebawvs]
    gebawvs.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ondlrnkk]
    ondlrnkk.dll

    R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys
    R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\WINDOWS\system32\Drivers\SSFS0BB9.SYS
    R0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys
    R0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys
    S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service
    S3 SBAPIFS;SBAPIFS;\??\C:\WINDOWS\system32\drivers\sbapifs.sys
    S3 TfNetMon;TfNetMon;\??\C:\WINDOWS\system32\drivers\TfNetMon.sys

    *Newly Created Service* - CATCHME
    .
    Contents of the 'Scheduled Tasks' folder
    "2007-11-08 00:50:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2007-02-03 01:01:06 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
    - C:\Program Files\Easy Internet signup\HPSdpApp.exe
    "2007-10-29 05:15:00 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
    "2007-11-03 01:01:30 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - HP_Owner.job"
    - C:\PROGRA~1\NORTON~1\NAVW32.EXE
    "2007-11-08 19:21:57 C:\WINDOWS\Tasks\RegCure Program Check.job"
    - C:\Program Files\RegCure\RegCure.exe
    "2007-10-25 08:20:21 C:\WINDOWS\Tasks\RegCure.job"
    "2007-10-30 14:00:00 C:\WINDOWS\Tasks\rpc.job"
    - C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
    .
    **************************************************************************

    catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-11-08 23:39:11
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    **************************************************************************
    .
    Completion time: 2007-11-08 23:40:44
    .
    --- E O F ---


    And just in case you need it, here's a new HJT log:

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 12:04:44 AM, on 11/9/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
    C:\Program Files\ThreatFire\TFTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    C:\PROGRA~1\Webshots\webshots.scr
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\HP_Owner\Desktop\HiJackThis_v2.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>;*.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Pictures - {8E929F51-5914-11D6-971F-0050FC3F9161} - C:\Program Files\Pictures Toolbar\Pictures.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
    O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SBCSTray] "C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe"
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O8 - Extra context menu item: &Search - ?p=ZK
    O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
    O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/SP.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128758963578
    O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.38/ttinst.cab
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712...amai.com/6712/player/install3.0/installer.exe
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712....akamai.com/6712/player/install/installer.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca04.rightnowtech.com/7020-b369h/rnl/java/RntX.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: gebawvs - gebawvs.dll (file missing)
    O20 - Winlogon Notify: ondlrnkk - ondlrnkk.dll (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    O24 - Desktop Component 0: (no name) - http://www.cartoonnetwork.com/tools/img/homepage/bkgd_gradient.jpg

    --
    End of file - 13984 bytes
     
  11. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    1. Please download The Avenger by Swandog46 to your Desktop.
    • Click on Avenger.zip to open the file
    • Extract avenger.exe to your desktop

    2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):


    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


    3. Now, start The Avenger program by clicking on its icon on your desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    4. The Avenger will automatically do the following:
    • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
    5. Please copy/paste the content of c:\avenger.txt into your reply.

    Rescan with Hijack This, close all browser windows except Hijack This, put a checkmark beside these entries and click fix checked.

    O20 - Winlogon Notify: gebawvs - gebawvs.dll (file missing)
    O20 - Winlogon Notify: ondlrnkk - ondlrnkk.dll (file missing)


    Reboot and post another Hijack This log please.
     
  12. matabao

    matabao Thread Starter

    Joined:
    Nov 5, 2007
    Messages:
    23
    I got an error message after reboot that I eventually had to Cancel, but after that the Avenger report generated.

    Avenger

    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Services\hejfrtst

    *******************

    Script file located at: \??\C:\WINDOWS\nyxsygum.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    File C:\WINDOWS\system32\ijllm.bak2 deleted successfully.
    File C:\WINDOWS\system32\gfhkj.bak2 deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.


    HJT

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 10:06:51 PM, on 11/9/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\ThreatFire\TFTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\PROGRA~1\Webshots\webshots.scr
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\alg.exe
    C:\Documents and Settings\HP_Owner\Desktop\HiJackThis_v2.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>;*.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Pictures - {8E929F51-5914-11D6-971F-0050FC3F9161} - C:\Program Files\Pictures Toolbar\Pictures.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
    O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SBCSTray] "C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe"
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O8 - Extra context menu item: &Search - ?p=ZK
    O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
    O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/SP.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128758963578
    O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.38/ttinst.cab
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712...amai.com/6712/player/install3.0/installer.exe
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712....akamai.com/6712/player/install/installer.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca04.rightnowtech.com/7020-b369h/rnl/java/RntX.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    O24 - Desktop Component 0: (no name) - http://www.cartoonnetwork.com/tools/img/homepage/bkgd_gradient.jpg

    --
    End of file - 13628 bytes
     
  13. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    How are things now
     
  14. matabao

    matabao Thread Starter

    Joined:
    Nov 5, 2007
    Messages:
    23
    I'm still here; I've just been trying to determine what, exactly, is left. It's definitely better now, but there are still at least a couple of problems.

    SpySweeper continues to find after every restart Troj/Virtum-Gen. Just can't get rid of it.

    And the really weird thing: Ad-Aware finds a million things and can't remove or quarantine any of them. When I select them and click either Remove or Quarantine, it simply unchecks them again. So, of course, nothing happens. The Ad-Aware log is way over the character limit, but I've pasted part of it below, for what it's worth. I should point out, though, that AA is finding this stuff in the registry and none of my other spyware programs seems to detect it.



    Ad-Aware 2007 Build
    Log File Created on: 2007-11-12 08:27:48
    Using Definitions File: C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\core.aawdef
    Computer name: MATABAO
    Name of user performing scan: SYSTEM

    System information
    ===========================
    Number of processors: 1
    Processor type: AMD Athlon(tm) XP 3100+
    Memory Available: 34%
    Total Physical Memory: 1073201152 Bytes
    Available Physical Memory: 362356736 Bytes
    Total Page File Size: 1675046912 Bytes
    Available On Page File: 1130278912 Bytes
    Total Virtual Memory: 2147352576 Bytes
    Available Virtual Memory: 1934491648 Bytes
    OS: Microsoft Windows XP Service Pack 2 (Build 2600)

    Ad-Aware 2007 Settings
    ===========================
    Skipping files larger than 1048576 kB
    Ignoring infections with lower TAI than: 3


    Extended Ad-Aware 2007 Settings
    ===========================
    Unloading known modules during scan
    Ignoring spanned files when scanning cab archives
    Scanning registry for all users
    Using permanent archive caching
    Reanalyzing results after scanning before displaying results
    Trying to unload modules prior to removal
    Let Windows remove files currently in use at next reboot
    Removing quarantined objects after restore
    Logging Ad-Aware events
    Blocking Pop-Ups aggressively
    Deactivating Ad-Watch during scans
    Writeprotecting system files after repairs
    Including Ad-aware command line parameters in log file
    Include info about ignored objects in log file
    Including basic settings in log file
    Including advanced settings in log file
    Including user and computer name in log file
    Include reference summary in log file
    Creating log file for removal operations
    Including module info in log file
    Include Alternate Data Stream details in log file
    Create and save WebUpdate log file

    Databaseinfo
    ===========================
    Version number: 33
    Build Number: 0
    Build Date and Time: 2007/11/12 01:22:48

    Scan Statistics
    ===========================
    Method: Smart
    Scan tracking cookies.............................: On
    Scan ADS filestreams..............................: Off

    Item Scanned: 10043861
    Infections Detected: 1466
    Infections Ignored: 0

    Scan detailed statistics
    ===========================
    Type Critical Total
    Process Scan....: 0 0
    Registry Scan...: 1458 1458
    Registry PE Scan: 0 0
    Hosts File Scan.: 0 0
    File Scan.......: 1 1
    Folder Scan.....: 0 0
    LSP Scan........: 0 0
    ADS Scan........: 0 0
    Cookie Scan.....: 6 6
    File Hash Scan..: 0 0

    Infections Found
    ===========================
    Family Id: 5 Name: 2020Search Category: DataMiner TAI:4
    Item Id: 300000110 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{17da0c9e-4a27-4ac5-bb75-5d24b8cdb972}
    Item Id: 300000111 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{4e7bd74f-2b8d-469e-92c6-ce7eb590a94d}
    Family Id: 6 Name: 404search Category: Malware TAI:5
    Item Id: 300000160 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{4e7bd74f-2b8d-469e-d7f9-fe60b89cac3f}
    Item Id: 300000161 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{53c330d6-a4ab-419b-b45d-fd4411c1fef4}
    Family Id: 8 Name: 7FaSSt Category: DataMiner TAI:7
    Item Id: 300000181 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}
    Family Id: 9 Name: 7search-BrowserAccelerator Category: DataMiner TAI:7
    Item Id: 300000200 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{074e3aa7-7718-4404-b3f8-ff8fb5414e0e}
    Family Id: 19 Name: ActualNames Category: DataMiner TAI:7
    Item Id: 300000282 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{92c7d65c-52f3-4545-8a35-213d730db1ed}
    Family Id: 20 Name: Ad-Popper Category: Malware TAI:6
    Item Id: 300000331 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{34d516ea-40e3-4e3b-8ba8-505112738ed5}
    Item Id: 300000333 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{4b021269-dd24-48b2-96b4-da121e9c0502}
    Item Id: 300000336 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{aefcdec8-eb7d-429f-bc73-4f30d07bfe41}
    Item Id: 300000338 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{db0018a2-f7d9-4b71-9651-640143df23f9}
    Item Id: 300000335 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{858126b0-3708-4051-ae8e-b48521401ca2}
    Family Id: 23 Name: AdBlaster Category: Malware TAI:7
    Item Id: 300000397 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{d6862a22-1dd6-11d3-bb7c-444553540000}
    Item Id: 300000398 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{bc0d2038-2de5-4a6f-92bc-b18a3e0de32a}
    Item Id: 300000399 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{6b12dabb-0b7c-44fa-b0b3-4baff3790256}
    Item Id: 300000400 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{4cebbc6b-5cee-4644-80cf-38980bae93f6}
    Item Id: 300000401 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{39af31dd-eafc-45ea-a56c-385b52e25cc0}
    Item Id: 300000403 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{941ca48c-3984-4e7d-aaf8-8755ed76eb50}
    Family Id: 24 Name: AdBreak Category: DataMiner TAI:7
    Item Id: 300000418 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{00000012-890e-4aac-afd9-eff6954a34dd}
    Family Id: 26 Name: AdGoblin Category: DataMiner TAI:6
    Item Id: 300000432 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{16c62381-ed34-40dc-91bb-9ec507670cd6}
    Item Id: 300000433 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{b2e8cb3f-c4e6-4407-95bf-537162282a47}
    Item Id: 300000434 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{d212259d-4648-4903-9fbd-02e88785d33c}
    Family Id: 27 Name: Adintelligence.AproposToolbar Category: Misc TAI:10
    Item Id: 300000452 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{65c8c1f5-230e-4dc9-9a0d-f3159a5e7778}
    Item Id: 300000453 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{645fd3bc-c314-4f7a-9d2e-64d62a0fdd78}
    Item Id: 300000454 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{2737a6c0-7e24-11d7-b299-00e0297e0844}
    Item Id: 300000455 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{016235be-59d4-4ceb-add5-e2378282a1d9}
    Family Id: 28 Name: Adlogix Category: Adware TAI:3
    Item Id: 300000478 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{024de5eb-3649-445e-8d57-c09a9a33d479}
    Family Id: 30 Name: AdPlus-SurferBar Category: Malware TAI:6
    Item Id: 300000487 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{ff7fd490-34e7-4fa1-927a-f5799e6aad7b}
    Family Id: 33 Name: AdRoar Category: Malware TAI:6
    Item Id: 300000532 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{e0f0e0e1-5d45-11d4-bc00-2dcc73302d70}
    Item Id: 300000533 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{fac6e0e1-5d45-4907-bc00-302d702dcc73}
    Item Id: 300000531 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{bdf6ce3d-f5c5-4462-9814-3c8eac330ca8}
    Family Id: 34 Name: AdRotator Category: Malware TAI:6
    Item Id: 300000580 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{017c20c1-f86f-11d8-9b25-000acd002ae3}
    Item Id: 300000581 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{1aeb13ee-d881-4ad3-9f0f-bf2ad7a2c111}
    Item Id: 300000582 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{226d4d69-b650-426e-a738-a5ba89abcc87}
    Item Id: 300000583 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{5074851c-f67a-488e-a9c9-c244573f4068}
    Item Id: 300000584 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{b7a8923f-b04e-4175-a2f1-df625ec0058b}
    Item Id: 300000590 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{d117a61f-92c3-4450-a0c8-f425b14d4127}
    Item Id: 300028848 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{6b8c17ee-d954-416f-8267-d2469f446386}
    Item Id: 300028943 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{a32e9a25-25b1-4b68-bdbf-5e4da10fbdc5}
    Family Id: 36 Name: Adsincontext Category: Malware TAI:6
    Item Id: 300000612 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{53bb15d5-d644-4142-86d8-8d5e1b70635e}
    Family Id: 38 Name: Adtomi Category: Malware TAI:5
    Item Id: 300000624 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{b549456d-f5d0-4641-bced-8648a0c13d83}
    Item Id: 300000626 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{a78860c8-ee1a-46df-a97f-e3e6d433e80b}
    Family Id: 39 Name: Adult Material Category: DataMiner TAI:6
    Item Id: 300000630 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{ce7c3cf0-4b15-11d1-abed-709549c10001}
    Family Id: 40 Name: Adultlinks Quickbar Category: Malware TAI:6
    Item Id: 300000671 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{765e6b09-6832-4738-bdbe-25f226ba2ab0}
    Family Id: 44 Name: Adware.180Solutions.SeekmoSearchAssistant Category: Adware TAI:4
    Item Id: 300000702 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{5929cd6e-2062-44a4-b2c5-2c7e78fbab38}
    Family Id: 45 Name: Adware.2Search Category: DataMiner TAI:3
    Item Id: 300000731 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{9125f250-eb4f-49fe-ae17-c17665873a5c}
    Family Id: 46 Name: Adware.Adhelper Category: Malware TAI:4
    Item Id: 300000758 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{d1bb7cf4-4463-4e91-88d7-ecc3ce0a13b7}
    Item Id: 300000764 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{1a199c20-de2b-4838-ae3f-b5257ece2b7e}
    Family Id: 47 Name: Adware.AdMedia Category: Adware TAI:10
    Item Id: 300000846 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{1d49d58d-5c84-4b50-8359-d9809beb2b32}
    Item Id: 300000847 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{63c55a7f-6e29-8d4f-5c76-4f850f28d13a}
    Item Id: 300000848 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{d424fe4e-caf9-4fdd-bc5f-e6e6b91d53bf}
    Item Id: 300036954 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{8ca5ed52-f3fb-4414-a105-2e3491156990}
    Item Id: 300000827 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{b8ccdd47-38e4-4cd2-b7fa-3b4b690f74bd}
    Family Id: 48 Name: Adware.Admess Category: DataMiner TAI:5
    Item Id: 300000862 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{9896231a-c487-43a5-8369-6ec9b0a96cc0}
    Family Id: 53 Name: Adware.Agent Category: Adware TAI:5
    Item Id: 300001013 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{907c7249-caaf-4873-b299-0fbfbcd562e5}
    Item Id: 300001020 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{98a3aa0c-5fc5-4730-a2bc-80661647cdeb}
    Item Id: 300001021 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{a646ce7e-951e-44d1-b93c-f7136da41e58}
    Item Id: 300001023 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{dfcb34b6-902d-426e-ae2b-1b294ae19f4f}
    Item Id: 300001025 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{32365484-96a1-6974-3269-123555124652}
    Item Id: 300001026 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{6bd97c5b-7a34-4ae9-8b0d-4e03f37a8dbf}
    Item Id: 300001031 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{a5845a98-ebda-4670-9de6-5201c506e741}
    Item Id: 300001038 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{a4f94c0c-54a7-4db1-9af3-b22e63d00305}
    Item Id: 300001039 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{f5bdc469-1ec5-4193-824b-2e209993d183}
    Item Id: 300001040 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{8610e1b4-57c3-441b-9821-c81c51c3ac09}
    Item Id: 300001042 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{208e7e77-507a-4649-b0c9-d39e9049c7a2}
    Item Id: 300001043 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{9fa1aa9e-7ecf-4f3b-ac23-7f09e01298e4}
    Item Id: 300001044 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{366b2151-e1c7-44a3-86a3-e5686c2a3d2f}
    Item Id: 300001066 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{5574e139-f59c-4bee-9a61-150b0d3a16c7}
    Item Id: 300001067 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{27a7fb75-fb40-4f94-bcf6-4945bcc8baaf}
    Item Id: 300001073 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{a75e294e-c047-4d29-b07e-37b792881bef}
    Item Id: 300001074 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{46a4e9d9-b30e-452a-8157-dbbec8573b03}
    Item Id: 300001080 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{16789285-c094-4aa6-88b9-2bb9dc13a485}
    Item Id: 300001091 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{d76f06d4-1659-482d-bcb2-3f731bfe0941}
    Item Id: 300026140 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{cb5b2bc6-f957-4d8a-be67-83f3ec58ba01}
    Item Id: 300026739 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{bc305684-8946-4d65-ab1d-10ae276d87ed}
    Item Id: 300026854 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{2724e072-19d0-486d-a819-9d914191ae92}
    Item Id: 300027022 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{16789285-c094-4aa6-88b9-2bb9dc13a485}
    Item Id: 300027709 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{1d72794f-d23c-4c23-a60c-d9123f897bcf}
    Item Id: 300027722 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{266a3562-ab67-480e-9f09-d54604fd817b}
    Item Id: 300028504 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{a75e294e-c047-4d29-b07e-37b792881bef}
    Item Id: 300028751 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{12365484-96a1-6974-3269-123555124655}
    Item Id: 300028752 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{bcf4d74b-e6bd-4c8f-83d7-90d6439705b9}
    Item Id: 300028991 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{8faa7a38-1d1e-48e3-b77f-6a98a9ba49cd}
    Item Id: 300029377 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{6cdd9d1f-7501-4b0f-90cd-5ada4f15e6e8}
    Item Id: 300029603 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{2c014816-5bd4-4166-85ea-62fe05e517c3}
    Item Id: 300029765 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{4118a625-1b64-4ed1-a2e9-76dec529d2d2}
    Item Id: 300029934 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{49cf52d7-8d58-4e22-a874-aad721f5b523}
    Item Id: 300030282 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{b5f1ca79-f895-43bb-b0c0-14051f2df46e}
    Item Id: 300030381 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{47c54f02-1b28-45f1-ae46-b5cdfb6e7926}
    Item Id: 300030745 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{af12cf13-dc3b-461c-b5ce-894806c15303}
    Item Id: 300031345 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{b72549ce-5644-4116-b8a4-a2b042321ec4}
    Item Id: 300031367 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{7af59c20-a1d8-4c1c-927a-99dd9f2a9e0b}
    Item Id: 300032730 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{7edf19b9-07e7-4f15-25b1-84b0e1662908}
    Item Id: 300033278 Value: Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{695a94fd-15d0-4ed7-8f40-d2b3bdc42c15}
    Item Id: 300033846 Value: Root: HKLM Path: <b>DELETED PORTION</B>

    End of Scan Section
    ===========================

    Cleaned Infections
    ===========================
    Root: HKU Path: S-1-5-21-169385266-3431857197-3496118193-1009\software\microsoft\internet explorer\desktop\components Value: GeneralFlags Data: 0, Belonging to Adware.WorldSearch
    Root: HKU Path: S-1-5-21-169385266-3431857197-3496118193-1009\software\microsoft\internet explorer\desktop\components Value: GeneralFlags Data: 0, Belonging to Dialerplatform
    Root: HKLM Path: software\antispyware, Belonging to PerfectCleaner
    Root: HKU Path: S-1-5-21-169385266-3431857197-3496118193-1009\control panel\desktop Value: WallpaperStyle Data: 2, Belonging to SpywareNo
    Root: HKU Path: S-1-5-21-169385266-3431857197-3496118193-1009\software\microsoft\internet explorer\desktop\components Value: GeneralFlags Data: 0, Belonging to SpywareNo
    Root: HKLM Path: system\currentcontrolset\services\symtdi, Belonging to Win32.TrojanDownloader.Agent
    File: c:\System Volume Information\tracking.log, Belonging to Win32.Trojandownloader.Zlob
    Root: HKLM Path: system\currentcontrolset\enum\root\legacy_ip6fw, Belonging to Win32.TrojanSpy.BZub

    End of Cleaned Infections
    ===========================
     
  15. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Download WinPFind3U.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
    • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
      • In the Processes group click ALL
      • In the Win32 Services group click ALL
      • In the Driver Services group click ALL
      • In the Registry group click ALL
      • In the Files Created Within group click 60 days Make sure Non-Microsoft only is UNCHECKED
      • In the Files Modified Within group select 30 days Make sure Non-Microsoft only is UNCHECKED
      • In the File String Search group select ALL
      in the Additional scans sections please press select ALL
    • Now click the Run Scan button on the toolbar.
    • The program will be scanning huge amounts of data so depending on your system it could take a long time to complete. Let it run unhindered until it finishes.
    • When the scan is complete Notepad will open with the report file loaded in it.
    • Save that notepad file but click on the "Format" menu and make sure that "word wrap" is not checked. If it is then click on it to uncheck it.
    Upload the report as an attachment please.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Similar Threads - Overrun Viruses Malware
  1. stef1808
    Replies:
    14
    Views:
    1,044
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/648035

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice