This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] How do I update HJT without internet access?

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Katsrock,

We seem to have cross posted, I didn't see your edit. Looks like they changed the heading in the newer version of FireFox , but you found the right one. :thumbup:

I'll have you do an online scan.

Panda Active Scan

  • Once you are on the Panda site, click the Scan now button
  • Panda Active scan will detect that you are using Firefox and have you install a plug. Follow the steps as prompted.
  • When prompted to install ActiveX control click Install
  • On the update page, click on the security warning at the top of the page and select "Run ActiveX control…"
  • Panda should now start scanning your system.
  • When the scan completes, if anything malicious is detected, click the Export To…(with a little notepad icon) button, then Save the report to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log. Let me know how things are running now.

Thanks
Hello oldman960,

Sorry about the edits, but I was trying things I knew you needed to know about after the initial post.

Here is the Panda and HJT logs:

;*******************************************************************************
*********************************************************************************
*******************
ANALYSIS: 2009-03-14 18:02:58
PROTECTIONS: 1
MALWARE: 11
SUSPECTS: 3
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
AVG 7.5.557 7.5.557 No Yes
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
00039204 adware/cws Adware No 0 Yes No c:\documents and settings\owner\favorites\health
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\vuoqfaaa.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\vukqecoh.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\peubaaaa.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\mxgmaewo.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\jkvkwixb.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\jkuxiswy.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\jkfoaaaa.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\jkbxlaaa.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\gpyfaaaa.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\gpvoujuc.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\gprigxfg.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\gpkceaaa.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\gpgyycra.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\aexctaaa.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\aeqnaaaa.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\aenrnjwo.exe
00330974 Trj/Cimuz.BP Virus/Trojan No 0 Yes No C:\WINNT\system32\vuprucbt.exe
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000088.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000089.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000090.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000091.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000092.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000093.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000094.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000095.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000096.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000097.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000098.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000099.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000100.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000102.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000103.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000104.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000105.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000107.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000108.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000109.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000110.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000111.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000113.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000114.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000115.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000116.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000117.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000118.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000120.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000121.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000122.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000123.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000124.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000125.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000126.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000127.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000128.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000129.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000130.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000131.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000132.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000133.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000135.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000136.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000137.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000139.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000140.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000143.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000144.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000145.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000146.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000147.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000149.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000150.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000152.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000153.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000154.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000155.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000156.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000158.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000159.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000161.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000162.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000163.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000164.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000165.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000166.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000167.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000168.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000169.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000170.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000171.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000172.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000173.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000174.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000175.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000176.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000177.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000178.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000179.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000180.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000181.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000183.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000184.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000185.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000186.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000187.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000188.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000189.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000190.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000191.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000192.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000193.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000195.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000196.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000198.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000199.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000200.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000201.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000202.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000203.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000204.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000087.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000207.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000208.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000210.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000211.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000212.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000213.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000214.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000215.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000216.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000217.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000218.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000219.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000220.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000221.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000222.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000223.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000224.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000225.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000226.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000227.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000228.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000229.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000231.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000232.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000233.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000234.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000235.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000236.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000237.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000238.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000239.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000240.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000242.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000243.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000245.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000246.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000247.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000248.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000249.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000250.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000252.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000253.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000254.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000255.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000256.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000257.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000258.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000259.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000260.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000261.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000262.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000263.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000264.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000265.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000266.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000267.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000268.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000270.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000271.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000272.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000273.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000275.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000276.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000277.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000278.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000279.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000280.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000281.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000282.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000283.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000284.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000285.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000286.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000287.exe
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000288.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000290.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000291.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000292.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000294.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000295.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000296.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000297.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000298.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000301.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000302.exe
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000303.DLL
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000304.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000306.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000307.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000308.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000309.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000311.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000312.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000313.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000314.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000315.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000316.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000317.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000318.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000319.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000320.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000078.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000079.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000086.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000085.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000084.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000083.dll
00447834 Adware/Lop Adware No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000206.dll
01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP10\A0002079.EXE
01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP10\A0002050.EXE
02426945 Bck/IRCFlood.CW Virus/Trojan No 0 Yes No C:\Program Files\BestDayTrader Chat Room\mirc.exe
02717487 Adware/LinkOptimizer Adware No 0 Yes No C:\Qoobox\Quarantine\C\WINNT\genjc1.dll.vir
02763634 Trj/ClassLoader.AH Virus/Trojan No 0 Yes No C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\52\7e615cf4-107e9062[VaannnaaBaa.class]
02763635 Trj/ClassLoader.AH Virus/Trojan No 0 Yes No C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\52\7e615cf4-107e9062[Bnnnnn.class]
02763636 Trj/ClassLoader.AH Virus/Trojan No 0 Yes No C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\52\7e615cf4-107e9062[BnnnnBaa.class]
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP10\A0002056.sys
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP6\A0000728.sys
03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\Program Files\smitRem.exe
03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\Documents and Settings\Owner\Desktop\smitRem.exe
03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\Documents and Settings\Owner\My Documents\Yahoo Store\ezinetactics.exe
;===============================================================================
=================================================================================
===================
SUSPECTS
Sent Location ¤
;===============================================================================
=================================================================================
===================
No C:\Documents and Settings\Owner\My Documents\ComboFix.exe ¤
No C:\Program Files\MBTrading\MBT Navigator\AtYourService.exe ¤
No C:\WINNT\system32\dpnldown.exe ¤
;===============================================================================
=================================================================================
===================
VULNERABILITIES
Id Severity Description ¤
;===============================================================================
=================================================================================
===================
;===============================================================================
=================================================================================
===================






HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:04:31 PM, on 3/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\explorer.exe
C:\WINNT\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: KTBho Class - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O2 - BHO: XBTB05988 - {5C43B8A2-24E8-4336-B86E-A94558E10C60} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Kaboodle Toolbar - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O3 - Toolbar: Blue Dot Toolbar - {2751F3AD-5600-44cc-A653-8A24CAE5AF6D} - C:\Program Files\Blue Dot Toolbar\bdtool.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [HP Component Manager] "c:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: searchle it! - {0376FDB9-A132-4929-8336-8CB3B2CAFCC0} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles2.js (HKCU)
O9 - Extra button: my!searchles - {3B72BA76-67BE-11DB-8373-B622A1EF5492} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles.js (HKCU)
O16 - DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} (RegUserCfgUI Class) - http://us.dl1.yimg.com/download.yahoo.com/…_1/yregucfg.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1165704139859
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SentinelProtectionServer - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

–
End of file - 7868 bytes


Thanks.
Hi Katsrock,

No problem, I'll make sure to check before I post. Some forum's software will warn you that a new/edited post has been made. :)

You have a very old program installed, ewido security suite. It's not doing you any good. I suggest you uninstall it. We can replace it with a more current program after we are done.



Open hijackthis, do a system scan only and checkmark these lines, if present

O2 - BHO: XBTB05988 - {5C43B8A2-24E8-4336-B86E-A94558E10C60} - (no file)


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



We'll use combofix again.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text (including the URL) in the code box below into the Notepad. Do Not copy the word CODE

http://forums.whatthetech.com/How_do_I_update_HJT_without_internet_access_t100742.html&st=30

Collect::[4]
C:\WINNT\system32\vuoqfaaa.exe
C:\WINNT\system32\vukqecoh.exe
C:\WINNT\system32\peubaaaa.exe
C:\WINNT\system32\mxgmaewo.exe
C:\WINNT\system32\jkvkwixb.exe
C:\WINNT\system32\jkuxiswy.exe
C:\WINNT\system32\jkfoaaaa.exe
C:\WINNT\system32\jkbxlaaa.exe
C:\WINNT\system32\gpyfaaaa.exe
C:\WINNT\system32\gpvoujuc.exe
C:\WINNT\system32\gprigxfg.exe
C:\WINNT\system32\gpkceaaa.exe
C:\WINNT\system32\gpgyycra.exe
C:\WINNT\system32\aeqnaaaa.exe
C:\WINNT\system32\aenrnjwo.exe
C:\WINNT\system32\vuprucbt.exe
C:\WINNT\system32\vuprucbt.exe
C:\WINNT\system32\aexctaaa.exe

File::
C:\Documents and Settings\Owner\My Documents\Yahoo Store\ezinetactics.exe

DirLook::
c:\documents and settings\owner\favorites\health

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
Ensure you are connected to the internet and click OK on the message box.



You have some old vulnerable versions of java on your computer. You may want to copy and paste the instructions for this tool into a notepad and save to your desktop for reference as your browser should be closed.

Please download JavaRa to your desktop and unzip it to its own folder. Close your browser.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
The current version is Java™ 6 Update 12


Post back with the combofix log and a new HJT log.

Thanks
Hello oldman960, I won't be able to access the infected computer for several days. I will send you a note in a few days with your new instructions completed. Thanks.
Hello oldman960,

I'm back and have completed your instructions. Ewido has been removed. The BHO has been removed. I will redo Java shortly. In the meantime, here are the new logs:

ComboFix Log:

ComboFix 09-03-19.02 - Owner 2009-03-21 19:55:29.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.176 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: AVG 7.5.557 *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\documents and settings\Owner\My Documents\Yahoo Store\ezinetactics.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\My Documents\Yahoo Store\ezinetactics.exe
c:\winnt\system32\aenrnjwo.exe
c:\winnt\system32\aeqnaaaa.exe
c:\winnt\system32\aexctaaa.exe
c:\winnt\system32\gpgyycra.exe
c:\winnt\system32\gpkceaaa.exe
c:\winnt\system32\gprigxfg.exe
c:\winnt\system32\gpvoujuc.exe
c:\winnt\system32\gpyfaaaa.exe
c:\winnt\system32\jkbxlaaa.exe
c:\winnt\system32\jkfoaaaa.exe
c:\winnt\system32\jkuxiswy.exe
c:\winnt\system32\jkvkwixb.exe
c:\winnt\system32\mxgmaewo.exe
c:\winnt\system32\peubaaaa.exe
c:\winnt\system32\vukqecoh.exe
c:\winnt\system32\vuoqfaaa.exe
c:\winnt\system32\vuprucbt.exe

.
((((((((((((((((((((((((( Files Created from 2009-02-22 to 2009-03-22 )))))))))))))))))))))))))))))))
.

2009-03-14 14:17 . 2009-03-14 14:17 d——– c:\program files\Panda Security
2009-03-14 14:17 . 2008-06-19 16:24 28,544 –a—— c:\winnt\system32\drivers\pavboot.sys
2009-03-10 20:01 . 2009-03-10 19:52 512,614 –a—— C:\HaxFix.exe
2009-03-10 13:13 . 2009-03-10 13:16 d——– C:\Rooter$
2009-03-10 01:41 . 2009-03-10 01:41 d——– c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-09 23:38 . 2009-03-09 23:38 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-09 23:38 . 2009-03-09 23:38 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2009-03-09 23:38 . 2009-03-09 23:38 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-09 23:38 . 2009-02-11 10:19 38,496 –a—— c:\winnt\system32\drivers\mbamswissarmy.sys
2009-03-09 23:38 . 2009-02-11 10:19 15,504 –a—— c:\winnt\system32\drivers\mbam.sys
2009-03-09 23:31 . 2009-03-09 23:32 d——– c:\program files\ERUNT
2009-03-09 19:31 . 2009-03-09 19:31 d——– c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-13 13:00 ——— d—–w c:\documents and settings\LocalService\Application Data\AVG7
2009-03-12 17:04 ——— d—–w c:\program files\McAfee
2009-03-10 06:55 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-03-10 06:54 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-10 04:56 ——— d—–w c:\documents and settings\Owner\Application Data\AVG7
2009-02-09 11:13 1,846,784 —-a-w c:\winnt\system32\win32k.sys
2009-02-09 11:13 1,846,784 ——w c:\winnt\system32\dllcache\win32k.sys
2009-01-17 03:35 3,594,752 —-a-w c:\winnt\system32\dllcache\mshtml.dll
2005-10-26 15:31 123,662 —-a-w c:\program files\smitRem.exe
2004-07-03 20:25 66,048 —-a-w c:\program files\notepad.exe
2008-08-30 05:50 32,768 –sha-w c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008083020080831\index.dat
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of c:\documents and settings\owner\favorites\health —-

2008-11-15 10:40 277 –a—— c:\documents and settings\owner\favorites\health\James Andrews (physician) - Wikipedia, the free encyclopedia.url


((((((((((((((((((((((((((((( SnapShot_2009-03-12_18.58.27.95 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-03 23:21:12 21,244,864 —-a-w c:\winnt\system32\MRT.exe
+ 2009-02-25 17:55:00 24,768,960 —-a-w c:\winnt\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~1\PSFree.exe" [2003-10-29 524288]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2003-11-18 155648]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2003-11-18 118784]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-06-26 53248]
"NeroCheck"="c:\winnt\System32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2002-05-20 90112]
"AVG7_CC"="c:\progra~1\Grisoft\AVGFRE~1\avgcc.exe" [2009-02-24 590848]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-24 28672]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [BU]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-23 219136]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-29 53248]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 282624]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware SE Personal\\Ad-Aware.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avgw.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avgvv.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4340:TCP"= 4340:TCP:WWW
"110:TCP"= 110:TCP:svchost

R0 pavboot;pavboot;c:\winnt\system32\drivers\pavboot.sys [2009-03-14 28544]
S3 LCcfltr;Logitech USB Filter Driver;c:\winnt\system32\drivers\LCcFltr.Sys [2004-02-26 13724]

— Other Services/Drivers In Memory —

*NewlyCreated* - PAVBOOT
.
Contents of the 'Scheduled Tasks' folder

2004-02-27 c:\winnt\Tasks\ISP signup reminder 1.job
- c:\winnt\System32\OOBE\oobebaln.exe [2008-04-13 19:12]

2004-03-07 c:\winnt\Tasks\ISP signup reminder 2.job
- c:\winnt\System32\OOBE\oobebaln.exe [2008-04-13 19:12]

2004-03-12 c:\winnt\Tasks\ISP signup reminder 3.job
- c:\winnt\System32\OOBE\oobebaln.exe [2008-04-13 19:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://new.kentuckysportsradio.com
mStart Page = hxxp://new.kentuckysportsradio.com
uInternet Settings,ProxyServer = http=127.0.0.1:80
uInternet Settings,ProxyOverride =
DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/controls/yregucfg/2005_6_10_1/yregucfg.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\10ub6eo9.default\
FF - prefs.js: browser.startup.homepage - hxxp://new.kentuckysportsradio.com/
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-21 19:57:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
MMTray = c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe?w???g????V??g????SOFTWARE\MusicMatch\MusicMatch Jukebox\4.0\TrayApp???%X??????????????????>?w0 ?w????3??w???g8!?????????g?RY??QY????????g????2??????? ???8???? @??%X??%X???????????????????Y?????n?Q?????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-21 19:59:35
ComboFix-quarantined-files.txt 2009-03-22 00:58:50
ComboFix2.txt 2009-03-12 23:59:51

Pre-Run: 42,996,019,200 bytes free
Post-Run: 42,982,858,752 bytes free

154 — E O F — 2009-03-21 14:46:57


HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:04 PM, on 3/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: KTBho Class - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Kaboodle Toolbar - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O3 - Toolbar: Blue Dot Toolbar - {2751F3AD-5600-44cc-A653-8A24CAE5AF6D} - C:\Program Files\Blue Dot Toolbar\bdtool.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [HP Component Manager] "c:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: searchle it! - {0376FDB9-A132-4929-8336-8CB3B2CAFCC0} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles2.js (HKCU)
O9 - Extra button: my!searchles - {3B72BA76-67BE-11DB-8373-B622A1EF5492} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles.js (HKCU)
O16 - DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} (RegUserCfgUI Class) - http://us.dl1.yimg.com/download.yahoo.com/…_1/yregucfg.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1165704139859
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SentinelProtectionServer - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

–
End of file - 7517 bytes


Thanks.
Hi Katsrock,

This looks ok.

We have some clean up to after you post back and the IE problem.

Do you have both computers hooked to the same router? If so, please post a HJT log from the computer that can access the internet with IE.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI