Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Outerinfo Popups - Neverending Spyware


  • This topic is locked This topic is locked
10 replies to this topic

#1 durianlover

durianlover

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:03:16 AM

Posted 10 December 2007 - 02:22 AM

I've used Spybot S&D and Ad Aware. Both of them clean things up, and I used AVG free virus protection. I installed my windows updates, did McAfee stinger, and CCleaner and put in Sygate firewall. And, Things keep coming back. I even used VundoFix which seemed to get rid of some stuff, but then there was still more.

Popups appear that say "Advertisement for Outerinfo" - usually three of them pop up together with IE. I use firefox.
Then, more stuff is always found by Spybot.

Sometimes I've also been getting a popup that says "Server Busy" and it has two boxes "Switch to..." and "Retry" - but it looks like it's probably a spyware popup, not a real thing.

I've tried a lot, so now I come to you for help. Thanks for taking the time to look at this :thumbsup:

- Daniel

HighjackThis log....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:17:21 PM, on 12/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe
C:\Program Files\s?curity\w?wexec.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\lpcywinp.exe,C:\WINDOWS\system32\userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CutePDF Form Filler - {D41289F2-69C6-417B-897E-C653D677CBAF} - C:\Program Files\Acro Software\CutePDF Filler Evaluation\CPFillerCoE.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [pdfSaver3] "C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
O4 - HKCU\..\Run: [Dblj] "C:\Program Files\s?curity\w?wexec.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Save to &Xdrive - res://C:\Program Files\Xdrive\Xdrive Desktop\xdrive.exe/std.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\profsy.html

--
End of file - 13445 bytes

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:16 PM

Posted 10 December 2007 - 10:41 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum durianlover
My name is Richie and i'll be helping you to fix your problems.

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6 update 3'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java version.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.


Download SDFix.exe and save it to your desktop:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

* Double click on SDFix on your desktop,and install the fix to C:\

Please then reboot your computer into Safe Mode by doing the following:

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.

* In Safe Mode,go to and open the C:\SDFix folder,then double click on RunThis.bat to start the script.
* Type Y to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.


If you have previously downloaded ComboFix,please delete that version now.
Warning
You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert.
It is intended by its creator to be used under the guidance and supervision of an expert,not for private use.
Using this tool incorrectly could render your system/pc inoperable.

Now download Combofix and save to your desktop:
Note
It is important that it is saved directly to your desktop

Close any open browsers.
Disconnect from the Internet.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.
Note
In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#3 durianlover

durianlover
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:03:16 AM

Posted 10 December 2007 - 02:48 PM

OK,
First off.. things look WAY better! Wow! Thanks! I just got on the internet and the pages load faster than they had in years! I guess there were some infections for a while now or something. Awesome! You rock!

I followed the instructions almost exactly, except a few things:
when it rebooted after Combofix was done, my Spybot Resident was blocking some things (it just came on again after the reboot). I didn't know what to do so I disabled Resident. But, then it seemed like maybe it blocked some combofix stuff. So, I ran Combofix again (I know, you didn't tell me to do that, but I did anyway). And, the second time it didn't reboot, it just went right to the log txt file.

Anyway, these are all the results:

SDFix LOG


SDFix: Version 1.117

Run by Administrator on Mon 12/10/2007 at 10:56 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\PROGRA~1\MESSEN~1\PROFSY~1.HTM - Deleted
C:\Program Files\E404 Helper\e404.v5.dll - Deleted
C:\WINDOWS\system32\ldinfo.ldr - Deleted
C:\WINDOWS\system32\pac.txt - Deleted



Folder C:\Program Files\E404 Helper - Removed

Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 11:04:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

IPC error: 2 The system cannot find the file specified.
scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile"=str(2):"c:\windows\system32\ESENT.dll"
"CategoryMessageFile"=str(2):"c:\windows\system32\ESENT.dll"

scanning hidden registry entries ...

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{065AD53E-05ED-ED60-C43D-270000369496}]
"iaaminlldfbkkgdpng"=hex:69,61,6a,69,62,62,6e,65,69,66,61,63,70,64,68,6f,65,6c,00,00
"haokoafpomngilae"=hex:6a,61,66,69,6e,70,6b,67,66,64,6d,65,64,6b,62,6b,6e,69,6a,67,00,..

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe:*:Enabled:BackWeb for Pavilion"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"="C:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe:*:Enabled:Dreamweaver MX"
"C:\\Program Files\\Sony\\Vegas 6.0\\VegSrv60.exe"="C:\\Program Files\\Sony\\Vegas 6.0\\VegSrv60.exe:*:Enabled:Sony Vegas Network Render Service Control"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
"C:\\temp\\HP_WebRelease\\Setup\\HPZnet01.exe"="C:\\temp\\HP_WebRelease\\Setup\\HPZnet01.exe:*:Enabled:ICE Network Plug in"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:HP Digital Imaging Monitor"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw"
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"="C:\\Program Files\\QuickTime\\QuickTimePlayer.exe:*:Enabled:QuickTime Player"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Microsoft Office\\Office10\\EXCEL.EXE"="C:\\Program Files\\Microsoft Office\\Office10\\EXCEL.EXE:*:Enabled:Microsoft Excel"
"C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\ttax.exe"="C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\updatemgr.exe"="C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\DOCUME~1\\HP_Owner\\LOCALS~1\\Temp\\winA17.tmp.exe"="C:\\DOCUME~1\\HP_Owner\\LOCALS~1\\Temp\\winA17.tmp.exe:*:Enabled:winA17.tmp"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\\iTunes\\iTunes.exe"="%ProgramFiles%\\iTunes\\iTunes.exe:*:enabled:iTunes"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Wed 29 Jun 2005 213 A.SHR --- "C:\BOOT.BAK"
Thu 1 Nov 2007 230,400 ..SHR --- "C:\Program Files\s?curity\w?wexec.exe"
Fri 23 Sep 2005 56 ..SHR --- "C:\WINDOWS\system32\6D69F4DD69.sys"
Fri 23 Sep 2005 2,098 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sun 23 Apr 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 13 Jul 2007 21,504 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\~WRL0403.tmp"
Tue 19 Jul 2005 24,576 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\old documents\~WRL0667.tmp"
Wed 7 Nov 2007 28,672 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\workshops\~WRL0249.tmp"
Wed 7 Nov 2007 34,304 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\workshops\~WRL1860.tmp"
Wed 7 Nov 2007 28,672 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\workshops\~WRL2145.tmp"
Mon 12 Nov 2007 28,160 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\workshops\~WRL3461.tmp"
Wed 7 Nov 2007 28,672 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\workshops\~WRL3502.tmp"
Wed 7 Nov 2007 28,672 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\workshops\~WRL3898.tmp"
Sat 27 Jan 2007 25,600 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\FR and articles in progress\~WRL3118.tmp"
Sat 14 Jul 2007 196,096 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL0491.tmp"
Sat 14 Jul 2007 193,024 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL0592.tmp"
Thu 19 Jul 2007 242,688 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL1092.tmp"
Fri 20 Jul 2007 287,232 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL1144.tmp"
Fri 20 Jul 2007 271,872 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL1498.tmp"
Mon 16 Jul 2007 201,728 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL1516.tmp"
Fri 20 Jul 2007 246,784 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL2052.tmp"
Thu 19 Jul 2007 236,032 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL2165.tmp"
Sat 14 Jul 2007 147,456 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL2179.tmp"
Sat 14 Jul 2007 167,424 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL2459.tmp"
Sat 14 Jul 2007 160,256 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL2498.tmp"
Fri 20 Jul 2007 285,696 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL2624.tmp"
Sat 14 Jul 2007 144,896 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL2824.tmp"
Fri 20 Jul 2007 282,624 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL2830.tmp"
Mon 16 Jul 2007 216,064 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL2976.tmp"
Sat 14 Jul 2007 121,856 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL3063.tmp"
Thu 19 Jul 2007 228,864 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL3291.tmp"
Sat 14 Jul 2007 142,336 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL3345.tmp"
Mon 16 Jul 2007 208,896 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL3669.tmp"
Sat 14 Jul 2007 187,392 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\guitar music\~WRL3686.tmp"
Thu 21 Oct 2004 19,968 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\Lance's Posts\~WRL0744.tmp"
Thu 21 Oct 2004 19,968 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\Lance's Posts\~WRL3315.tmp"
Thu 6 Apr 2006 63,488 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\workshops\AoR\~WRL2625.tmp"
Thu 6 Dec 2007 47,104 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\workshops\AoR\~WRL2755.tmp"
Thu 6 Dec 2007 47,616 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\workshops\AoR\~WRL3669.tmp"
Thu 6 Dec 2007 46,592 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\workshops\AoR\~WRL3996.tmp"
Mon 5 Nov 2007 29,184 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\Dan\invoices\Invoices\~WRL0004.tmp"
Tue 19 Jun 2007 80,384 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0090.tmp"
Tue 19 Jun 2007 79,872 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0098.tmp"
Tue 19 Jun 2007 80,384 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0255.tmp"
Tue 19 Jun 2007 80,384 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0319.tmp"
Tue 19 Jun 2007 76,288 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0354.tmp"
Tue 19 Jun 2007 81,408 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0377.tmp"
Tue 19 Jun 2007 75,264 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0451.tmp"
Tue 19 Jun 2007 76,288 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0502.tmp"
Wed 20 Jun 2007 81,408 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0537.tmp"
Tue 19 Jun 2007 77,824 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0571.tmp"
Tue 19 Jun 2007 19,968 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0675.tmp"
Tue 19 Jun 2007 81,408 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0678.tmp"
Sun 17 Jun 2007 75,776 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0750.tmp"
Wed 20 Jun 2007 81,920 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0939.tmp"
Tue 19 Jun 2007 80,384 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL0996.tmp"
Wed 20 Jun 2007 81,408 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1018.tmp"
Tue 19 Jun 2007 80,384 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1183.tmp"
Wed 20 Jun 2007 82,944 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1213.tmp"
Sun 17 Jun 2007 73,728 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1264.tmp"
Sun 17 Jun 2007 75,264 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1284.tmp"
Wed 20 Jun 2007 20,992 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1335.tmp"
Wed 20 Jun 2007 81,920 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1349.tmp"
Tue 19 Jun 2007 80,896 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1400.tmp"
Tue 19 Jun 2007 77,312 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1472.tmp"
Tue 19 Jun 2007 75,264 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1492.tmp"
Tue 19 Jun 2007 80,384 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1512.tmp"
Tue 19 Jun 2007 76,288 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1638.tmp"
Wed 20 Jun 2007 81,920 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1641.tmp"
Sun 17 Jun 2007 74,752 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1699.tmp"
Tue 19 Jun 2007 79,360 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1737.tmp"
Tue 19 Jun 2007 77,824 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1757.tmp"
Tue 19 Jun 2007 79,360 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1768.tmp"
Wed 20 Jun 2007 82,432 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL1839.tmp"
Tue 19 Jun 2007 80,384 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2053.tmp"
Thu 21 Jun 2007 84,992 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2084.tmp"
Tue 19 Jun 2007 79,872 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2146.tmp"
Wed 20 Jun 2007 20,480 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2174.tmp"
Tue 19 Jun 2007 77,312 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2199.tmp"
Tue 19 Jun 2007 75,264 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2220.tmp"
Wed 20 Jun 2007 20,480 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2227.tmp"
Thu 21 Jun 2007 84,480 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2386.tmp"
Tue 19 Jun 2007 76,800 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2614.tmp"
Tue 19 Jun 2007 74,752 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2732.tmp"
Sun 17 Jun 2007 23,040 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2737.tmp"
Wed 20 Jun 2007 20,480 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2789.tmp"
Tue 19 Jun 2007 79,360 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2794.tmp"
Tue 19 Jun 2007 77,824 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2864.tmp"
Wed 20 Jun 2007 19,968 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2944.tmp"
Wed 20 Jun 2007 20,992 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL2967.tmp"
Wed 20 Jun 2007 20,480 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3108.tmp"
Tue 19 Jun 2007 79,360 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3216.tmp"
Thu 21 Jun 2007 84,480 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3309.tmp"
Tue 19 Jun 2007 79,872 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3341.tmp"
Tue 19 Jun 2007 76,800 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3551.tmp"
Thu 21 Jun 2007 83,968 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3561.tmp"
Sun 17 Jun 2007 75,264 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3648.tmp"
Tue 19 Jun 2007 77,824 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3663.tmp"
Tue 19 Jun 2007 75,264 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3710.tmp"
Tue 19 Jun 2007 78,336 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3804.tmp"
Sun 17 Jun 2007 75,776 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL3916.tmp"
Tue 19 Jun 2007 19,968 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL4019.tmp"
Wed 20 Jun 2007 19,968 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\2007\~WRL4062.tmp"
Thu 14 Jun 2007 45,056 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL0155.tmp"
Fri 15 Jun 2007 50,176 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL0191.tmp"
Sat 16 Jun 2007 59,392 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL0238.tmp"
Sun 17 Jun 2007 70,144 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL0321.tmp"
Thu 14 Jun 2007 46,080 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL0492.tmp"
Thu 14 Jun 2007 41,984 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL0600.tmp"
Thu 14 Jun 2007 42,496 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL0828.tmp"
Sat 16 Jun 2007 59,904 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL0935.tmp"
Fri 15 Jun 2007 57,856 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL0974.tmp"
Sun 17 Jun 2007 65,024 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1002.tmp"
Thu 14 Jun 2007 43,520 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1005.tmp"
Sat 16 Jun 2007 65,024 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1014.tmp"
Sun 17 Jun 2007 66,048 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1259.tmp"
Thu 14 Jun 2007 46,592 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1271.tmp"
Fri 15 Jun 2007 50,688 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1300.tmp"
Fri 15 Jun 2007 57,856 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1366.tmp"
Fri 15 Jun 2007 47,616 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1440.tmp"
Fri 15 Jun 2007 57,856 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1601.tmp"
Sun 17 Jun 2007 72,704 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1627.tmp"
Sun 17 Jun 2007 71,168 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1692.tmp"
Sat 16 Jun 2007 64,512 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1700.tmp"
Sat 16 Jun 2007 63,488 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1818.tmp"
Fri 15 Jun 2007 50,176 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL1863.tmp"
Thu 14 Jun 2007 42,496 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL2037.tmp"
Sun 17 Jun 2007 70,144 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL2139.tmp"
Fri 15 Jun 2007 52,736 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL2241.tmp"
Thu 14 Jun 2007 46,592 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL2492.tmp"
Sat 16 Jun 2007 62,976 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL2568.tmp"
Fri 15 Jun 2007 58,880 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL2633.tmp"
Thu 14 Jun 2007 43,520 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3003.tmp"
Sun 17 Jun 2007 66,048 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3014.tmp"
Sat 16 Jun 2007 63,488 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3027.tmp"
Thu 14 Jun 2007 45,568 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3031.tmp"
Sat 16 Jun 2007 63,488 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3076.tmp"
Sun 17 Jun 2007 68,096 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3145.tmp"
Thu 14 Jun 2007 45,568 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3182.tmp"
Thu 14 Jun 2007 46,592 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3190.tmp"
Thu 14 Jun 2007 45,568 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3196.tmp"
Wed 13 Jun 2007 31,232 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3336.tmp"
Fri 15 Jun 2007 50,688 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3774.tmp"
Sat 16 Jun 2007 63,488 A..H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\AoS\Outlines\~WRL3831.tmp"
Wed 11 Apr 2007 58,880 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\Charismatic Conversations\binder\~WRL0584.tmp"
Thu 12 Apr 2007 166,912 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\Charismatic Conversations\binder\~WRL0941.tmp"
Thu 12 Apr 2007 52,736 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\Charismatic Conversations\binder\~WRL2951.tmp"
Fri 6 Apr 2007 51,712 ...H. --- "C:\Documents and Settings\HP_Owner\My Documents\PU101 products\Charismatic Conversations\binder\~WRL2967.tmp"

Finished!


ComboFix LOG


ComboFix 07-12-10.2 - HP_Owner 2007-12-10 11:32:13.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.134 [GMT -8:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Program Files\scurit~1
C:\Program Files\scurit~1\w?wexec.exe
C:\Program Files\SecCenter
C:\Temp\bkR11
C:\WINDOWS\hg173.exe
C:\WINDOWS\system32\daSgo02
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\sznf.ascii
C:\WINDOWS\system32\wintsvtr32.exe
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2007-11-10 to 2007-12-10 )))))))))))))))))))))))))))))))
.

2007-12-10 10:56 . 2007-12-10 10:56 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-10 10:53 . 2005-02-17 00:42 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-12-10 10:53 . 2005-02-17 00:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-12-10 10:53 . 2005-02-17 00:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2007-12-10 10:53 . 2005-02-17 00:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterMute
2007-12-10 10:53 . 2005-02-17 00:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2007-12-10 10:28 . 2007-12-10 10:28 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-10 10:28 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-09 23:03 . 2007-12-09 23:10 1,374 --a------ C:\WINDOWS\imsins.BAK
2007-12-09 22:47 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2007-12-09 22:47 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2007-12-09 22:47 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2007-12-09 22:47 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2007-12-09 22:47 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2007-12-09 22:47 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2007-12-09 22:46 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2007-12-09 20:32 . 2007-12-09 21:19 <DIR> d-------- C:\VundoFix Backups
2007-12-09 20:26 . 2007-12-09 20:26 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-09 14:42 . 2007-12-09 14:42 97 --a------ C:\WINDOWS\wininit.ini
2007-12-09 14:29 . 2007-12-09 14:29 <DIR> d-------- C:\Program Files\CCleaner
2007-12-09 13:41 . 2007-12-10 10:09 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\AVG7
2007-12-09 13:40 . 2007-12-09 13:40 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-09 13:40 . 2007-12-09 14:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 13:39 . 2007-12-09 13:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 12:46 . 2007-12-09 12:46 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-09 12:46 . 2007-12-09 12:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-08 21:38 . 2007-12-09 14:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2007-12-08 21:37 . 2007-12-09 16:20 <DIR> d-------- C:\WINDOWS\system32\nuinopsd
2007-12-08 21:36 . 2007-12-09 14:38 <DIR> d-------- C:\Program Files\tutklsxo
2007-12-08 21:36 . 2007-12-09 14:42 <DIR> d-------- C:\Program Files\MalwareAlarm
2007-12-08 21:36 . 2007-12-09 14:00 <DIR> d-------- C:\Program Files\Kzqqgsxa
2007-12-08 21:36 . 2007-12-08 21:36 1,154,709 --a------ C:\Install
2007-12-08 21:36 . 2007-12-08 21:36 103,936 --------- C:\WINDOWS\system32\drvrod.dll
2007-12-08 21:35 . 2007-12-09 13:32 <DIR> d-------- C:\Program Files\Spruce
2007-12-08 21:35 . 2007-12-08 21:35 12 --a------ C:\WINDOWS\system32\din.ip
2007-12-08 21:35 . 2007-12-08 21:35 4 --a------ C:\WINDOWS\system32\jpewocmz.ini
2007-12-08 00:12 . 2007-12-08 00:12 <DIR> d-------- C:\Program Files\uTorrent
2007-12-08 00:10 . 2007-12-08 00:39 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\uTorrent

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-10 18:28 --------- d-----w C:\Program Files\Java
2007-12-10 08:28 --------- d-----w C:\Program Files\TimeLog
2007-12-09 22:13 --------- d-----w C:\Program Files\Microsoft Works
2007-12-09 22:02 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\OpenOffice.org2
2007-12-09 21:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-09 21:07 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-03 21:52 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Skype
2007-12-02 20:01 --------- d-----w C:\Program Files\Mozilla Thunderbird
2007-10-27 22:12 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\dvdcss
2007-10-26 03:36 8,454,656 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-25 00:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-22 20:16 --------- d-----w C:\Program Files\DivX
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 18:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 18:22 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-11 23:14 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-05-13 19:55 136,240 -c--a-w C:\Documents and Settings\HP_Owner\Application Data\GDIPFONTCACHEV1.DAT
2006-11-25 07:57 482 ----a-w C:\Program Files\Del.js
2006-05-15 06:59 3,228,939 -c--a-w C:\Program Files\mplayer-win32-mingw-dev-cvs20051227.exe
2006-03-13 01:27 758,784 ----a-w C:\Program Files\VirtualDub.exe
2006-03-13 01:27 120,219 -c--a-w C:\Program Files\VirtualDub.vdi
2006-03-13 01:25 7,738 -c--a-w C:\Program Files\vdub.exe
2006-03-13 01:25 16,384 -c--a-w C:\Program Files\auxsetup.exe
2006-03-13 01:24 7,168 -c--a-w C:\Program Files\vdremote.dll
2006-03-13 01:24 6,656 -c--a-w C:\Program Files\vdicmdrv.dll
2006-03-13 01:24 5,120 -c--a-w C:\Program Files\vdsvrlnk.dll
2006-03-13 01:24 210,421 -c--a-w C:\Program Files\VirtualDub.chm
2005-12-20 05:52 18,321 -c--a-w C:\Program Files\copying
2005-09-23 21:41 56 --sh--r C:\WINDOWS\system32\6D69F4DD69.sys
2005-09-23 21:41 2,098 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\xdrive.LinkedFolder]
@={5D64CBA3-BDEC-427C-8A7F-8CB7C9EA7C74}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\xdrive.LinkedSharedFolder]
@={7C541B8D-BD5A-4687-9010-50E2B5D4A8E4}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\xdrive.SharedFolder]
@={39C2972F-3338-471B-8D67-FA82E46E3AC2}

[HKEY_CLASSES_ROOT\CLSID\{5D64CBA3-BDEC-427C-8A7F-8CB7C9EA7C74}]
2005-10-24 16:23 77824 --a------ C:\Program Files\Xdrive\Xdrive Desktop\Overlay.dll

[HKEY_CLASSES_ROOT\CLSID\{7C541B8D-BD5A-4687-9010-50E2B5D4A8E4}]
2005-10-24 16:23 77824 --a------ C:\Program Files\Xdrive\Xdrive Desktop\Overlay.dll

[HKEY_CLASSES_ROOT\CLSID\{39C2972F-3338-471B-8D67-FA82E46E3AC2}]
2005-10-24 16:23 77824 --a------ C:\Program Files\Xdrive\Xdrive Desktop\Overlay.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00]
"pdfSaver3"="C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe" [2004-09-05 17:20]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 16:45]
"Dblj"="C:\Program Files\s?curity\w?wexec.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 08:04]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 16:10 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 C:\WINDOWS\AGRSMMSG.exe]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 10:53]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 10:42]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 11:02]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 12:43]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2004-10-25 13:17]
"AlcWzrd"="ALCWZRD.EXE" [2004-10-13 15:17 C:\WINDOWS\ALCWZRD.EXE]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 13:54]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2004-12-13 18:23]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-10 15:26]
"pdfSaver3"="" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 02:50]
"MaxtorOneTouch"="C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe" [2005-12-01 16:04]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 19:52]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 07:59]
"SoundMan"="SOUNDMAN.EXE" [2004-10-13 13:01 C:\WINDOWS\SOUNDMAN.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 15:55]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-09 13:39]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-09 13:39]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-05-20 17:50:26]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-09-27 13:50:08]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-29 22:37:20]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 19:28:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-02-17 01:04:47]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Messenger\profsy.html
FriendlyName=

S3 HPZs2k12;Storage Class Driver for IEEE-1284.4 (HPZ12);C:\WINDOWS\system32\Drivers\hpzs2k12.sys
S3 NUVision;Pinnacle DVC 80 Video;C:\WINDOWS\system32\DRIVERS\nuvvid2.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{946850c5-1e27-11d9-baf0-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2a43531-fbd1-11db-82a2-0014bf570427}]
\Shell\AutoRun\command - Iexplores.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-06 23:21:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-10-30 19:14:00 C:\WINDOWS\Tasks\Windows Media Player.job"
- C:\PROGRA~1\WINDOW~1\wmplayer.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 11:35:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-10 11:36:03
.
--- E O F --- 2007-12-10 07:10:53


HijackThis LOG


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:41:23 AM, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CutePDF Form Filler - {D41289F2-69C6-417B-897E-C653D677CBAF} - C:\Program Files\Acro Software\CutePDF Filler Evaluation\CPFillerCoE.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [pdfSaver3] "C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
O4 - HKCU\..\Run: [Dblj] "C:\Program Files\s?curity\w?wexec.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Save to &Xdrive - res://C:\Program Files\Xdrive\Xdrive Desktop\xdrive.exe/std.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\profsy.html

--
End of file - 13243 bytes



That's it...
Like I said. Things are much faster on my computer, and I haven't had any difficulties yet.
Thank you!

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:16 PM

Posted 10 December 2007 - 06:08 PM

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\system32\jpewocmz.ini
C:\WINDOWS\system32\drvrod.dll
Folder::
C:\WINDOWS\system32\nuinopsd
C:\Program Files\tutklsxo
C:\Program Files\Kzqqgsxa
Registry::
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\DOCUME~1\\HP_Owner\\LOCALS~1\\Temp\\winA17.tmp.exe"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dblj"=-
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2a43531-fbd1-11db-82a2-0014bf570427}]

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.


I now need you to do the following if you will:

Go here:http://virusscan.jotti.org/
Using the 'Browse' button,browse to:
C:\Program Files\mplayer-win32-mingw-dev-cvs20051227.exe
Then press the 'Submit' button.
Wait while the file is scanned.
Post the results into your next reply.

If Jotti's too busy,try here:
http://www.virustotal.com/en/virustotalf.html
Click on the 'Analysis' tab.
Using the 'Browse' button,browse to:
C:\Program Files\mplayer-win32-mingw-dev-cvs20051227.exe
Then click on 'Send File'.
Post the results into your next reply.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#5 durianlover

durianlover
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:03:16 AM

Posted 10 December 2007 - 09:08 PM

Thanks again!


Here's the logs...

ComboFix Log

ComboFix 07-12-10.2 - HP_Owner 2007-12-10 16:39:42.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.164 [GMT -8:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Owner\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\drvrod.dll
C:\WINDOWS\system32\jpewocmz.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Kzqqgsxa
C:\Program Files\tutklsxo
C:\WINDOWS\system32\drvrod.dll
C:\WINDOWS\system32\jpewocmz.ini
C:\WINDOWS\system32\nuinopsd
C:\WINDOWS\system32\nuinopsd\bg1.gif
C:\WINDOWS\system32\nuinopsd\bgtop.gif
C:\WINDOWS\system32\nuinopsd\bottom1.gif
C:\WINDOWS\system32\nuinopsd\essentials.gif
C:\WINDOWS\system32\nuinopsd\icon1.ico
C:\WINDOWS\system32\nuinopsd\install1.gif
C:\WINDOWS\system32\nuinopsd\left1.gif
C:\WINDOWS\system32\nuinopsd\li.gif
C:\WINDOWS\system32\nuinopsd\logo.gif
C:\WINDOWS\system32\nuinopsd\main.htm
C:\WINDOWS\system32\nuinopsd\mainframe.htm
C:\WINDOWS\system32\nuinopsd\reinstall1.gif
C:\WINDOWS\system32\nuinopsd\right1.gif
C:\WINDOWS\system32\nuinopsd\s1.htm
C:\WINDOWS\system32\nuinopsd\s2.htm
C:\WINDOWS\system32\nuinopsd\s3.htm
C:\WINDOWS\system32\nuinopsd\SMTop1.gif
C:\WINDOWS\system32\nuinopsd\SMTop2.gif
C:\WINDOWS\system32\nuinopsd\SMTop3.gif
C:\WINDOWS\system32\nuinopsd\SMTop4.gif
C:\WINDOWS\system32\nuinopsd\soft1_off.gif
C:\WINDOWS\system32\nuinopsd\soft1_off_ext.gif
C:\WINDOWS\system32\nuinopsd\soft1_on.gif
C:\WINDOWS\system32\nuinopsd\soft1_on_ext.gif
C:\WINDOWS\system32\nuinopsd\soft2_off.gif
C:\WINDOWS\system32\nuinopsd\soft2_off_ext.gif
C:\WINDOWS\system32\nuinopsd\soft2_on.gif
C:\WINDOWS\system32\nuinopsd\soft2_on_ext.gif
C:\WINDOWS\system32\nuinopsd\soft3_off.gif
C:\WINDOWS\system32\nuinopsd\soft3_off_ext.gif
C:\WINDOWS\system32\nuinopsd\soft3_on.gif
C:\WINDOWS\system32\nuinopsd\soft3_on_ext.gif
C:\WINDOWS\system32\nuinopsd\softbottom_off.gif
C:\WINDOWS\system32\nuinopsd\softbottom_on.gif
C:\WINDOWS\system32\nuinopsd\softleft_off.gif
C:\WINDOWS\system32\nuinopsd\softleft_on.gif
C:\WINDOWS\system32\nuinopsd\top1.gif
C:\WINDOWS\system32\nuinopsd\top2.gif
C:\WINDOWS\system32\nuinopsd\turnoff1.gif
C:\WINDOWS\system32\nuinopsd\turnon1.gif

.
((((((((((((((((((((((((( Files Created from 2007-11-11 to 2007-12-11 )))))))))))))))))))))))))))))))
.

2007-12-10 14:23 . 2007-12-10 14:23 <DIR> d-------- C:\Program Files\Common Files\Canon
2007-12-10 14:07 . 2004-05-11 10:53 626,960 -ra------ C:\WINDOWS\system32\hpvaut32.dll
2007-12-10 14:07 . 2004-05-11 10:53 487,424 -ra------ C:\WINDOWS\system32\hpvcp70.dll
2007-12-10 14:07 . 2004-05-11 10:53 344,064 -ra------ C:\WINDOWS\system32\hpvcr70.dll
2007-12-10 14:05 . 2004-03-14 03:43 135,249 --a------ C:\WINDOWS\system32\hpzlnt10.dll
2007-12-10 14:03 . 2007-12-10 14:04 640 --a------ C:\WINDOWS\hpntwksetup.ini
2007-12-10 13:58 . 2007-12-10 14:15 104,550 --a------ C:\WINDOWS\hpoins04.dat
2007-12-10 13:58 . 2004-06-22 07:30 17,176 --------- C:\WINDOWS\hpomdl04.dat
2007-12-10 12:03 . 2007-12-10 12:03 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-12-10 10:56 . 2007-12-10 10:56 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-10 10:53 . 2005-02-17 00:42 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-12-10 10:53 . 2005-02-17 00:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-12-10 10:53 . 2005-02-17 00:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2007-12-10 10:53 . 2005-02-17 00:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterMute
2007-12-10 10:53 . 2005-02-17 00:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2007-12-10 10:28 . 2007-12-10 10:28 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-10 10:28 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-09 23:03 . 2007-12-09 23:10 1,374 --a------ C:\WINDOWS\imsins.BAK
2007-12-09 22:47 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2007-12-09 22:47 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2007-12-09 22:47 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2007-12-09 22:47 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2007-12-09 22:47 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2007-12-09 22:47 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2007-12-09 22:46 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2007-12-09 20:32 . 2007-12-09 21:19 <DIR> d-------- C:\VundoFix Backups
2007-12-09 20:26 . 2007-12-09 20:26 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-09 14:42 . 2007-12-09 14:42 97 --a------ C:\WINDOWS\wininit.ini
2007-12-09 14:29 . 2007-12-09 14:29 <DIR> d-------- C:\Program Files\CCleaner
2007-12-09 13:41 . 2007-12-10 10:09 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\AVG7
2007-12-09 13:40 . 2007-12-09 13:40 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-09 13:40 . 2007-12-09 14:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 13:39 . 2007-12-09 13:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 12:46 . 2007-12-09 12:46 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-09 12:46 . 2007-12-09 12:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-08 21:38 . 2007-12-09 14:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2007-12-08 21:36 . 2007-12-09 14:42 <DIR> d-------- C:\Program Files\MalwareAlarm
2007-12-08 21:36 . 2007-12-08 21:36 1,154,709 --a------ C:\Install
2007-12-08 21:35 . 2007-12-09 13:32 <DIR> d-------- C:\Program Files\Spruce
2007-12-08 21:35 . 2007-12-08 21:35 12 --a------ C:\WINDOWS\system32\din.ip
2007-12-08 00:12 . 2007-12-08 00:12 <DIR> d-------- C:\Program Files\uTorrent
2007-12-08 00:10 . 2007-12-08 00:39 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\uTorrent

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-10 22:23 --------- d-----w C:\Program Files\Canon
2007-12-10 22:16 --------- d-----w C:\Program Files\Hewlett-Packard
2007-12-10 22:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-10 22:07 --------- d-----w C:\Program Files\HP
2007-12-10 18:28 --------- d-----w C:\Program Files\Java
2007-12-10 08:28 --------- d-----w C:\Program Files\TimeLog
2007-12-09 22:13 --------- d-----w C:\Program Files\Microsoft Works
2007-12-09 22:02 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\OpenOffice.org2
2007-12-09 21:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-09 21:07 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-03 21:52 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Skype
2007-12-02 20:01 --------- d-----w C:\Program Files\Mozilla Thunderbird
2007-10-27 22:12 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\dvdcss
2007-10-26 03:36 8,454,656 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-22 20:16 --------- d-----w C:\Program Files\DivX
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 18:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 18:22 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-11 23:14 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-05-13 19:55 136,240 -c--a-w C:\Documents and Settings\HP_Owner\Application Data\GDIPFONTCACHEV1.DAT
2006-11-25 07:57 482 ----a-w C:\Program Files\Del.js
2006-05-15 06:59 3,228,939 -c--a-w C:\Program Files\mplayer-win32-mingw-dev-cvs20051227.exe
2006-03-13 01:27 758,784 ----a-w C:\Program Files\VirtualDub.exe
2006-03-13 01:27 120,219 -c--a-w C:\Program Files\VirtualDub.vdi
2006-03-13 01:25 7,738 -c--a-w C:\Program Files\vdub.exe
2006-03-13 01:25 16,384 -c--a-w C:\Program Files\auxsetup.exe
2006-03-13 01:24 7,168 -c--a-w C:\Program Files\vdremote.dll
2006-03-13 01:24 6,656 -c--a-w C:\Program Files\vdicmdrv.dll
2006-03-13 01:24 5,120 -c--a-w C:\Program Files\vdsvrlnk.dll
2006-03-13 01:24 210,421 -c--a-w C:\Program Files\VirtualDub.chm
2005-12-20 05:52 18,321 -c--a-w C:\Program Files\copying
2005-09-23 21:41 56 --sh--r C:\WINDOWS\system32\6D69F4DD69.sys
2005-09-23 21:41 2,098 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2007-12-10_11.35.05.04 )))))))))))))))))))))))))))))))))))))))))
.
- 1998-10-29 23:45:06 306,688 -c--a-w C:\WINDOWS\IsUninst.exe
+ 1998-10-30 00:45:06 306,688 ----a-w C:\WINDOWS\IsUninst.exe
- 2001-08-17 20:53:32 6,784 -c--a-w C:\WINDOWS\system32\dllcache\serscan.sys
+ 2001-08-17 21:53:32 6,784 ----a-w C:\WINDOWS\system32\dllcache\serscan.sys
- 2001-08-17 20:53:32 6,784 ----a-w C:\WINDOWS\system32\drivers\serscan.sys
+ 2001-08-17 21:53:32 6,784 ----a-w C:\WINDOWS\system32\drivers\serscan.sys
- 2004-03-14 10:32:06 278,528 ----a-w C:\WINDOWS\system32\hpgwiamd.dll
+ 2004-03-14 11:32:06 278,528 ----a-w C:\WINDOWS\system32\hpgwiamd.dll
- 2004-04-13 08:10:24 581,632 ----a-w C:\WINDOWS\system32\hpotscl.dll
+ 2004-04-13 09:10:24 581,632 ----a-w C:\WINDOWS\system32\hpotscl.dll
- 2004-04-13 08:10:16 90,112 -c--a-w C:\WINDOWS\system32\hpovst08.dll
+ 2004-04-13 09:10:16 90,112 ----a-w C:\WINDOWS\system32\hpovst08.dll
- 2004-03-14 10:34:10 270,336 -c--a-w C:\WINDOWS\system32\HPZc3212.dll
+ 2004-03-14 11:34:10 270,336 ----a-w C:\WINDOWS\system32\HPZc3212.dll
- 2004-04-07 14:34:26 196,608 -c--a-w C:\WINDOWS\system32\hpzcoi10.dll
+ 2004-04-07 15:34:26 196,608 ----a-w C:\WINDOWS\system32\hpzcoi10.dll
- 2004-04-07 14:33:20 344,064 -c--a-w C:\WINDOWS\system32\hpzcon10.dll
+ 2004-04-07 15:33:20 344,064 ----a-w C:\WINDOWS\system32\hpzcon10.dll
- 2004-04-08 09:17:06 131,470 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpof2510.dat
+ 2004-04-08 10:17:06 131,470 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpof2510.dat
- 2004-04-13 08:10:12 36,864 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpofax08.dll
+ 2004-04-13 09:10:12 36,864 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpofax08.dll
- 2004-04-08 09:16:30 131,317 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpop2510.dat
+ 2004-04-08 10:16:30 131,317 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpop2510.dat
- 2004-03-14 10:43:28 196,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpz2ku10.dll
+ 2004-03-14 11:43:28 196,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpz2ku10.dll
- 2004-03-24 07:04:48 286,720 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcfg10.exe
+ 2004-03-24 08:04:48 286,720 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcfg10.exe
- 2004-04-07 14:34:26 196,608 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcoi10.dll
+ 2004-04-07 15:34:26 196,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcoi10.dll
- 2004-04-07 14:33:20 344,064 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcon10.dll
+ 2004-04-07 15:33:20 344,064 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcon10.dll
- 2004-03-24 07:04:54 647,168 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzeng10.exe
+ 2004-03-24 08:04:54 647,168 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzeng10.exe
- 2004-03-24 07:04:58 69,632 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzflt10.dll
+ 2004-03-24 08:04:58 69,632 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzflt10.dll
- 2004-03-24 07:05:00 1,589,248 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzimc10.dll
+ 2004-03-24 08:05:00 1,589,248 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzimc10.dll
- 2004-03-24 07:05:04 352,256 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzime10.dll
+ 2004-03-24 08:05:04 352,256 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzime10.dll
- 2004-03-24 07:05:08 1,671,168 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzims10.dll
+ 2004-03-24 08:05:08 1,671,168 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzims10.dll
- 2004-03-24 07:05:14 200,704 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzjui10.dll
+ 2004-03-24 08:05:14 200,704 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzjui10.dll
- 2004-03-14 10:43:30 135,249 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzlnt10.dll
+ 2004-03-14 11:43:30 135,249 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzlnt10.dll
- 2004-03-24 07:05:18 143,360 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpcl10.dll
+ 2004-03-24 08:05:18 143,360 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpcl10.dll
- 2004-03-14 10:43:30 487,424 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpm310.dll
+ 2004-03-14 11:43:30 487,424 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpm310.dll
- 2004-03-24 07:05:22 331,776 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpre10.exe
+ 2004-03-24 08:05:22 331,776 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpre10.exe
- 2004-03-14 10:44:34 3,182,592 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzr3210.dll
+ 2004-03-14 11:44:34 3,182,592 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzr3210.dll
- 2004-03-24 07:05:26 368,640 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzres10.dll
+ 2004-03-24 08:05:26 368,640 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzres10.dll
- 2004-03-14 10:44:36 1,695,744 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzrm310.dll
+ 2004-03-14 11:44:36 1,695,744 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzrm310.dll
- 2004-03-24 07:05:28 679,936 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzslk10.dll
+ 2004-03-24 08:05:28 679,936 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzslk10.dll
- 2004-03-14 10:43:30 180,315 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzsnt10.dll
+ 2004-03-14 11:43:30 180,315 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzsnt10.dll
- 2004-03-24 07:05:32 385,024 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzstc10.exe
+ 2004-03-24 08:05:32 385,024 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzstc10.exe
- 2004-03-24 07:05:36 163,840 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzstw10.exe
+ 2004-03-24 08:05:36 163,840 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzstw10.exe
- 2004-03-24 07:05:38 61,440 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbi10.dll
+ 2004-03-24 08:05:38 61,440 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbi10.dll
- 2004-03-24 07:05:42 172,032 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbu10.exe
+ 2004-03-24 08:05:42 172,032 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbu10.exe
- 2004-04-09 19:51:56 7,331,840 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbx10.exe
+ 2004-04-09 20:51:56 7,331,840 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbx10.exe
- 2004-03-24 07:05:52 155,708 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzvip10.dll
+ 2004-03-24 08:05:52 155,708 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzvip10.dll
- 2004-04-08 09:16:30 131,317 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpop2510.dat
+ 2004-04-08 10:16:30 131,317 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpop2510.dat
- 2004-03-24 07:04:48 286,720 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzcfg10.exe
+ 2004-03-24 08:04:48 286,720 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzcfg10.exe
- 2004-04-07 14:34:26 196,608 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzcoi10.dll
+ 2004-04-07 15:34:26 196,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzcoi10.dll
- 2004-04-07 14:33:20 344,064 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzcon10.dll
+ 2004-04-07 15:33:20 344,064 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzcon10.dll
- 2004-03-24 07:05:08 1,671,168 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzims10.dll
+ 2004-03-24 08:05:08 1,671,168 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzims10.dll
- 2004-03-24 07:05:18 143,360 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzpcl10.dll
+ 2004-03-24 08:05:18 143,360 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzpcl10.dll
- 2004-03-24 07:05:22 331,776 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzpre10.exe
+ 2004-03-24 08:05:22 331,776 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzpre10.exe
- 2004-03-14 10:44:36 1,695,744 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzrm310.dll
+ 2004-03-14 11:44:36 1,695,744 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzrm310.dll
- 2004-03-24 07:05:28 679,936 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzslk10.dll
+ 2004-03-24 08:05:28 679,936 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzslk10.dll
- 2004-03-24 07:05:32 385,024 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzstc10.exe
+ 2004-03-24 08:05:32 385,024 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzstc10.exe
- 2004-03-24 07:05:36 163,840 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzstw10.exe
+ 2004-03-24 08:05:36 163,840 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzstw10.exe
- 2004-03-24 07:05:38 61,440 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpztbi10.dll
+ 2004-03-24 08:05:38 61,440 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpztbi10.dll
- 2004-03-24 07:05:42 172,032 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpztbu10.exe
+ 2004-03-24 08:05:42 172,032 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpztbu10.exe
- 2004-04-09 19:51:56 7,331,840 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpztbx10.exe
+ 2004-04-09 20:51:56 7,331,840 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpztbx10.exe
- 2004-03-24 07:05:52 155,708 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzvip10.dll
+ 2004-03-24 08:05:52 155,708 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpzvip10.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\xdrive.LinkedFolder]
@={5D64CBA3-BDEC-427C-8A7F-8CB7C9EA7C74}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\xdrive.LinkedSharedFolder]
@={7C541B8D-BD5A-4687-9010-50E2B5D4A8E4}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\xdrive.SharedFolder]
@={39C2972F-3338-471B-8D67-FA82E46E3AC2}

[HKEY_CLASSES_ROOT\CLSID\{5D64CBA3-BDEC-427C-8A7F-8CB7C9EA7C74}]
2005-10-24 16:23 77824 --a------ C:\Program Files\Xdrive\Xdrive Desktop\Overlay.dll

[HKEY_CLASSES_ROOT\CLSID\{7C541B8D-BD5A-4687-9010-50E2B5D4A8E4}]
2005-10-24 16:23 77824 --a------ C:\Program Files\Xdrive\Xdrive Desktop\Overlay.dll

[HKEY_CLASSES_ROOT\CLSID\{39C2972F-3338-471B-8D67-FA82E46E3AC2}]
2005-10-24 16:23 77824 --a------ C:\Program Files\Xdrive\Xdrive Desktop\Overlay.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00]
"pdfSaver3"="C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe" [2004-09-05 17:20]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 16:45]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 08:04]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 16:10 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 C:\WINDOWS\AGRSMMSG.exe]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 10:53]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 10:42]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 11:02]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 12:43]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2004-10-25 13:17]
"AlcWzrd"="ALCWZRD.EXE" [2004-10-13 15:17 C:\WINDOWS\ALCWZRD.EXE]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 13:54]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2004-12-13 18:23]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-10 15:26]
"pdfSaver3"="" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 02:50]
"MaxtorOneTouch"="C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe" [2005-12-01 16:04]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 19:52]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 07:59]
"SoundMan"="SOUNDMAN.EXE" [2004-10-13 13:01 C:\WINDOWS\SOUNDMAN.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 15:55]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-09 13:39]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-09 13:39]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-05-20 17:50:26]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-09-27 13:50:08]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-29 22:37:20]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 19:28:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-02-17 01:04:47]

S3 HPZs2k12;Storage Class Driver for IEEE-1284.4 (HPZ12);C:\WINDOWS\system32\Drivers\hpzs2k12.sys
S3 NUVision;Pinnacle DVC 80 Video;C:\WINDOWS\system32\DRIVERS\nuvvid2.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{946850c5-1e27-11d9-baf0-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-06 23:21:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-10-30 19:14:00 C:\WINDOWS\Tasks\Windows Media Player.job"
- C:\PROGRA~1\WINDOW~1\wmplayer.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 16:43:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-10 16:44:15
C:\ComboFix2.txt ... 2007-12-10 11:36
.
--- E O F --- 2007-12-10 07:10:53


Scan Results for C:\Program Files\mplayer-win32-mingw-dev-cvs20051227.exe


Scan taken on 11 Dec 2007 01:07:35 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing


HijackThis LOG


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:06:24 PM, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ALCWZRD.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CutePDF Form Filler - {D41289F2-69C6-417B-897E-C653D677CBAF} - C:\Program Files\Acro Software\CutePDF Filler Evaluation\CPFillerCoE.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [pdfSaver3] "C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Save to &Xdrive - res://C:\Program Files\Xdrive\Xdrive Desktop\xdrive.exe/std.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
O24 - Desktop Component 0: (no name) - (no file)

--
End of file - 13253 bytes

#6 durianlover

durianlover
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:03:16 AM

Posted 10 December 2007 - 09:10 PM

oh yeah... another note...
My printer wasn't working after the last fix, so I just reinstalled the driver and now it works fine. (Just a FYI)


Thanks so much for your help with this! :thumbsup:

#7 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:16 PM

Posted 11 December 2007 - 04:26 AM

Please disable Spybot S&D’s protection,or it will interfere.
You can enable it after you're clean.

Open Spybot and click on 'Mode' and check 'Advanced Mode'.
Click on 'Tools' in bottom left hand corner.
Click on the 'System Startup' icon.
Uncheck 'Teatimer' box and/or uncheck 'Resident'.
Click the 'Allow Change' box.
Then, check next to the computer clock to see if the icon for Spybot is still there.
If it is, right click it and choose 'exit Spybot-S&D Resident'.
Restart the computer.
If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:
http://www.russelltexas.com/malware/teatimer.htm

Click on Start/Run,copy and paste ComboFix /u into the 'Open:' space,then press Ok.

Posted Image

Please download OTMoveIt by OldTimer:
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Click on the 'Cleanup' button Posted Image
When you do this a text file named cleanup.txt will be downloaded from the internet.
If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so.
When the 'Confirm' box appears click 'Yes'.
Restart your pc when prompted.


Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1
Do not run it just yet.

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.
Do not run it just yet.

You might want to print/copy the following as you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O24 - Desktop Component 0: (no name) - (no file)
Exit Hijackthis.

Now double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.
Click 'Exit' on the Main menu to close the program.

Now Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image

#8 durianlover

durianlover
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:03:16 AM

Posted 11 December 2007 - 03:21 PM

Well,
My PC seems to be working fine. There's nothing major that I notice. Here are the logs.

I noticed that even though I did the fix with HijackThis on O24 - Desktop Component 0: (no name) - (no file)
after the reboot, it's still there.

Anyway, take a look.

Thanks again for your thorough help :thumbsup:

HiJackThis LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:16:50 PM, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CutePDF Form Filler - {D41289F2-69C6-417B-897E-C653D677CBAF} - C:\Program Files\Acro Software\CutePDF Filler Evaluation\CPFillerCoE.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [pdfSaver3] "C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Save to &Xdrive - res://C:\Program Files\Xdrive\Xdrive Desktop\xdrive.exe/std.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
O24 - Desktop Component 0: (no name) - (no file)

--
End of file - 13062 bytes


SUPERAntiSpyware LOG


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/11/2007 at 12:10 PM

Application Version : 3.9.1008

Core Rules Database Version : 3359
Trace Rules Database Version: 1358

Scan type : Complete Scan
Total Scan Time : 01:17:54

Memory items scanned : 173
Memory threats detected : 0
Registry items scanned : 7442
Registry threats detected : 0
File items scanned : 46738
File threats detected : 1

Malware.MalwareAlarm
C:\Program Files\MalwareAlarm

#9 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:16 PM

Posted 11 December 2007 - 05:09 PM

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.reg to your desktop.
Then double click on the fix.reg file on your desktopPosted Imageand agree to merge the imformation into the registry,then restart your pc.

REGEDIT4
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]


Your log is clean :thumbsup: ,please do the following:

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

You should take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:

Simple and easy ways to keep your computer safe and secure on the Internet:
http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

How to prevent Malware:
http://users.telenet.be/bluepatchy/miekiem...prevention.html

So how did I get infected in the first place:
http://forums.spybot.info/showthread.php?t=279

Malware Cleanup Programs and Preventative Procedures:
http://russelltexas.com/malware/allclear.htm
Posted Image
Posted Image

#10 durianlover

durianlover
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:03:16 AM

Posted 11 December 2007 - 07:17 PM

Thank you SO much!

You've been very helpful.

- Daniel

#11 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:16 PM

Posted 11 December 2007 - 07:47 PM

You're most welcome Daniel :thumbsup:

This thread will now be closed.
If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you.
Include the address of this thread in your request.
If you should have a new issue, please start a new topic.
This applies only to the original topic starter.
Everyone else please begin a New Topic.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users