This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Laptop sometimes hang on start up

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

BennyLCB, It's not important if it doesn't exist. If it does, it's infected and can re-infect the rest of your computer. Could it be a Thumb drive?
do u mean during the scan a tumb drive was placed in the usb? if yes, i did not have any tumb drive in the usb.. but i do use tumb drives for my assignment, movies etc..
BennyLCB,

What ever the J: drive is was not plugged in during the scan. Therefore, the contaminated files were not cleaned from it.

Please plug your thumb drive in and then look in My Computer. If it shows a J: drive DO NOT OPEN ANY OF THE FILES ON IT.

Let me know and we will re-run a partial script with the thumb drive installed so that we can clean it.
BennyLCB,

Please download Flash Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the
    utility to clean up those drives as well. Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that is plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

Then please give me a new HijackThis log.
oh ya, there's smthg i forgot to report to u.. since the 1st time i start using combofix, my sound card smtimes go undetected, no sound files can be played.. and i need to restart my laptop to get the sound back.. any way to fix it too? and 1 more thing. what is 'NMIndexingService.exe' from system? this .exe is causing my laptop to hang on startup, i comfirmed it by holding Ctrl+Alt+Del to see what process is causing the hang during start up.. and whenever its this .exe to load, it'll hang around 8/10 times.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:48:05 PM, on 3/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20583)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
E:\Program Files\QvodPlayer\QvodTerminal.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\User\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
E:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\QvodPlayer\QvodPlayer.exe
C:\WINDOWS\explorer.exe
E:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENMY/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - E:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ATI Tray Tools.lnk = E:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Qvod Terminal - Shenzhen QVOD Technology Co.,Ltd - E:\Program Files\QvodPlayer\QvodTerminal.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

–
End of file - 13050 bytes
BennyLCB,

NMIndexingService.exe is part of Nero. It works in the background to "index" all of your media files. It basically searches your drives for media files and then "writes down" where they are found at just in case you should want to access them with Nero. This is supposed to speed up access time but it can be a bit of a resource hog.

Worse than that is you are partially re-infected. Let's see if we can find out where that came from.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\WINDOWS\system32\olhrwef.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2 X86-based PC ( Multiprocessor Free : Genuine Intel® CPU T2300 @ 1.66GHz ) BIOS : Ver 1.00PARTTBLq USER : User ( Administrator ) BOOT : Normal boot Antivirus : AVG 7.5.557 7.5.557 (Activated) C:\ (Local Disk) - NTFS - Total:39 Go (Free:9 Go) D:\ (CD or DVD) E:\ (Local Disk) - NTFS - Total:35 Go (Free:7 Go) F:\ (CD or DVD) G:\ (CD or DVD) Sun 03/01/2009|22:59 ———————-\\ Search.. No infections found ! 1 - "C:\Rooter$\Rooter_1.txt" - Thu 02/19/2009|23:49 2 - "C:\Rooter$\Rooter_2.txt" - Sun 03/01/2009|23:00 ———————-\\ Scan completed at 23:00
ComboFix 09-02-17.02 - User 2009-03-02 7:27:05.13 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.68 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\worknow.com
Command switches used :: c:\docume~1\User\Desktop\CFScript.txt
AV: AVG 7.5.557 *On-access scanning enabled* (Updated)
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -

FILE ::
c:\windows\system32\olhrwef.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds1.dll
c:\windows\system32\olhrwef.exe

.
((((((((((((((((((((((((( Files Created from 2009-02-01 to 2009-03-01 )))))))))))))))))))))))))))))))
.

2009-02-23 04:53 . 2009-02-23 04:25 d——– c:\program files\EsetOnlineScanner
2009-02-23 04:50 . 2005-07-14 12:31 27,648 –a—— c:\windows\system32\AVSredirect.dll
2009-02-23 04:46 . 2008-06-19 16:24 28,544 –a—— c:\windows\system32\drivers\pavboot.sys
2009-02-23 04:45 . 2009-02-23 04:45 d——– c:\program files\Panda Security
2009-02-23 04:42 . 2009-02-23 04:28 108,843 -r-hs—- C:\gi2ky.exe
2009-02-23 04:36 . 2006-10-26 19:56 32,592 –a—— c:\windows\system32\msonpmon.dll
2009-02-23 04:33 . 2009-02-23 04:33 d——– c:\program files\Microsoft Works
2009-02-23 04:29 . 2009-02-23 04:29 d——– c:\program files\Microsoft.NET
2009-02-23 04:27 . 2009-02-13 17:26 108,565 -r-hs—- C:\ur0.com
2009-02-23 04:23 . 2009-02-23 04:41 d——– c:\program files\Microsoft Visual Studio 8
2009-02-23 04:21 . 2009-02-23 04:44 d——– c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-20 20:47 . 2009-02-20 20:47 d——– c:\windows\Sun
2009-02-20 07:01 . 2009-02-20 07:00 410,984 –a—— c:\windows\system32\deploytk.dll
2009-02-20 07:01 . 2009-02-20 07:00 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-02-20 07:00 . 2009-02-20 07:00 d——– c:\program files\Java
2009-02-19 23:48 . 2009-03-01 23:00 d——– C:\Rooter$
2009-02-15 11:08 . 2009-02-23 04:11 d——– C:\Download
2009-02-12 03:40 . 2009-02-23 05:08 d——– c:\program files\Star Downloader

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-01 06:32 ——— d—–w c:\program files\Messenger Plus! Live
2009-03-01 05:32 ——— d—–w c:\documents and settings\User\Application Data\AVG7
2009-02-22 21:04 ——— d—–w c:\documents and settings\User\Application Data\MegauploadToolbar
2009-02-22 20:32 ——— d—–w c:\program files\MSBuild
2009-02-22 20:23 ——— d—–w c:\program files\Garena
2009-02-16 17:04 ——— d—–w c:\documents and settings\User\Application Data\Hoyle Casino
2009-02-11 02:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 02:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-01-31 09:09 ——— d—–w c:\program files\MAIET
2009-01-28 16:59 ——— d—–w c:\program files\Valve
2009-01-28 11:54 ——— d—–w c:\documents and settings\User\Application Data\U3
2009-01-28 00:58 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-28 00:58 ——— d—–w c:\documents and settings\User\Application Data\InstallShield
2009-01-27 13:49 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-01-25 20:16 ——— d—–w c:\program files\AviSynth 2.5
2009-01-22 10:25 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2009-01-22 10:23 ——— d—–w c:\program files\Yahoo!
2009-01-22 10:23 ——— d—–w c:\documents and settings\User\Application Data\Yahoo!
2009-01-17 22:10 ——— d—–w c:\documents and settings\All Users\Application Data\avg7
2008-07-16 09:44 25,880 —-a-w c:\documents and settings\User\Application Data\GDIPFONTCACHEV1.DAT
2006-05-03 10:06 163,328 –sh–r c:\windows\system32\flvDX.dll
2007-02-21 11:47 31,232 –sh–r c:\windows\system32\msfDX.dll
2008-03-16 13:30 216,064 –sh–r c:\windows\system32\nbDX.dll
2008-03-06 11:41 16,384 –sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
2008-03-06 11:41 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2008-01-17 12:44 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008011720080118\index.dat
.

((((((((((((((((((((((((((((( SnapShot_2009-02-23_ 4.21.42.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-01 09:09:42 16,384 —-atw c:\windows\temp\Perflib_Perfdata_374.dat
+ 2009-03-01 09:11:25 16,384 —-atw c:\windows\temp\Perflib_Perfdata_e0c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-01-18 486856]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2007-07-22 1694208]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-01-08 4363504]
"cdoosoft"="c:\windows\system32\olhrwef.exe" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2007-07-22 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-11-30 225280]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"LogitechCameraAssistant"="c:\program files\Acer\OrbiCam\CameraAssistant.exe" [2005-11-29 438272]
"LogitechVideo[inspector]"="c:\program files\Acer\OrbiCam\InstallHelper.exe" [2005-11-29 14:51 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2005-11-28 569413]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2009-03-01 590848]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-27 185896]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-20 148888]
"GrooveMonitor"="e:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 c:\windows\RTHDCPL.exe]
"AtiPTA"="atiptaxx.exe" [2006-02-22 c:\windows\system32\atiptaxx.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-01-18 219136]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

c:\documents and settings\User\Start Menu\Programs\Startup\
ATI Tray Tools.lnk - e:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.exe [2008-01-01 570528]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-12-02 618557]
Microsoft Office.lnk - e:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.divxa32"= divxa32.acm

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"e:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"c:\\ijji\\ENGLISH\\u_gunz.exe"=
"c:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\Garena.exe"=
"c:\\ijji\\ENGLISH\\Gunz\\Gunz.exe"=
"e:\\Program Files\\QvodPlayer\\QvodTerminal.exe"=
"c:\\Program Files\\Counter-Strike\\cstrike.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23951:TCP"= 23951:TCP:BitComet 23951 TCP
"23951:UDP"= 23951:UDP:BitComet 23951 UDP
"12432:TCP"= 12432:TCP:BitComet 12432 TCP
"12432:UDP"= 12432:UDP:BitComet 12432 UDP
"23385:TCP"= 23385:TCP:BitComet 23385 TCP
"23385:UDP"= 23385:UDP:BitComet 23385 UDP
"9429:TCP"= 9429:TCP:BitComet 9429 TCP
"9429:UDP"= 9429:UDP:BitComet 9429 UDP
"38215:TCP"= 38215:TCP:*:Disabled:SolidNetworkManager
"38215:UDP"= 38215:UDP:*:Disabled:SolidNetworkManager
"41330:TCP"= 41330:TCP:*:Disabled:SolidNetworkManager
"41330:UDP"= 41330:UDP:*:Disabled:SolidNetworkManager
"31799:TCP"= 31799:TCP:*:Disabled:SolidNetworkManager
"31799:UDP"= 31799:UDP:*:Disabled:SolidNetworkManager
"16853:TCP"= 16853:TCP:NortonAV
"13227:TCP"= 13227:TCP:NortonAV
"13279:TCP"= 13279:TCP:NortonAV
"17629:TCP"= 17629:TCP:NortonAV
"18181:TCP"= 18181:TCP:NortonAV
"1:TCP"= 1:TCP:Bitcomet
"16973:TCP"= 16973:TCP:NortonAV
"13951:TCP"= 13951:TCP:NortonAV
"14895:TCP"= 14895:TCP:NortonAV
"16601:TCP"= 16601:TCP:NortonAV
"15531:TCP"= 15531:TCP:NortonAV
"13258:TCP"= 13258:TCP:NortonAV
"12225:TCP"= 12225:TCP:NortonAV
"16331:TCP"= 16331:TCP:NortonAV
"15813:TCP"= 15813:TCP:NortonAV
"16983:TCP"= 16983:TCP:NortonAV
"3876:TCP"= 3876:TCP:igcpxf

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-02-23 28544]
R1 atitray;atitray;e:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [2008-01-28 17952]
R2 Qvod Terminal;Qvod Terminal;e:\program files\QvodPlayer\QvodTerminal.exe [2008-12-11 499712]
R3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [2008-01-17 1088896]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S3 dump_wmimmc;dump_wmimmc;\??\e:\runup_my\Luna\GameGuard\dump_wmimmc.sys –> e:\runup_my\Luna\GameGuard\dump_wmimmc.sys [?]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys –> c:\windows\system32\XDva037.sys [?]
S3 XDva104;XDva104;\??\c:\windows\system32\XDva104.sys –> c:\windows\system32\XDva104.sys [?]
S3 XDva170;XDva170;\??\c:\windows\system32\XDva170.sys –> c:\windows\system32\XDva170.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c1ecf76-f9df-11dd-b49f-001302017674}]
\Shell\AutoRun\command - H:\ur0.com
\Shell\open\Command - H:\ur0.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c1ecf77-f9df-11dd-b49f-001302017674}]
\Shell\AutoRun\command - I:\ur0.com
\Shell\open\Command - I:\ur0.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dfc78c34-eb16-11dd-b45d-001302017674}]
\Shell\AutoRun\command - H:\svdioajm.cmd
\Shell\explore\Command - H:\svdioajm.cmd
\Shell\open\Command - H:\svdioajm.cmd
.
Contents of the 'Scheduled Tasks' folder

2009-03-01 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 17:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
IE: &Clean; Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download; with &DAP; - c:\program files\DAP\dapextie.htm
IE: &Windows; Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: Download &all; with DAP - c:\program files\DAP\dapextie2.htm
IE: Download with Star Downloader - c:\program files\Star Downloader\sdie.htm
IE: E&xport; to Microsoft Excel - e:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\y27yfeav.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - component: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\y27yfeav.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\y27yfeav.default\extensions\[removed]\plugins\npssn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npstar.dll
FF - plugin: e:\program files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll
FF - plugin: e:\program files\Opera\program\plugins\npdsplay.dll
FF - plugin: e:\program files\Opera\program\plugins\NPOFF12.DLL
FF - plugin: e:\program files\Opera\program\plugins\npwmsdrm.dll
FF - plugin: e:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: e:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: e:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-02 07:32:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1409082233-1303643608-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1409082233-1303643608-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:73,62,4d,f4,25,e1,de,8b,65,c7,c1,1e,96,ce,3a,3f,ba,03,87,85,e5,7f,d4,
ec,a3,c9,dd,0e,c4,3a,ff,e9,fe,56,8c,1b,c0,ce,13,4c,ee,46,dd,af,9f,11,02,bb,\
"??"=hex:38,a8,d2,55,76,02,c1,cd,82,c5,05,9c,7c,de,e1,d1
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(944)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe
c:\progra~1\Grisoft\AVG7\avgamsvr.exe
c:\progra~1\Grisoft\AVG7\avgupsvc.exe
c:\progra~1\Grisoft\AVG7\avgemc.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\docume~1\User\LOCALS~1\temp\RtkBtMnt.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-03-02 7:35:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-01 23:35:12
ComboFix2.txt 2009-02-19 22:07:21
ComboFix3.txt 2009-02-19 15:57:58
ComboFix4.txt 2008-11-03 15:18:54
ComboFix5.txt 2009-02-22 20:23:11

Pre-Run: 9,857,200,128 bytes free
Post-Run: 9,855,688,704 bytes free

292


sry for delay.. was in a rush this morning..
BennyLCB,

It looks like you were recontaminated by your flash drive. Did you run Flash Disninfector on it?

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\gi2ky.exe
    C:\ur0.com
    c:\windows\system32\olhrwef.exe
    H:\ur0.com
    I:\ur0.com
    H:\svdioajm.cmd
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "cdoosoft"=-
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c1ecf76-f9df-11dd-b49f-001302017674}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dfc78c34-eb16-11dd-b45d-001302017674}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
ComboFix 09-02-17.02 - User 2009-03-02 15:16:21.14 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.93 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\worknow.com
Command switches used :: c:\docume~1\User\Desktop\CFScript.txt
AV: AVG 7.5.557 *On-access scanning enabled* (Updated)
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -

FILE ::
C:\gi2ky.exe
C:\ur0.com
c:\windows\system32\olhrwef.exe
H:\svdioajm.cmd
H:\ur0.com
I:\ur0.com
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\gi2ky.exe
C:\ur0.com
H:\svdioajm.cmd

.
((((((((((((((((((((((((( Files Created from 2009-02-02 to 2009-03-02 )))))))))))))))))))))))))))))))
.

2009-02-23 04:53 . 2009-02-23 04:25 d——– c:\program files\EsetOnlineScanner
2009-02-23 04:50 . 2005-07-14 12:31 27,648 –a—— c:\windows\system32\AVSredirect.dll
2009-02-23 04:46 . 2008-06-19 16:24 28,544 –a—— c:\windows\system32\drivers\pavboot.sys
2009-02-23 04:45 . 2009-02-23 04:45 d——– c:\program files\Panda Security
2009-02-23 04:36 . 2006-10-26 19:56 32,592 –a—— c:\windows\system32\msonpmon.dll
2009-02-23 04:33 . 2009-02-23 04:33 d——– c:\program files\Microsoft Works
2009-02-23 04:29 . 2009-02-23 04:29 d——– c:\program files\Microsoft.NET
2009-02-23 04:23 . 2009-02-23 04:41 d——– c:\program files\Microsoft Visual Studio 8
2009-02-23 04:21 . 2009-02-23 04:44 d——– c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-20 20:47 . 2009-02-20 20:47 d——– c:\windows\Sun
2009-02-20 07:01 . 2009-02-20 07:00 410,984 –a—— c:\windows\system32\deploytk.dll
2009-02-20 07:01 . 2009-02-20 07:00 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-02-20 07:00 . 2009-02-20 07:00 d——– c:\program files\Java
2009-02-19 23:48 . 2009-03-01 23:00 d——– C:\Rooter$
2009-02-15 11:08 . 2009-02-23 04:11 d——– C:\Download
2009-02-12 03:40 . 2009-02-23 05:08 d——– c:\program files\Star Downloader

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-02 07:07 ——— d—–w c:\documents and settings\User\Application Data\AVG7
2009-03-01 06:32 ——— d—–w c:\program files\Messenger Plus! Live
2009-02-22 21:04 ——— d—–w c:\documents and settings\User\Application Data\MegauploadToolbar
2009-02-22 20:32 ——— d—–w c:\program files\MSBuild
2009-02-22 20:23 ——— d—–w c:\program files\Garena
2009-02-16 17:04 ——— d—–w c:\documents and settings\User\Application Data\Hoyle Casino
2009-02-11 02:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 02:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-01-31 09:09 ——— d—–w c:\program files\MAIET
2009-01-28 16:59 ——— d—–w c:\program files\Valve
2009-01-28 11:54 ——— d—–w c:\documents and settings\User\Application Data\U3
2009-01-28 00:58 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-28 00:58 ——— d—–w c:\documents and settings\User\Application Data\InstallShield
2009-01-27 13:49 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-01-25 20:16 ——— d—–w c:\program files\AviSynth 2.5
2009-01-22 10:25 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2009-01-22 10:23 ——— d—–w c:\program files\Yahoo!
2009-01-22 10:23 ——— d—–w c:\documents and settings\User\Application Data\Yahoo!
2009-01-17 22:10 ——— d—–w c:\documents and settings\All Users\Application Data\avg7
2008-07-16 09:44 25,880 —-a-w c:\documents and settings\User\Application Data\GDIPFONTCACHEV1.DAT
2006-05-03 10:06 163,328 –sh–r c:\windows\system32\flvDX.dll
2007-02-21 11:47 31,232 –sh–r c:\windows\system32\msfDX.dll
2008-03-16 13:30 216,064 –sh–r c:\windows\system32\nbDX.dll
2008-03-06 11:41 16,384 –sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
2008-03-06 11:41 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2008-01-17 12:44 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008011720080118\index.dat
.

((((((((((((((((((((((((((((( SnapShot_2009-02-23_ 4.21.42.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-02 07:06:48 16,384 —-atw c:\windows\temp\Perflib_Perfdata_6f4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-01-18 486856]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2007-07-22 1694208]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-01-08 4363504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2007-07-22 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-11-30 225280]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"LogitechCameraAssistant"="c:\program files\Acer\OrbiCam\CameraAssistant.exe" [2005-11-29 438272]
"LogitechVideo[inspector]"="c:\program files\Acer\OrbiCam\InstallHelper.exe" [2005-11-29 14:51 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2005-11-28 569413]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2009-03-01 590848]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-27 185896]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-20 148888]
"GrooveMonitor"="e:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 c:\windows\RTHDCPL.exe]
"AtiPTA"="atiptaxx.exe" [2006-02-22 c:\windows\system32\atiptaxx.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-01-18 219136]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

c:\documents and settings\User\Start Menu\Programs\Startup\
ATI Tray Tools.lnk - e:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.exe [2008-01-01 570528]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-12-02 618557]
Microsoft Office.lnk - e:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.divxa32"= divxa32.acm

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"e:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"c:\\ijji\\ENGLISH\\u_gunz.exe"=
"c:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\Garena.exe"=
"c:\\ijji\\ENGLISH\\Gunz\\Gunz.exe"=
"e:\\Program Files\\QvodPlayer\\QvodTerminal.exe"=
"c:\\Program Files\\Counter-Strike\\cstrike.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23951:TCP"= 23951:TCP:BitComet 23951 TCP
"23951:UDP"= 23951:UDP:BitComet 23951 UDP
"12432:TCP"= 12432:TCP:BitComet 12432 TCP
"12432:UDP"= 12432:UDP:BitComet 12432 UDP
"23385:TCP"= 23385:TCP:BitComet 23385 TCP
"23385:UDP"= 23385:UDP:BitComet 23385 UDP
"9429:TCP"= 9429:TCP:BitComet 9429 TCP
"9429:UDP"= 9429:UDP:BitComet 9429 UDP
"38215:TCP"= 38215:TCP:*:Disabled:SolidNetworkManager
"38215:UDP"= 38215:UDP:*:Disabled:SolidNetworkManager
"41330:TCP"= 41330:TCP:*:Disabled:SolidNetworkManager
"41330:UDP"= 41330:UDP:*:Disabled:SolidNetworkManager
"31799:TCP"= 31799:TCP:*:Disabled:SolidNetworkManager
"31799:UDP"= 31799:UDP:*:Disabled:SolidNetworkManager
"16853:TCP"= 16853:TCP:NortonAV
"13227:TCP"= 13227:TCP:NortonAV
"13279:TCP"= 13279:TCP:NortonAV
"17629:TCP"= 17629:TCP:NortonAV
"18181:TCP"= 18181:TCP:NortonAV
"1:TCP"= 1:TCP:Bitcomet
"16973:TCP"= 16973:TCP:NortonAV
"13951:TCP"= 13951:TCP:NortonAV
"14895:TCP"= 14895:TCP:NortonAV
"16601:TCP"= 16601:TCP:NortonAV
"15531:TCP"= 15531:TCP:NortonAV
"13258:TCP"= 13258:TCP:NortonAV
"12225:TCP"= 12225:TCP:NortonAV
"16331:TCP"= 16331:TCP:NortonAV
"15813:TCP"= 15813:TCP:NortonAV
"16983:TCP"= 16983:TCP:NortonAV
"3876:TCP"= 3876:TCP:igcpxf

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-02-23 28544]
R1 atitray;atitray;e:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [2008-01-28 17952]
R2 Qvod Terminal;Qvod Terminal;e:\program files\QvodPlayer\QvodTerminal.exe [2008-12-11 499712]
R3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [2008-01-17 1088896]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S3 dump_wmimmc;dump_wmimmc;\??\e:\runup_my\Luna\GameGuard\dump_wmimmc.sys –> e:\runup_my\Luna\GameGuard\dump_wmimmc.sys [?]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys –> c:\windows\system32\XDva037.sys [?]
S3 XDva104;XDva104;\??\c:\windows\system32\XDva104.sys –> c:\windows\system32\XDva104.sys [?]
S3 XDva170;XDva170;\??\c:\windows\system32\XDva170.sys –> c:\windows\system32\XDva170.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c1ecf77-f9df-11dd-b49f-001302017674}]
\Shell\AutoRun\command - I:\ur0.com
\Shell\open\Command - I:\ur0.com
.
Contents of the 'Scheduled Tasks' folder

2009-03-02 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 17:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
IE: &Clean; Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download; with &DAP; - c:\program files\DAP\dapextie.htm
IE: &Windows; Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: Download &all; with DAP - c:\program files\DAP\dapextie2.htm
IE: Download with Star Downloader - c:\program files\Star Downloader\sdie.htm
IE: E&xport; to Microsoft Excel - e:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-02 15:16:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1409082233-1303643608-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1409082233-1303643608-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:73,62,4d,f4,25,e1,de,8b,65,c7,c1,1e,96,ce,3a,3f,ba,03,87,85,e5,7f,d4,
ec,a3,c9,dd,0e,c4,3a,ff,e9,fe,56,8c,1b,c0,ce,13,4c,ee,46,dd,af,9f,11,02,bb,\
"??"=hex:38,a8,d2,55,76,02,c1,cd,82,c5,05,9c,7c,de,e1,d1
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(940)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-03-02 15:18:41
ComboFix-quarantined-files.txt 2009-03-02 07:18:35
ComboFix2.txt 2009-03-01 23:35:19
ComboFix3.txt 2009-02-19 22:07:21
ComboFix4.txt 2009-02-19 15:57:58
ComboFix5.txt 2009-03-02 07:15:35

Pre-Run: 9,765,490,688 bytes free
Post-Run: 9,755,521,024 bytes free

246
tomk, i cant use kaspersky for some reason, im using panda activescan instead.. is it ok? here's the log.. ;******************************************************************************* ********************************************************************************* ******************* ANALYSIS: 2009-03-03 15:15:35 PROTECTIONS: 1 MALWARE: 32 SUSPECTS: 0 ;******************************************************************************* ********************************************************************************* ******************* PROTECTIONS Description Version Active Updated ;=============================================================================== ================================================================================= =================== AVG 7.5.557 7.5.557 Yes Yes ;=============================================================================== ================================================================================= =================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=============================================================================== ================================================================================= =================== 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\User\Cookies\user@doubleclick[1].txt 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\User\Cookies\user@atdmt[2].txt 00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\User\Cookies\user@mediaplex[1].txt 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\User\Cookies\user@serving-sys[1].txt 00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\User\Cookies\[removed]-sys[2].txt 00366244 Application/NirCmd.A HackTools No 0 No No C:\Documents and Settings\User\Desktop\Virus fix\Flash_Disinfector.exe[C:\Documents and Settings\User\Desktop\Virus fix\Flash_Disinfector.exe][nircmd.exe] 00390584 W32/Gamania.gen Virus No 0 Yes No C:\Qoobox\Quarantine\H\svdioajm.cmd.vir 00390584 W32/Gamania.gen Virus No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000023.exe 00390584 W32/Gamania.gen Virus No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000024.dll 00390584 W32/Gamania.gen Virus No 0 Yes No C:\Qoobox\Quarantine\C\1rfw8hjr.com.vir 00390584 W32/Gamania.gen Virus No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000030.cmd 00390584 W32/Gamania.gen Virus No 0 Yes No C:\Qoobox\Quarantine\C\svdioajm.cmd.vir 00390584 W32/Gamania.gen Virus No 0 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000035.cmd 00390584 W32/Gamania.gen Virus No 0 Yes No C:\Qoobox\Quarantine\E\1rfw8hjr.com.vir 00390584 W32/Gamania.gen Virus No 0 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\ckvo.exe.vir 00390584 W32/Gamania.gen Virus No 0 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\ckvo0.dll.vir 00390584 W32/Gamania.gen Virus No 0 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\ckvo1.dll.vir 00390584 W32/Gamania.gen Virus No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000025.dll 00390584 W32/Gamania.gen Virus No 0 Yes No C:\Qoobox\Quarantine\E\svdioajm.cmd.vir 00429440 W32/Lineage.KAJ.worm Virus/Trojan No 1 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\ckvo2.dll.vir 00429441 W32/Lineage.KAJ.worm Virus/Trojan No 1 Yes No C:\Qoobox\Quarantine\E\av11.zip[Qoobox/Quarantine/E/xlk9.com.vir] 00429441 W32/Lineage.KAJ.worm Virus/Trojan No 1 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP18\A0002449.com 00429441 W32/Lineage.KAJ.worm Virus/Trojan No 1 Yes No C:\Qoobox\Quarantine\C\xlk9.com.vir 00432608 W32/Lineage.KAY.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\C\autorun.inf.vir 00432608 W32/Lineage.KAY.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\E\autorun.inf.vir 00439042 W32/Lineage.KAY.worm Virus/Worm No 1 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000036.cmd 00439042 W32/Lineage.KAY.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\E\xih9.cmd.vir 00439042 W32/Lineage.KAY.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\C\xih9.cmd.vir 00443985 W32/Lineage.KDD Virus/Worm No 1 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000033.cmd 00443985 W32/Lineage.KDD Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\E\nq0cq.cmd.vir 00444033 W32/Autorun.ALJ.worm Virus/Worm No 1 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP18\A0002448.com 00444033 W32/Autorun.ALJ.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\C\whi.com.vir 00444033 W32/Autorun.ALJ.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\E\av11.zip[Qoobox/Quarantine/E/whi.com.vir] 00444033 W32/Autorun.ALJ.worm Virus/Worm No 1 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP18\A0002442.com 00445556 W32/Lineage.KDJ Virus No 0 Yes No C:\Qoobox\Quarantine\C\sq.com.vir 00445556 W32/Lineage.KDJ Virus No 0 Yes No C:\Qoobox\Quarantine\E\sq.com.vir 00445556 W32/Lineage.KDJ Virus No 0 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000034.com 00445556 W32/Lineage.KDJ Virus No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000022.com 00531079 W32/Autorun.AQG.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\msqpdxrwallywq.dll.vir 00531079 W32/Autorun.AQG.worm Virus/Worm No 1 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000002.dll 00534172 Rootkit/Conficker.C Virus/Worm No 0 Yes No C:\Qoobox\Quarantine\[4]-[removed][02.tmp] 00534172 Rootkit/Conficker.C Virus/Worm No 0 Yes No C:\Qoobox\Quarantine\[4]-[removed][03.tmp] 00534172 Rootkit/Conficker.C Virus/Worm No 0 Yes No C:\Qoobox\Quarantine\[4]-[removed][01.tmp] 00534172 Rootkit/Conficker.C Virus/Worm No 0 Yes No C:\Qoobox\Quarantine\[4]-[removed][04.tmp] 00534496 W32/Conficker.C.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\[4]-[removed][cgnmgrks.dll] 00585524 W32/Lineage.KMF.worm Virus/Worm No 1 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000031.bat 00585524 W32/Lineage.KMF.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\C\1utbfd.bat.vir 00585524 W32/Lineage.KMF.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\E\1utbfd.bat.vir 00585524 W32/Lineage.KMF.worm Virus/Worm No 1 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000020.bat 00586395 W32/Lineage.KNK.worm Virus/Worm No 1 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000032.exe 00586395 W32/Lineage.KNK.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\E\2aaxaiy.exe.vir 00586395 W32/Lineage.KNK.worm Virus/Worm No 1 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000021.exe 00586395 W32/Lineage.KNK.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\C\2aaxaiy.exe.vir 00587511 W32/Lineage.KMF.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\E\av11.zip[Qoobox/Quarantine/E/opgde.exe.vir] 00587511 W32/Lineage.KMF.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\[4]-[removed][opgde.exe] 00587511 W32/Lineage.KMF.worm Virus/Worm No 1 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP18\A0002445.exe 00594518 W32/Lineage.KFS Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\C\ur0.com.vir 00594518 W32/Lineage.KFS Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\[4]-[removed][ur0.com] 00594518 W32/Lineage.KFS Virus/Worm No 1 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP18\A0002447.com 00594518 W32/Lineage.KFS Virus/Worm No 1 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP25\A0015972.com 00594518 W32/Lineage.KFS Virus/Worm No 1 Yes No E:\ur0.com 00594518 W32/Lineage.KFS Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\E\av11.zip[Qoobox/Quarantine/E/ur0.com.vir] 00595867 W32/Lineage.KNS Virus No 0 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP18\A0002446.com 00595867 W32/Lineage.KNS Virus No 0 Yes No C:\Qoobox\Quarantine\[4]-[removed][qphdin.com] 00595867 W32/Lineage.KNS Virus No 0 Yes No C:\Qoobox\Quarantine\E\av11.zip[Qoobox/Quarantine/E/qphdin.com.vir] 00598764 W32/Lineage.KNV Virus No 0 Yes No C:\Qoobox\Quarantine\[4]-[removed][hyetn1i.exe] 00598764 W32/Lineage.KNV Virus No 0 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP18\A0002444.exe 00598764 W32/Lineage.KNV Virus No 0 Yes No C:\Qoobox\Quarantine\E\av11.zip[Qoobox/Quarantine/E/hyetn1i.exe.vir] 00599130 W32/Lineage.KNV.worm Virus/Worm No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP22\A0004599.dll 00602363 W32/Lineage.KNV.worm Virus/Worm No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000026.dll 00602363 W32/Lineage.KNV.worm Virus/Worm No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000027.dll 00602372 W32/Lineage.KNV Virus No 0 Yes No C:\Qoobox\Quarantine\E\av11.zip[Qoobox/Quarantine/E/cv22.cmd.vir] 00602372 W32/Lineage.KNV Virus No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000028.exe 00602372 W32/Lineage.KNV Virus No 0 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP18\A0002443.cmd 00602372 W32/Lineage.KNV Virus No 0 Yes No C:\Qoobox\Quarantine\[4]-[removed][cv22.cmd] 01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP24\A0015793.EXE 01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP18\A0002482.EXE 01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP4\A0001338.EXE 02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP3\A0001282.sys 02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP18\A0002457.sys 02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP0\A0000003.sys 02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP4\A0001310.sys 02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP24\A0015770.sys 03931361 Generic Trojan Virus/Trojan No 0 No No C:\Qoobox\Quarantine\E\av11.zip[Qoobox/Quarantine/E/App/Witcobber_RM_to_AVI_MPEG_WMV_VCD_SVCD_DVD_Converter.rar.vir][Witcobber RM to AVI MPEG WMV VCD SVCD DVD Converter\SuperRmtoAlKeygen.exe] 04199562 Generic Trojan Virus/Trojan No 0 No No C:\Qoobox\Quarantine\C\Documents and Settings\User\Desktop\5800\Smartphoneware Best Reminder v1.0.S60v5.SymbianOS9.4.Incl Keygen-HSpda.rar.vir[Smartphoneware Best Reminder v1.0.S60v5.SymbianOS9 .4.Incl Keygen-HSpda\keygen.exe] 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP24\A0015762.dll 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\nmdfgds1.dll.vir 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP24\A0015763.dll 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\nmdfgds0.dll.vir 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP23\A0015714.dll 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP22\A0005601.dll 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP23\A0014715.dll 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP23\A0006648.dll 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP23\A0009648.dll 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP23\A0012649.dll 05089776 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP23\A0007647.dll 05089791 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP23\A0012652.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No E:\gi2ky.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP22\A0002607.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP23\A0015715.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP24\A0015748.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP25\A0015971.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP24\A0015764.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\gi2ky.exe.vir 05089791 Generic Malware Virus/Trojan No 0 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP22\A0002608.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP23\A0012653.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP23\A0015716.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No E:\System Volume Information\_restore{CDC7DCBA-C0C5-4C4B-B2C4-A8C704604870}\RP24\A0015749.exe 05089791 Generic Malware Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\olhrwef.exe.vir ;=============================================================================== ================================================================================= =================== SUSPECTS Sent Location ;=============================================================================== ================================================================================= =================== ;=============================================================================== ================================================================================= =================== VULNERABILITIES Id Severity Description ;=============================================================================== ================================================================================= =================== 184380 MEDIUM MS08-002 184379 MEDIUM MS08-001 182048 HIGH MS07-069 182046 HIGH MS07-067 182043 HIGH MS07-064 179553 HIGH MS07-061 176382 HIGH MS07-057 176383 HIGH MS07-058 170911 HIGH MS07-050 170907 HIGH MS07-046 170906 HIGH MS07-045 170904 HIGH MS07-043 150243 HIGH MS07-008 126087 HIGH MS06-046 120825 MEDIUM MS06-032 120823 MEDIUM MS06-030 108743 MEDIUM MS06-007 93394 HIGH MS05-050 93454 MEDIUM MS05-049 ;=============================================================================== ================================================================================= ===================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:18:04 PM, on 3/3/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20583)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
E:\Program Files\QvodPlayer\QvodTerminal.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\DOCUME~1\User\LOCALS~1\Temp\RtkBtMnt.exe
E:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\usnsvc.exe
E:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENMY/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - E:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ATI Tray Tools.lnk = E:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Qvod Terminal - Shenzhen QVOD Technology Co.,Ltd - E:\Program Files\QvodPlayer\QvodTerminal.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

–
End of file - 12884 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI