This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Re-Directing

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've read a couple of other posters problems and I'm having the same issue. Anytime I click a link from a google search I get redirected to random sites. Also cannot install/load spybot search and destroy. I just got rid of the "Virus Alert!" virus, I'm hoping someone can help me with the redirecting problem. :notworthy:

I've run MBAM, fixwareout and ATF-Cleaner so far… Please help!!!

EDIT!!! While waiting for a response I have seem to have been able to resolve the redirecting issues and everything seems to be working well at this point. I WOULD definitely still love and appreciate it if you could take a look at my current HJT log just to make sure I've got a clean bill of health…. Thanks for the help!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:23:49 PM, on 4/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\AOL\1140474985\ee\AOLSoftware.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\system32\DfrgNtfs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Qwest
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {3D97A85A-5010-42AD-A6E5-4B02893248A4} - C:\WINDOWS\system32\wvUmnLcy.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1140474985\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickCare2.2] C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe /P QuickCare2.2
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Qwest Live - {3A97D3DF-91B6-4557-BCFB-381872254C87} - http://qwest.live.com (file missing) (HKCU)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: sxiest.dll qhkqlz.dll smkrhz.dll ctbfxb.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O22 - SharedTaskScheduler: {874443fe-aa33-4ebf-a6ac-73208787e62d} - bestreak - (no file)
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 11372 bytes
Hi,

There are still some bad entries in your log, but they could be leftovers.

Please run MalwareBytes', update it and run a Quick Scan. If it finds anything, please post the log it gives (after letting it remove what it finds).

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
Thanks for the help… MBAM did find some more things, here is the log: Malwarebytes' Anti-Malware 1.36 Database version: 1959 Windows 5.1.2600 Service Pack 2 4/14/2009 12:18:12 PM mbam-log-2009-04-14 (12-18-12).txt Scan type: Quick Scan Objects scanned: 78479 Time elapsed: 16 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 34 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\bgrqfetx.bolb (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\bgrqfetx.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\Temp\tdss1582.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss2622.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss3c33.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss3ef7.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss4006.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss4150.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss449d.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss4c9e.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss4e07.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss5005.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss52ff.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss5bea.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6182.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss63d4.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6474.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6495.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6514.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6655.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss667a.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss66f5.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss678b.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6f3f.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss7362.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss7421.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss74a9.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss74fd.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss860d.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss877a.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss8780.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss964b.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss9f40.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdssa517.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdssb81a.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdssc7de.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. Here is the DDS: Malwarebytes' Anti-Malware 1.36 Database version: 1959 Windows 5.1.2600 Service Pack 2 4/14/2009 12:18:12 PM mbam-log-2009-04-14 (12-18-12).txt Scan type: Quick Scan Objects scanned: 78479 Time elapsed: 16 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 34 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\bgrqfetx.bolb (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\bgrqfetx.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\Temp\tdss1582.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss2622.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss3c33.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss3ef7.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss4006.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss4150.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss449d.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss4c9e.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss4e07.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss5005.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss52ff.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss5bea.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6182.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss63d4.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6474.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6495.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6514.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6655.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss667a.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss66f5.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss678b.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss6f3f.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss7362.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss7421.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss74a9.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss74fd.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss860d.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss877a.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss8780.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss964b.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdss9f40.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdssa517.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdssb81a.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tdssc7de.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Attachments:

Hi, It looks like you posted the MBAM log twice instead of posting the DDS log. I need to see the first log DDS gives (DDS.txt). Thanks.

Hi,

It looks like you posted the MBAM log twice instead of posting the DDS log. I need to see the first log DDS gives (DDS.txt).

Thanks.

:wall: Not sure how I pulled that one off…. sorry about that! Here's the DDS log:


DDS (Ver_09-03-16.01) - NTFSx86
Run by [removed] at 10:04:39.19 on Wed 04/15/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.12 [GMT -6:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\1XConfig.exe
C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Family\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://qwest.live.com/
uSearch Page = hxxp://www.google.com
uWindow Title = Windows Internet Explorer provided by Qwest
uDefault_Page_URL = hxxp://qwest.live.com
mDefault_Page_URL = hxxp://qwest.live.com
mStart Page = hxxp://qwest.live.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: {3d97a85a-5010-42ad-a6e5-4b02893248a4} - c:\windows\system32\wvUmnLcy.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: &Google; Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [PhotoShow Deluxe Media Manager] c:\progra~1\comcast\comcas~1\data\xtras\mssysmgr.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [PRONoMgr.exe] c:\program files\intel\prosetwireless\ncs\proset\PRONoMgr.exe
mRun: [SigmaTel StacMon] c:\program files\sigmatel\sigmatel ac97 audio drivers\stacmon.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
dRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil9f.exe
uPolicies-explorer: StartMenuLogoff = 1 (0x1)
IE: &Windows; Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {00000161-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www1.snapfish.com/SnapfishActivia.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: Sebring - c:\windows\system32\LgNotify.dll
AppInit_DLLs: sxiest.dll qhkqlz.dll smkrhz.dll ctbfxb.dll
STS: bestreak - No File
STS: IE Component Categories cache daemon: {553858a7-4922-4e7e-b1c1-97140c1c16ef} - c:\windows\system32\ieframe.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Authentication Packages = msv1_0 c:\windows\system32\wvUmnLcy

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\family\applic~1\mozilla\firefox\profiles\c85z28qn.default\
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-4-9 325640]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-4-9 27656]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-9 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-2-17 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-2-17 55024]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2004-2-9 301200]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-4-9 298264]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2004-2-29 255096]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2004-2-29 242808]
R2 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2004-2-9 37008]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2004-3-12 1221864]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-2-15 24652]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090414.020\naveng.sys [2009-4-14 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090414.020\navex15.sys [2009-4-14 876144]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-2-17 7408]
S2 KXKFOGHC;KXKFOGHC;\??\c:\windows\system32\kxkfoghc.jqh –> c:\windows\system32\kxkfoghc.jqh [?]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2004-2-29 87160]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2004-3-12 169192]
S3 vsdatant;vsdatant;\??\c:\windows\system32\vsdatant.sys –> c:\windows\system32\vsdatant.sys [?]

=============== Created Last 30 ================

2009-04-14 16:34 –d—– c:\windows\system32\scripting
2009-04-14 16:34 –d—– c:\windows\l2schemas
2009-04-14 16:34 –d—– c:\windows\system32\en
2009-04-14 16:34 –d—– c:\windows\system32\bits
2009-04-14 16:25 –d—– c:\windows\ServicePackFiles
2009-04-14 16:07 –d—– c:\windows\EHome
2009-04-10 13:49 410,984 a——- c:\windows\system32\deploytk.dll
2009-04-10 13:12 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-04-10 13:11 –d—– c:\program files\SUPERAntiSpyware
2009-04-10 13:11 –d—– c:\docume~1\family\applic~1\SUPERAntiSpyware.com
2009-04-10 13:11 –d—– c:\program files\common files\Wise Installation Wizard
2009-04-09 14:48 –d—– c:\program files\Trend Micro
2009-04-09 14:11 –d—– C:\fixwareout
2009-04-09 14:08 67,866 ——– c:\windows\system32\drivers\netwlan5.img
2009-04-09 14:07 1,261 ——– c:\windows\system32\pid.inf
2009-04-09 13:53 2,189,184 -c—— c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-09 13:53 2,145,280 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-09 13:53 2,023,936 -c—— c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-09 13:53 2,066,048 -c—— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-09 13:51 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2009-04-09 13:51 333,952 -c—— c:\windows\system32\dllcache\srv.sys
2009-04-09 13:51 691,712 -c—— c:\windows\system32\dllcache\inetcomm.dll
2009-04-09 13:50 337,408 -c—— c:\windows\system32\dllcache\netapi32.dll
2009-04-09 13:31 –d—– c:\program files\CCleaner
2009-04-09 13:26 –d—– c:\program files\Wise Registry Cleaner
2009-04-09 12:57 –d—– c:\docume~1\family\applic~1\Malwarebytes
2009-04-09 12:57 15,504 a——- c:\windows\system32\drivers\mbam.sys
2009-04-09 12:57 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-09 12:57 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-09 12:57 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-04-09 11:15 –d-h— C:\$AVG8.VAULT$
2009-04-09 11:12 10,520 a——- c:\windows\system32\avgrsstx.dll
2009-04-09 11:12 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-04-09 11:12 325,640 a——- c:\windows\system32\drivers\avgldx86.sys
2009-04-09 11:12 –d—– c:\windows\system32\drivers\Avg
2009-04-09 11:11 –d—– c:\program files\AVG
2009-04-09 11:11 –d—– c:\docume~1\alluse~1\applic~1\avg8
2009-04-09 10:58 54,156 a—h— c:\windows\QTFont.qfn
2009-04-09 10:58 1,409 a——- c:\windows\QTFont.for
2009-04-09 09:59 –d—– c:\windows\pss
2009-03-30 20:47 2,510,527 —sh— c:\windows\system32\fbbxhxmr.ini
2009-03-29 18:54 2,510,527 —sh— c:\windows\system32\sjidekfy.ini

==================== Find3M ====================

2009-04-14 16:38 77,423 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-04-09 11:49 6,358 a–sh— c:\windows\system32\ycLnmUvw.ini2
2009-04-09 08:58 90,112 a——- c:\windows\DUMP33ad.tmp
2009-04-09 08:57 90,112 a——- c:\windows\DUMP1b4e.tmp
2009-02-28 09:35 48,274 a——- c:\windows\system32\bftifgkkheftuvn.exe
2009-02-09 05:13 1,846,784 a——- c:\windows\system32\win32k.sys
2007-12-17 11:22 284 a——- c:\docume~1\family\applic~1\ViewerApp.dat
2006-02-20 16:27 114,660 a——- c:\program files\AOLDNLD.exe
2006-01-12 18:44 34,816 a——- c:\program files\Minutes Mountain Area - 1-06.doc
2006-01-12 18:43 36,864 a——- c:\program files\ESS Equipment Inventory Sheet.doc
2006-01-11 15:28 10,626,920 a——- c:\program files\RhapsodyReal.exe
2006-01-11 15:09 774,144 a——- c:\program files\RngInterstitial.dll
2006-01-11 15:09 482,328 a——- c:\program files\realarcade_comcast_stub.exe
2006-01-11 12:08 20,921,040 a——- c:\program files\AdbeRdr705_enu_full.exe
2006-01-10 15:24 359,112 a——- c:\program files\LimeWireWin.exe
2006-01-10 15:19 2,625,400 a——- c:\program files\comcast_photoshow_deluxe_4.exe
2003-04-22 11:46 2,719,744 ——– c:\program files\aiodrv.msi
2003-04-22 11:42 2,588,672 ——– c:\program files\aiosw.msi
2003-04-22 11:24 16,606 a——- c:\program files\hpomdl01.dat
2003-04-22 11:24 19,469 a——- c:\program files\autorun.inf
2003-04-22 11:23 267 a——- c:\program files\readme.html
2003-04-09 19:19 2,848 a——- c:\program files\hpound08.inf
2003-04-09 19:19 14,157 a——- c:\program files\hpousc08.inf
2003-04-09 19:00 2,889 a——- c:\program files\hpousb08.inf
2003-04-09 19:00 4,715 a——- c:\program files\hpoglu08.inf
2003-03-20 17:20 22,523 a——- c:\program files\HPZius12.cat
2003-03-20 17:20 22,082 a——- c:\program files\hpzist12.cat
2003-03-20 17:20 24,728 a——- c:\program files\HPZipr12.cat
2003-03-20 17:20 22,082 a——- c:\program files\HPZid412.cat
2003-03-20 17:20 21,641 a——- c:\program files\HPOunp08.cat
2003-03-20 17:20 24,285 a——- c:\program files\hposcu08.cat
2003-03-20 17:20 205,503 a——- c:\program files\hpoprn08.cat
2003-03-09 22:30 184,320 a——- c:\program files\hpzscr07.dll
2003-03-09 22:30 14,285 a——- c:\program files\hpzius12.inf
2003-03-09 22:30 10,325 a——- c:\program files\hpzipr12.inf
2003-03-09 22:30 3,667 a——- c:\program files\hpzist12.inf
2003-03-09 22:30 274,432 a——- c:\program files\hpzglu07.exe
2003-03-09 22:30 237,568 a——- c:\program files\hpzc3212.dll
2003-03-09 22:30 63,562 a——- c:\program files\hposcu08.inf
2003-03-09 22:30 51,266 a——- c:\program files\hpoprn08.inf
2003-03-09 22:30 33,952 a——- c:\program files\hpzid412.inf
2003-03-09 22:30 23,186 a——- c:\program files\hpzcin06.ex_
2003-03-09 22:30 3,898 a——- c:\program files\hpounp08.inf
2002-09-09 19:48 22,608 a——- c:\program files\usbprint.sys
2002-09-09 19:48 12,288 a——- c:\program files\usbmon.dll
2002-09-09 19:47 254,005 a——- c:\program files\msvcrt.dll
2002-09-09 19:47 70,656 a——- c:\program files\msvcirt.dll
2002-09-09 19:47 55,155 a——- c:\program files\hpzusb00.sy_
2002-09-09 19:47 5,705 a——- c:\program files\hpzuci02.dl_
2002-09-09 19:47 25,639 a——- c:\program files\hpzpom04.dl_
2002-09-09 19:47 212,992 a——- c:\program files\hpzpnp07.dll
2002-09-09 19:46 49,212 a——- c:\program files\hpzjvp01.dll
2002-09-09 19:46 249,913 a——- c:\program files\hpzjut01.dll
2002-09-09 19:46 417,849 a——- c:\program files\hpzjpp01.dll
2002-09-09 19:46 28,722 a——- c:\program files\hpzjlog.dll
2002-09-09 19:46 52,552 a——- c:\program files\hpziou01.dl_
2002-09-09 19:46 46,017 a——- c:\program files\hpzion00.sy_
2002-09-06 11:54 995,383 a——- c:\program files\MFC42.DLL
2008-09-30 16:09 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008093020081001\index.dat
2008-10-04 21:21 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100420081005\index.dat
2008-10-12 14:17 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101220081013\index.dat
2008-10-26 15:52 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008102620081027\index.dat
2008-10-28 15:39 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008102820081029\index.dat

============= FINISH: 10:05:48.61 ===============
Looks like there is more left than I thought. Are you using AVG AntiVirus and Symantec Security Suite?

Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Please open the AVG Control Center program, by right clicking on the AVG 8 icon on task bar.
  • Click on Tools.
  • Select Advanced.
  • In the left hand pane, scroll down to "Resident Shield".
  • In the main pane, deselect the option to "Enable Resident Shield".
    To re-enable AVG 8, select "Enable Resident Shield" again.
Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Yea - Something must have corrupted symantec, I wasn't able to use it to scan the computer or do anything helpful. I had to download AVG to clear some other virus stuff. I had done everything I could to disable Symantec, but apparently something was wrong… I ran Combofix, I've already noticed some big differences and Symantec is working again! Below are both the logs you need.

ComboFix:

ComboFix 09-04-15.08 - Family 04/15/2009 11:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.192 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\autorun.inf
c:\windows\system32\bxgmxddw.ini
c:\windows\system32\cefkbmgd.ini
c:\windows\system32\dmnrmady.ini
c:\windows\system32\dsmfhgfh.ini
c:\windows\system32\eqoudtkt.ini
c:\windows\system32\fbbxhxmr.ini
c:\windows\system32\ggrajvmb.ini
c:\windows\system32\hqtrwkpc.ini
c:\windows\system32\ijncrgrb.ini
c:\windows\system32\jdiklrtk.ini
c:\windows\system32\jobgxxix.ini
c:\windows\system32\jsikqlck.ini
c:\windows\system32\knrycdis.ini
c:\windows\system32\lskdppuk.ini
c:\windows\system32\minwmant.ini
c:\windows\system32\nnfqcblh.ini
c:\windows\system32\ougluhum.ini
c:\windows\system32\qkyhyqag.ini
c:\windows\system32\qvidojlh.ini
c:\windows\system32\rqkmbumd.ini
c:\windows\system32\sjidekfy.ini
c:\windows\system32\users32.exe
c:\windows\system32\vokmmjsp.ini
c:\windows\system32\vsdswccx.ini
c:\windows\system32\vykehnhd.ini
c:\windows\system32\wdrqnqqr.ini
c:\windows\system32\ycLnmUvw.ini
c:\windows\system32\ycLnmUvw.ini2
c:\windows\system32\ymisuvec.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV
——-\Service_tdssserv


((((((((((((((((((((((((( Files Created from 2009-03-15 to 2009-04-15 )))))))))))))))))))))))))))))))
.

2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\system32\scripting
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\l2schemas
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\system32\en
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\system32\bits
2009-04-14 22:25 . 2009-04-14 22:35 ——– d—–w c:\windows\ServicePackFiles
2009-04-14 22:07 . 2009-04-14 22:07 ——– d—–w c:\windows\EHome
2009-04-10 19:49 . 2009-04-10 19:48 410984 —-a-w c:\windows\system32\deploytk.dll
2009-04-10 19:12 . 2009-04-10 19:12 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-10 19:11 . 2009-04-10 19:11 ——– d—–w c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com
2009-04-09 20:11 . 2009-04-09 20:15 ——– d—–w C:\fixwareout
2009-04-09 20:08 . 2004-07-17 17:35 67866 ——w c:\windows\system32\drivers\netwlan5.img
2009-04-09 20:07 . 2007-09-17 08:48 1261 ——w c:\windows\system32\pid.inf
2009-04-09 20:02 . 2009-04-09 20:02 ——– d—–w c:\documents and settings\Family\Local Settings\Application Data\Mozilla
2009-04-09 19:53 . 2008-08-14 10:11 2189184 -c—-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-09 19:53 . 2008-08-14 10:09 2145280 -c—-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-09 19:53 . 2008-08-14 09:33 2023936 -c—-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-09 19:53 . 2008-08-14 09:33 2066048 -c—-w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-09 19:51 . 2008-10-24 11:21 455296 -c—-w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-09 19:51 . 2008-12-11 10:57 333952 -c—-w c:\windows\system32\dllcache\srv.sys
2009-04-09 19:51 . 2008-04-11 19:04 691712 -c—-w c:\windows\system32\dllcache\inetcomm.dll
2009-04-09 19:50 . 2008-10-15 16:34 337408 -c—-w c:\windows\system32\dllcache\netapi32.dll
2009-04-09 19:10 . 2009-04-09 19:10 ——– d—–w c:\documents and settings\All Users\Application Data\nView_Profiles
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\documents and settings\Family\Application Data\Malwarebytes
2009-04-09 18:57 . 2009-04-06 21:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-09 18:57 . 2009-04-06 21:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-09 17:15 . 2009-04-14 18:00 ——– d–h–w C:\$AVG8.VAULT$
2009-04-09 17:12 . 2009-04-09 17:12 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-04-09 17:12 . 2009-04-09 17:12 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-09 17:12 . 2009-04-09 17:12 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-09 17:12 . 2009-04-15 15:59 ——– d—–w c:\windows\system32\drivers\Avg
2009-04-09 17:11 . 2009-04-09 18:19 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-09 16:58 . 2009-04-15 16:03 54156 —ha-w c:\windows\QTFont.qfn
2009-04-09 16:58 . 2009-04-09 16:58 1409 —-a-w c:\windows\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-15 17:56 . 2006-02-09 16:10 ——– d—–w c:\program files\Symantec AntiVirus
2009-04-14 23:36 . 2007-06-03 16:49 49152 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2009-04-14 23:36 . 2007-06-03 16:49 49152 –sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
2009-04-14 23:36 . 2007-06-03 16:49 360448 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
2009-04-14 23:35 . 2009-04-14 23:36 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009041420090415\index.dat
2009-04-14 23:35 . 2009-04-14 23:36 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009040620090413\index.dat
2009-04-14 22:38 . 2005-12-29 01:39 77423 —-a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-14 22:19 . 2004-08-12 14:02 250048 –sha-r C:\ntldr
2009-04-10 19:48 . 2006-01-10 21:26 ——– d—–w c:\program files\Java
2009-04-10 19:40 . 2009-04-10 19:11 ——– d—–w c:\program files\SUPERAntiSpyware
2009-04-10 19:11 . 2009-04-10 19:11 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-09 20:48 . 2009-04-09 20:48 ——– d—–w c:\program files\Trend Micro
2009-04-09 20:28 . 2007-11-11 23:03 244 —ha-w C:\sqmnoopt03.sqm
2009-04-09 20:28 . 2007-11-11 23:03 232 —ha-w C:\sqmdata03.sqm
2009-04-09 20:11 . 2007-11-11 23:03 244 —ha-w C:\sqmnoopt02.sqm
2009-04-09 20:11 . 2007-11-11 23:03 232 —ha-w C:\sqmdata02.sqm
2009-04-09 19:31 . 2009-04-09 19:31 ——– d—–w c:\program files\CCleaner
2009-04-09 19:28 . 2009-04-09 19:26 ——– d—–w c:\program files\Wise Registry Cleaner
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-09 17:27 . 2008-08-11 05:47 ——– d—–w c:\documents and settings\All Users\Application Data\services
2009-04-09 17:11 . 2009-04-09 17:11 ——– d—–w c:\program files\AVG
2009-04-09 15:42 . 2007-11-11 23:03 232 —ha-w C:\sqmdata01.sqm
2009-04-09 15:42 . 2007-11-11 23:03 244 —ha-w C:\sqmnoopt01.sqm
2009-04-09 15:13 . 2007-11-11 22:28 244 —ha-w C:\sqmnoopt00.sqm
2009-04-09 15:13 . 2007-11-11 22:28 232 —ha-w C:\sqmdata00.sqm
2009-04-09 14:58 . 2004-10-28 00:02 90112 —-a-w c:\windows\DUMP33ad.tmp
2009-04-09 14:57 . 2004-10-28 00:02 90112 —-a-w c:\windows\DUMP1b4e.tmp
2009-03-31 03:03 . 2009-03-31 02:53 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009033020090331\index.dat
2009-03-31 02:45 . 2007-11-19 06:12 232 —ha-w C:\sqmdata19.sqm
2009-03-31 02:45 . 2007-11-19 06:12 244 —ha-w C:\sqmnoopt19.sqm
2009-03-30 01:24 . 2008-05-18 03:31 ——– d—–w c:\program files\Apple Software Update
2009-03-30 00:52 . 2006-03-01 22:11 ——– d—–w c:\program files\Google
2009-03-25 15:58 . 2007-11-19 05:35 268 —ha-w C:\sqmdata18.sqm
2009-03-25 15:58 . 2007-11-19 05:35 244 —ha-w C:\sqmnoopt18.sqm
2009-03-11 15:10 . 2007-11-19 04:43 268 —ha-w C:\sqmdata17.sqm
2009-03-11 15:10 . 2007-11-19 04:43 244 —ha-w C:\sqmnoopt17.sqm
2009-02-28 19:14 . 2007-11-19 03:17 268 —ha-w C:\sqmdata16.sqm
2009-02-28 19:14 . 2007-11-19 03:17 244 —ha-w C:\sqmnoopt16.sqm
2009-02-28 15:35 . 2008-08-11 05:47 48274 —-a-w c:\windows\system32\bftifgkkheftuvn.exe
2009-02-28 15:18 . 2009-02-28 15:18 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009022820090301\index.dat
2009-02-11 21:44 . 2007-11-18 22:18 268 —ha-w C:\sqmdata15.sqm
2009-02-11 21:44 . 2007-11-18 22:18 244 —ha-w C:\sqmnoopt15.sqm
2009-02-11 19:08 . 2009-02-11 19:08 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009021120090212\index.dat
2009-02-09 11:13 . 2004-08-12 14:09 1846784 —-a-w c:\windows\system32\win32k.sys
2009-01-27 01:36 . 2009-01-27 01:36 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009012620090127\index.dat
2008-08-16 20:17 . 2006-01-17 22:15 19496 —-a-w c:\documents and settings\Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-08-06 19:30 . 2006-02-19 05:32 19496 —-a-w c:\documents and settings\Rob\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-12-17 17:22 . 2007-12-17 17:22 284 —-a-w c:\documents and settings\Family\Application Data\ViewerApp.dat
2007-12-03 00:38 . 2007-09-04 01:02 836 —-a-w c:\documents and settings\Rob\Application Data\ViewerApp.dat
2006-02-20 22:27 . 2006-02-20 22:27 114660 —-a-w c:\program files\AOLDNLD.exe
2006-01-13 00:44 . 2006-01-13 00:44 34816 —-a-w c:\program files\Minutes Mountain Area - 1-06.doc
2006-01-13 00:43 . 2006-01-13 00:43 36864 —-a-w c:\program files\ESS Equipment Inventory Sheet.doc
2006-01-11 21:28 . 2006-01-11 21:28 10626920 —-a-w c:\program files\RhapsodyReal.exe
2006-01-11 21:09 . 2006-01-11 21:10 774144 —-a-w c:\program files\RngInterstitial.dll
2006-01-11 21:09 . 2006-01-11 21:08 482328 —-a-w c:\program files\realarcade_comcast_stub.exe
2006-01-11 18:08 . 2006-01-11 18:07 20921040 —-a-w c:\program files\AdbeRdr705_enu_full.exe
2006-01-10 21:24 . 2006-01-10 21:24 359112 —-a-w c:\program files\LimeWireWin.exe
2006-01-10 21:19 . 2006-01-10 21:18 2625400 —-a-w c:\program files\comcast_photoshow_deluxe_4.exe
2003-04-22 17:46 . 2003-04-22 17:46 2719744 ——w c:\program files\aiodrv.msi
2003-04-22 17:42 . 2003-04-22 17:42 2588672 ——w c:\program files\aiosw.msi
2003-04-22 17:24 . 2003-04-22 17:24 16606 —-a-w c:\program files\hpomdl01.dat
2003-04-22 17:23 . 2003-04-22 17:23 267 —-a-w c:\program files\readme.html
2003-04-10 01:19 . 2003-04-10 01:19 2848 —-a-w c:\program files\hpound08.inf
2003-04-10 01:19 . 2003-04-10 01:19 14157 —-a-w c:\program files\hpousc08.inf
2003-04-10 01:00 . 2003-04-10 01:00 2889 —-a-w c:\program files\hpousb08.inf
2003-04-10 01:00 . 2003-04-10 01:00 4715 —-a-w c:\program files\hpoglu08.inf
2003-03-20 23:20 . 2003-03-20 23:20 22523 —-a-w c:\program files\HPZius12.cat
2003-03-20 23:20 . 2003-03-20 23:20 22082 —-a-w c:\program files\hpzist12.cat
2003-03-20 23:20 . 2003-03-20 23:20 24728 —-a-w c:\program files\HPZipr12.cat
2003-03-20 23:20 . 2003-03-20 23:20 22082 —-a-w c:\program files\HPZid412.cat
2003-03-20 23:20 . 2003-03-20 23:20 21641 —-a-w c:\program files\HPOunp08.cat
2003-03-20 23:20 . 2003-03-20 23:20 24285 —-a-w c:\program files\hposcu08.cat
2003-03-20 23:20 . 2003-03-20 23:20 205503 —-a-w c:\program files\hpoprn08.cat
2003-03-10 04:30 . 2003-03-10 04:30 3667 —-a-w c:\program files\hpzist12.inf
2003-03-10 04:30 . 2003-03-10 04:30 184320 —-a-w c:\program files\hpzscr07.dll
2003-03-10 04:30 . 2003-03-10 04:30 14285 —-a-w c:\program files\hpzius12.inf
2003-03-10 04:30 . 2003-03-10 04:30 10325 —-a-w c:\program files\hpzipr12.inf
2003-03-10 04:30 . 2003-03-10 04:30 63562 —-a-w c:\program files\hposcu08.inf
2003-03-10 04:30 . 2003-03-10 04:30 51266 —-a-w c:\program files\hpoprn08.inf
2003-03-10 04:30 . 2003-03-10 04:30 3898 —-a-w c:\program files\hpounp08.inf
2003-03-10 04:30 . 2003-03-10 04:30 33952 —-a-w c:\program files\hpzid412.inf
2003-03-10 04:30 . 2003-03-10 04:30 274432 —-a-w c:\program files\hpzglu07.exe
2003-03-10 04:30 . 2003-03-10 04:30 237568 —-a-w c:\program files\hpzc3212.dll
2003-03-10 04:30 . 2003-03-10 04:30 23186 —-a-w c:\program files\hpzcin06.ex_
2002-09-10 01:48 . 2002-09-10 01:48 22608 —-a-w c:\program files\usbprint.sys
2002-09-10 01:48 . 2002-09-10 01:48 12288 —-a-w c:\program files\usbmon.dll
2002-09-10 01:47 . 2002-09-10 01:47 254005 —-a-w c:\program files\msvcrt.dll
2002-09-10 01:47 . 2002-09-10 01:47 70656 —-a-w c:\program files\msvcirt.dll
2002-09-10 01:47 . 2002-09-10 01:47 55155 —-a-w c:\program files\hpzusb00.sy_
2002-09-10 01:47 . 2002-09-10 01:47 5705 —-a-w c:\program files\hpzuci02.dl_
2002-09-10 01:47 . 2002-09-10 01:47 25639 —-a-w c:\program files\hpzpom04.dl_
2002-09-10 01:47 . 2002-09-10 01:47 212992 —-a-w c:\program files\hpzpnp07.dll
2002-09-10 01:46 . 2002-09-10 01:46 49212 —-a-w c:\program files\hpzjvp01.dll
2002-09-10 01:46 . 2002-09-10 01:46 249913 —-a-w c:\program files\hpzjut01.dll
2002-09-10 01:46 . 2002-09-10 01:46 417849 —-a-w c:\program files\hpzjpp01.dll
2002-09-10 01:46 . 2002-09-10 01:46 28722 —-a-w c:\program files\hpzjlog.dll
2002-09-10 01:46 . 2002-09-10 01:46 52552 —-a-w c:\program files\hpziou01.dl_
2002-09-10 01:46 . 2002-09-10 01:46 46017 —-a-w c:\program files\hpzion00.sy_
2002-09-06 17:54 . 2002-09-06 17:54 995383 —-a-w c:\program files\MFC42.DLL
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe" [2005-05-09 192512]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-10 1830128]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\program files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-19 86016]
"SigmaTel StacMon"="c:\program files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2004-04-29 90169]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 66680]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-09 1932568]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-26 4632576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil9f.exe" [2008-03-25 218496]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-01-13 22:17 110592 —-a-w c:\windows\system32\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-09 17:12 10520 —-a-w c:\windows\system32\avgrsstx.dll
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2005-11-03 03:01 50792 —-a-w c:\program files\Common Files\AOL\1140474985\ee\aolsoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickCare2.2]
2007-05-04 13:21 198184 —-a-w c:\program files\Qwest\QuickCare\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
2004-03-12 22:18 124128 —-a-w c:\progra~1\SYMANT~1\VPTray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140474985\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140474985\\ee\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R2 KXKFOGHC;KXKFOGHC; [x]
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2004-03-12 169192]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-09 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-09 108552]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-10 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-02-17 55024]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-09 298264]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]

.
Contents of the 'Scheduled Tasks' folder

2009-03-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 18:34]

2009-04-15 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 18:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{3D97A85A-5010-42AD-A6E5-4B02893248A4} - c:\windows\system32\wvUmnLcy.dll
SharedTaskScheduler-bestreak - (no file)
MSConfigStartUp-CTFMON - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://qwest.live.com/
mStart Page = hxxp://qwest.live.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Family\Application Data\Mozilla\Firefox\Profiles\c85z28qn.default\
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-15 15:11
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\KXKFOGHC]
"ImagePath"="\??\c:\windows\system32\kxkfoghc.jqh"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{860c2f6b-ca82-4282-9187-beccbb66f0af}\Implemented Categories]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{860c2f6b-ca82-4282-9187-beccbb66f0af}\InprocServer32]
@DACL=(02 0000)
@="c:\\Program Files\\IntCodec\\iesplugin.dll"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\bgrqfetx.dll"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}\ProgID]
@DACL=(02 0000)
@="bgrqfetx.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}\Programmable]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}\TypeLib]
@DACL=(02 0000)
@="{20E1148B-A9DB-4678-82AB-E3E72B0F2959}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}\VersionIndependentProgID]
@DACL=(02 0000)
@="bgrqfetx"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C6B1408-FC27-4864-9B5D-F70A93A789C4}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C6B1408-FC27-4864-9B5D-F70A93A789C4}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C6B1408-FC27-4864-9B5D-F70A93A789C4}\TypeLib]
@DACL=(02 0000)
@="{20E1148B-A9DB-4678-82AB-E3E72B0F2959}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}\TypeLib]
@DACL=(02 0000)
@="{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{20E1148B-A9DB-4678-82AB-E3E72B0F2959}\1.0]
@DACL=(02 0000)
@="bgrqfetx"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(804)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\LgNotify.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\S24EvMon.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\RegSrvc.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\ZCfgSvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\1XConfig.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-04-15 15:16 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-15 21:15

Pre-Run: 18,922,803,200 bytes free
Post-Run: 19,054,055,424 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=3 Default=3 Failed=2 LastKnownGood=1 Sets=1,2,3,4
517 — E O F — 2009-04-14 22:46




HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:25:08 PM, on 4/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\1XConfig.exe
C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Qwest Live - {3A97D3DF-91B6-4557-BCFB-381872254C87} - http://qwest.live.com (file missing) (HKCU)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 9866 bytes


I'm hoping this has taken care of everything - I appreciate your time on this!
Hi,

We are getting there. You have a fair few files lying in your Program Files directory, have you put these there?

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

file::
C:\sqmnoopt03.sqm
C:\sqmdata03.sqm
C:\sqmnoopt02.sqm
C:\sqmdata02.sqm
C:\sqmdata01.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt00.sqm
C:\sqmdata00.sqm
c:\windows\DUMP33ad.tmp
c:\windows\DUMP1b4e.tmp
C:\sqmdata19.sqm
C:\sqmnoopt19.sqm
C:\sqmdata18.sqm
C:\sqmnoopt18.sqm
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
C:\sqmdata16.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt15.sqm
C:\sqmdata15.sqm
c:\windows\system32\bftifgkkheftuvn.exe
c:\windows\system32\kxkfoghc.jqh
c:\WINDOWS\bgrqfetx.dll

Folder::
c:\Program Files\IntCodec

Driver::
KXKFOGHC

RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{860c2f6b-ca82-4282-9187-beccbb66f0af}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C6B1408-FC27-4864-9B5D-F70A93A789C4}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{20E1148B-A9DB-4678-82AB-E3E72B0F2959}]

Registry::
[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{860c2f6b-ca82-4282-9187-beccbb66f0af}]
[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C6B1408-FC27-4864-9B5D-F70A93A789C4}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{20E1148B-A9DB-4678-82AB-E3E72B0F2959}]
[-HKEY_LOCAL_MACHINE\System\ControlSet003\Services\KXKFOGHC]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-

FileLook::
c:\program files\AOLDNLD.exe
c:\program files\LimeWireWin.exe

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Let me know how things are running now.
I was out of town for a family emergency and didn't respond in time - so hoping this can be looked at again…

This is the last information I received from jpshortstuff. I've run all scans requested and posted three logs below:
Hi,

We are getting there. You have a fair few files lying in your Program Files directory, have you put these there?

1. Please open Notepad

* Click Start , then Run
* Type notepad.exe in the Run Box.


2. Now copy/paste the entire content of the codebox below into the Notepad window:

CODE
file::
C:\sqmnoopt03.sqm
C:\sqmdata03.sqm
C:\sqmnoopt02.sqm
C:\sqmdata02.sqm
C:\sqmdata01.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt00.sqm
C:\sqmdata00.sqm
c:\windows\DUMP33ad.tmp
c:\windows\DUMP1b4e.tmp
C:\sqmdata19.sqm
C:\sqmnoopt19.sqm
C:\sqmdata18.sqm
C:\sqmnoopt18.sqm
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
C:\sqmdata16.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt15.sqm
C:\sqmdata15.sqm
c:\windows\system32\bftifgkkheftuvn.exe
c:\windows\system32\kxkfoghc.jqh
c:\WINDOWS\bgrqfetx.dll

Folder::
c:\Program Files\IntCodec

Driver::
KXKFOGHC

RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{860c2f6b-ca82-4282-9187-beccbb66f0af}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C6B1408-FC27-4864-9B5D-F70A93A789C4}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{20E1148B-A9DB-4678-82AB-E3E72B0F2959}]

Registry::
[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{860c2f6b-ca82-4282-9187-beccbb66f0af}]
[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C6B1408-FC27-4864-9B5D-F70A93A789C4}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{20E1148B-A9DB-4678-82AB-E3E72B0F2959}]
[-HKEY_LOCAL_MACHINE\System\ControlSet003\Services\KXKFOGHC]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-

FileLook::
c:\program files\AOLDNLD.exe
c:\program files\LimeWireWin.exe


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.



5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:

* Combofix.txt
* A new HijackThis log.



Please go to Kaspersky website and perform an online antivirus scan.

1. Read through the requirements and privacy statement and click on Accept button.
2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
3. When the downloads have finished, click on Settings.
4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Mail databases
5. Click on My Computer under Scan.
6. Once the scan is complete, it will display the results. Click on View Scan Report.
7. You will see a list of infected items there. Click on Save Report As….
8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
9. Please post this log in your next reply.

Let me know how things are running now.


ComboFix 09-04-22.02 - Family 04/21/2009 16:38.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.210 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Family\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
C:\sqmdata00.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata15.sqm
C:\sqmdata16.sqm
C:\sqmdata17.sqm
C:\sqmdata18.sqm
C:\sqmdata19.sqm
C:\sqmnoopt00.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt15.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt17.sqm
C:\sqmnoopt18.sqm
C:\sqmnoopt19.sqm
c:\windows\bgrqfetx.dll
c:\windows\DUMP1b4e.tmp
c:\windows\DUMP33ad.tmp
c:\windows\system32\bftifgkkheftuvn.exe
c:\windows\system32\kxkfoghc.jqh
.

((((((((((((((((((((((((( Files Created from 2009-03-22 to 2009-04-22 )))))))))))))))))))))))))))))))
.

2009-04-16 01:18 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-16 01:18 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 01:18 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 01:18 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-16 01:18 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 01:18 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 01:18 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 01:18 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 01:18 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 01:17 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 01:17 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 01:17 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\system32\scripting
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\l2schemas
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\system32\en
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\system32\bits
2009-04-14 22:25 . 2009-04-14 22:35 ——– d—–w c:\windows\ServicePackFiles
2009-04-14 22:07 . 2009-04-14 22:07 ——– d—–w c:\windows\EHome
2009-04-10 19:49 . 2009-04-10 19:48 410984 —-a-w c:\windows\system32\deploytk.dll
2009-04-10 19:12 . 2009-04-10 19:12 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-10 19:11 . 2009-04-10 19:11 ——– d—–w c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com
2009-04-10 09:01 . 2009-04-16 09:07 1374 —-a-w c:\windows\imsins.BAK
2009-04-09 20:11 . 2009-04-09 20:15 ——– d—–w C:\fixwareout
2009-04-09 20:08 . 2004-07-17 17:35 67866 ——w c:\windows\system32\drivers\netwlan5.img
2009-04-09 20:07 . 2007-09-17 08:48 1261 ——w c:\windows\system32\pid.inf
2009-04-09 20:02 . 2009-04-09 20:02 ——– d—–w c:\documents and settings\Family\Local Settings\Application Data\Mozilla
2009-04-09 19:53 . 2009-02-06 11:08 2189056 -c—-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-09 19:53 . 2009-02-06 11:06 2145280 -c—-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-09 19:53 . 2009-02-06 10:32 2023936 -c—-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-09 19:53 . 2009-02-08 01:02 2066048 -c—-w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-09 19:51 . 2008-10-24 11:21 455296 -c—-w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-09 19:51 . 2008-12-11 10:57 333952 -c—-w c:\windows\system32\dllcache\srv.sys
2009-04-09 19:51 . 2008-04-11 19:04 691712 -c—-w c:\windows\system32\dllcache\inetcomm.dll
2009-04-09 19:50 . 2008-10-15 16:34 337408 -c—-w c:\windows\system32\dllcache\netapi32.dll
2009-04-09 19:10 . 2009-04-09 19:10 ——– d—–w c:\documents and settings\All Users\Application Data\nView_Profiles
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\documents and settings\Family\Application Data\Malwarebytes
2009-04-09 18:57 . 2009-04-06 21:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-09 18:57 . 2009-04-06 21:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-09 17:15 . 2009-04-14 18:00 ——– d–h–w C:\$AVG8.VAULT$
2009-04-09 17:12 . 2009-04-09 17:12 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-04-09 17:12 . 2009-04-09 17:12 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-09 17:12 . 2009-04-09 17:12 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-09 17:12 . 2009-04-21 22:30 ——– d—–w c:\windows\system32\drivers\Avg
2009-04-09 17:11 . 2009-04-09 18:19 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-09 16:58 . 2009-04-21 22:28 54156 —ha-w c:\windows\QTFont.qfn
2009-04-09 16:58 . 2009-04-09 16:58 1409 —-a-w c:\windows\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-21 22:35 . 2004-11-05 22:08 36560 —-a-w c:\windows\system32\nvModes.dat
2009-04-21 22:27 . 2006-02-09 16:10 ——– d—–w c:\program files\Symantec AntiVirus
2009-04-15 21:21 . 2006-01-17 22:15 20272 —-a-w c:\documents and settings\Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-14 22:38 . 2005-12-29 01:39 77423 —-a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-14 22:19 . 2004-08-12 14:02 250048 –sha-r C:\ntldr
2009-04-10 19:48 . 2006-01-10 21:26 ——– d—–w c:\program files\Java
2009-04-10 19:40 . 2009-04-10 19:11 ——– d—–w c:\program files\SUPERAntiSpyware
2009-04-10 19:11 . 2009-04-10 19:11 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-09 20:48 . 2009-04-09 20:48 ——– d—–w c:\program files\Trend Micro
2009-04-09 19:31 . 2009-04-09 19:31 ——– d—–w c:\program files\CCleaner
2009-04-09 19:28 . 2009-04-09 19:26 ——– d—–w c:\program files\Wise Registry Cleaner
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-09 17:27 . 2008-08-11 05:47 ——– d—–w c:\documents and settings\All Users\Application Data\services
2009-04-09 17:11 . 2009-04-09 17:11 ——– d—–w c:\program files\AVG
2009-03-30 01:24 . 2008-05-18 03:31 ——– d—–w c:\program files\Apple Software Update
2009-03-30 00:52 . 2006-03-01 22:11 ——– d—–w c:\program files\Google
2009-03-06 14:22 . 2004-08-12 14:03 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-12 14:09 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-12 13:58 78336 —-a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2004-08-12 13:59 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-12 14:04 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2004-08-12 14:02 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-12 13:55 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2004-08-12 14:09 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-08 01:02 . 2004-08-03 22:59 2066048 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2004-08-12 14:05 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2004-08-12 14:02 2189056 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-12 14:04 35328 —-a-w c:\windows\system32\sc.exe
2009-02-03 19:59 . 2004-08-12 14:04 56832 —-a-w c:\windows\system32\secur32.dll
2008-08-06 19:30 . 2006-02-19 05:32 19496 —-a-w c:\documents and settings\Rob\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-12-17 17:22 . 2007-12-17 17:22 284 —-a-w c:\documents and settings\Family\Application Data\ViewerApp.dat
2007-12-03 00:38 . 2007-09-04 01:02 836 —-a-w c:\documents and settings\Rob\Application Data\ViewerApp.dat
2006-02-20 22:27 . 2006-02-20 22:27 114660 —-a-w c:\program files\AOLDNLD.exe
2006-01-13 00:44 . 2006-01-13 00:44 34816 —-a-w c:\program files\Minutes Mountain Area - 1-06.doc
2006-01-13 00:43 . 2006-01-13 00:43 36864 —-a-w c:\program files\ESS Equipment Inventory Sheet.doc
2006-01-11 21:28 . 2006-01-11 21:28 10626920 —-a-w c:\program files\RhapsodyReal.exe
2006-01-11 21:09 . 2006-01-11 21:10 774144 —-a-w c:\program files\RngInterstitial.dll
2006-01-11 21:09 . 2006-01-11 21:08 482328 —-a-w c:\program files\realarcade_comcast_stub.exe
2006-01-11 18:08 . 2006-01-11 18:07 20921040 —-a-w c:\program files\AdbeRdr705_enu_full.exe
2006-01-10 21:24 . 2006-01-10 21:24 359112 —-a-w c:\program files\LimeWireWin.exe
2006-01-10 21:19 . 2006-01-10 21:18 2625400 —-a-w c:\program files\comcast_photoshow_deluxe_4.exe
2003-04-22 17:46 . 2003-04-22 17:46 2719744 ——w c:\program files\aiodrv.msi
2003-04-22 17:42 . 2003-04-22 17:42 2588672 ——w c:\program files\aiosw.msi
2003-04-22 17:24 . 2003-04-22 17:24 16606 —-a-w c:\program files\hpomdl01.dat
2003-04-22 17:23 . 2003-04-22 17:23 267 —-a-w c:\program files\readme.html
2003-04-10 01:19 . 2003-04-10 01:19 2848 —-a-w c:\program files\hpound08.inf
2003-04-10 01:19 . 2003-04-10 01:19 14157 —-a-w c:\program files\hpousc08.inf
2003-04-10 01:00 . 2003-04-10 01:00 2889 —-a-w c:\program files\hpousb08.inf
2003-04-10 01:00 . 2003-04-10 01:00 4715 —-a-w c:\program files\hpoglu08.inf
2003-03-20 23:20 . 2003-03-20 23:20 22523 —-a-w c:\program files\HPZius12.cat
2003-03-20 23:20 . 2003-03-20 23:20 22082 —-a-w c:\program files\hpzist12.cat
2003-03-20 23:20 . 2003-03-20 23:20 24728 —-a-w c:\program files\HPZipr12.cat
2003-03-20 23:20 . 2003-03-20 23:20 22082 —-a-w c:\program files\HPZid412.cat
2003-03-20 23:20 . 2003-03-20 23:20 21641 —-a-w c:\program files\HPOunp08.cat
2003-03-20 23:20 . 2003-03-20 23:20 24285 —-a-w c:\program files\hposcu08.cat
2003-03-20 23:20 . 2003-03-20 23:20 205503 —-a-w c:\program files\hpoprn08.cat
2003-03-10 04:30 . 2003-03-10 04:30 3667 —-a-w c:\program files\hpzist12.inf
2003-03-10 04:30 . 2003-03-10 04:30 184320 —-a-w c:\program files\hpzscr07.dll
2003-03-10 04:30 . 2003-03-10 04:30 14285 —-a-w c:\program files\hpzius12.inf
2003-03-10 04:30 . 2003-03-10 04:30 10325 —-a-w c:\program files\hpzipr12.inf
2003-03-10 04:30 . 2003-03-10 04:30 63562 —-a-w c:\program files\hposcu08.inf
2003-03-10 04:30 . 2003-03-10 04:30 51266 —-a-w c:\program files\hpoprn08.inf
2003-03-10 04:30 . 2003-03-10 04:30 3898 —-a-w c:\program files\hpounp08.inf
2003-03-10 04:30 . 2003-03-10 04:30 33952 —-a-w c:\program files\hpzid412.inf
2003-03-10 04:30 . 2003-03-10 04:30 274432 —-a-w c:\program files\hpzglu07.exe
2003-03-10 04:30 . 2003-03-10 04:30 237568 —-a-w c:\program files\hpzc3212.dll
2003-03-10 04:30 . 2003-03-10 04:30 23186 —-a-w c:\program files\hpzcin06.ex_
2002-09-10 01:48 . 2002-09-10 01:48 22608 —-a-w c:\program files\usbprint.sys
2002-09-10 01:48 . 2002-09-10 01:48 12288 —-a-w c:\program files\usbmon.dll
2002-09-10 01:47 . 2002-09-10 01:47 254005 —-a-w c:\program files\msvcrt.dll
2002-09-10 01:47 . 2002-09-10 01:47 70656 —-a-w c:\program files\msvcirt.dll
2002-09-10 01:47 . 2002-09-10 01:47 55155 —-a-w c:\program files\hpzusb00.sy_
2002-09-10 01:47 . 2002-09-10 01:47 5705 —-a-w c:\program files\hpzuci02.dl_
2002-09-10 01:47 . 2002-09-10 01:47 25639 —-a-w c:\program files\hpzpom04.dl_
2002-09-10 01:47 . 2002-09-10 01:47 212992 —-a-w c:\program files\hpzpnp07.dll
2002-09-10 01:46 . 2002-09-10 01:46 49212 —-a-w c:\program files\hpzjvp01.dll
2002-09-10 01:46 . 2002-09-10 01:46 249913 —-a-w c:\program files\hpzjut01.dll
2002-09-10 01:46 . 2002-09-10 01:46 417849 —-a-w c:\program files\hpzjpp01.dll
2002-09-10 01:46 . 2002-09-10 01:46 28722 —-a-w c:\program files\hpzjlog.dll
2002-09-10 01:46 . 2002-09-10 01:46 52552 —-a-w c:\program files\hpziou01.dl_
2002-09-10 01:46 . 2002-09-10 01:46 46017 —-a-w c:\program files\hpzion00.sy_
2002-09-06 17:54 . 2002-09-06 17:54 995383 —-a-w c:\program files\MFC42.DLL
2008-09-30 22:09 . 2008-09-30 12:42 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008093020081001\index.dat
2008-10-05 03:21 . 2008-10-04 17:18 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008100420081005\index.dat
2008-10-12 20:17 . 2008-10-12 19:22 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101220081013\index.dat
2008-10-26 21:52 . 2008-10-26 21:09 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102620081027\index.dat
2008-10-28 21:39 . 2008-10-28 12:39 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102820081029\index.dat
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.


—- c:\program files\AOLDNLD.exe —-
Company: America Online, Inc.
File Description: AOL Download Utility 2.0.6.1.1
File Version: 2.0.6.1.1
Product Name: AOL Download Utility
Copyright: Copyright c 2004-2005 - America Online, Inc. All Rights Reserved.
Original file name:
File Size: 114660
Created Time: 2006-02-20 22:27
Modified Time: 2006-02-20 22:27
Accessed Time: 2009-04-21 22:38
MD5: 6BD12A800DB1D0823FAF19D22D757182
SHA: AB3458A9B476BEE6823D8EEE95E2CEAFD1E9CF9F

c:\program files\LimeWireWin.exe – Unable to find file version info.
File Size: 359112
Created Time: 2006-01-10 21:24
Modified Time: 2006-01-10 21:24
Accessed Time: 2009-04-21 22:38
MD5: 4F9BC958677DCC3C9B9AC8DE250C4E06
SHA: 6FD3B2D8546B3B938DB7614773588F16BC05B97E


((((((((((((((((((((((((((((( SnapShot@2009-04-15_21.11.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-21 22:27 . 2009-04-21 22:27 16384 c:\windows\Temp\Perflib_Perfdata_7e0.dat
+ 2004-08-12 14:10 . 2008-05-09 10:53 90112 c:\windows\system32\wshext.dll
- 2004-08-12 14:10 . 2008-04-14 00:12 90112 c:\windows\system32\wshext.dll
+ 2006-08-30 18:57 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2006-08-30 18:57 . 2007-08-11 02:46 26488 c:\windows\system32\spupdsvc.exe
- 2006-08-30 18:57 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
+ 2006-08-30 18:57 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2004-08-12 14:03 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
- 2004-08-12 14:03 . 2008-12-20 23:15 44544 c:\windows\system32\pngfilt.dll
+ 2004-08-12 14:03 . 2009-04-16 14:23 61544 c:\windows\system32\perfc009.dat
- 2004-08-12 14:03 . 2009-04-14 23:38 61544 c:\windows\system32\perfc009.dat
+ 2005-12-29 01:35 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
- 2005-12-29 01:35 . 2008-04-14 00:12 91648 c:\windows\system32\mtxoci.dll
+ 2004-08-12 14:01 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
- 2004-08-12 14:01 . 2008-04-14 00:12 66560 c:\windows\system32\mtxclu.dll
- 2006-08-23 06:31 . 2008-12-20 23:15 52224 c:\windows\system32\msfeedsbs.dll
+ 2006-08-23 06:31 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
- 2005-12-29 01:35 . 2008-04-14 00:11 58880 c:\windows\system32\msdtclog.dll
+ 2005-12-29 01:35 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
+ 2004-08-12 13:58 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2004-08-12 13:58 . 2008-12-20 23:15 27648 c:\windows\system32\jsproxy.dll
+ 2006-08-23 06:13 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
- 2006-08-23 06:13 . 2008-12-19 09:10 13824 c:\windows\system32\ieudinit.exe
- 2004-08-12 13:58 . 2008-12-20 23:15 44544 c:\windows\system32\iernonce.dll
+ 2004-08-12 13:58 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
+ 2004-08-12 13:57 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2004-08-12 13:57 . 2008-12-19 09:10 70656 c:\windows\system32\ie4uinit.exe
- 2006-08-23 06:10 . 2008-12-20 23:15 63488 c:\windows\system32\icardie.dll
+ 2006-08-23 06:10 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 90112 c:\windows\system32\dllcache\wshext.dll
+ 2009-02-03 19:59 . 2009-02-03 19:59 56832 c:\windows\system32\dllcache\secur32.dll
+ 2004-08-12 14:04 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe
+ 2004-08-12 14:03 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2004-08-12 14:03 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2007-11-11 17:56 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-11-11 17:56 . 2008-12-20 23:15 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll
- 2004-08-12 13:58 . 2008-12-20 23:15 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-12 13:58 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-11-11 17:56 . 2008-12-19 09:10 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-11-11 17:56 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2004-08-12 13:58 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
- 2004-08-12 13:58 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
- 2004-08-12 13:57 . 2008-12-19 09:10 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2004-08-12 13:57 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-11-11 17:56 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
- 2007-11-11 17:56 . 2008-12-20 23:15 63488 c:\windows\system32\dllcache\icardie.dll
+ 2006-01-13 00:45 . 2009-04-16 09:02 23040 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 23040 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 27136 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 27136 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 11264 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 11264 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 12288 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 12288 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-04-16 09:07 . 2008-12-19 09:10 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-04-16 09:07 . 2008-04-14 00:11 81920 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-04-16 09:07 . 2008-12-19 09:10 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
+ 2006-01-13 00:45 . 2009-04-16 09:02 4096 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 4096 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2004-08-12 14:10 . 2008-05-08 11:24 155648 c:\windows\system32\wscript.exe
- 2004-08-12 14:10 . 2008-04-14 00:12 155648 c:\windows\system32\wscript.exe
+ 2004-08-12 14:09 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
- 2004-08-12 14:09 . 2008-04-14 00:12 354304 c:\windows\system32\winhttp.dll
- 2004-08-12 14:09 . 2008-12-20 23:15 233472 c:\windows\system32\webcheck.dll
+ 2004-08-12 14:09 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2005-12-29 01:35 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2005-12-29 01:35 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2005-12-29 01:35 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
+ 2004-08-12 14:08 . 2008-05-09 10:53 430080 c:\windows\system32\vbscript.dll
- 2004-08-12 14:08 . 2008-12-20 23:15 105984 c:\windows\system32\url.dll
+ 2004-08-12 14:08 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
- 2004-08-12 14:04 . 2008-04-14 00:12 172032 c:\windows\system32\scrrun.dll
+ 2004-08-12 14:04 . 2008-05-09 10:53 172032 c:\windows\system32\scrrun.dll
- 2004-08-12 14:04 . 2008-04-14 00:12 180224 c:\windows\system32\scrobj.dll
+ 2004-08-12 14:04 . 2008-05-09 10:53 180224 c:\windows\system32\scrobj.dll
+ 2004-08-12 14:03 . 2009-04-16 14:23 401908 c:\windows\system32\perfh009.dat
- 2004-08-12 14:03 . 2009-04-14 23:38 401908 c:\windows\system32\perfh009.dat
+ 2004-08-12 14:02 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
- 2004-08-12 14:02 . 2008-12-20 23:15 102912 c:\windows\system32\occache.dll
- 2004-08-12 14:01 . 2008-12-20 23:15 671232 c:\windows\system32\mstime.dll
+ 2004-08-12 14:01 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
- 2004-08-12 14:01 . 2008-12-20 23:15 193024 c:\windows\system32\msrating.dll
+ 2004-08-12 14:01 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
+ 2004-08-12 14:00 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
- 2004-08-12 14:00 . 2008-12-20 23:15 477696 c:\windows\system32\mshtmled.dll
- 2006-08-23 06:31 . 2008-12-20 23:15 459264 c:\windows\system32\msfeeds.dll
+ 2006-08-23 06:31 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
+ 2005-12-29 01:35 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
- 2005-12-29 01:35 . 2008-04-14 00:11 161792 c:\windows\system32\msdtcuiu.dll
+ 2005-12-29 01:35 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
- 2005-12-29 01:35 . 2008-04-14 00:11 956928 c:\windows\system32\msdtctm.dll
+ 2005-12-29 01:35 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll
+ 2004-08-12 13:58 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
- 2004-08-12 13:58 . 2008-04-14 00:11 989696 c:\windows\system32\kernel32.dll
- 2004-08-12 13:58 . 2008-04-14 00:11 512000 c:\windows\system32\jscript.dll
+ 2004-08-12 13:58 . 2008-05-09 10:53 512000 c:\windows\system32\jscript.dll
+ 2006-08-23 06:09 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
+ 2006-08-23 05:36 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
- 2006-08-23 05:36 . 2008-12-20 23:15 383488 c:\windows\system32\ieapfltr.dll
+ 2004-08-12 13:57 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
- 2004-08-12 13:57 . 2008-12-19 05:23 161792 c:\windows\system32\ieakui.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 133120 c:\windows\system32\extmgr.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
+ 2008-05-08 11:24 . 2008-05-08 11:24 155648 c:\windows\system32\dllcache\wscript.exe
+ 2004-08-12 14:09 . 2009-03-03 00:18 826368 c:\windows\system32\dllcache\wininet.dll
- 2004-08-12 14:09 . 2008-12-20 23:15 826368 c:\windows\system32\dllcache\wininet.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
+ 2004-08-12 14:09 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
- 2004-08-12 14:09 . 2008-12-20 23:15 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 430080 c:\windows\system32\dllcache\vbscript.dll
- 2004-08-12 14:08 . 2008-12-20 23:15 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-12 14:08 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
- 2004-08-12 14:02 . 2008-12-20 23:15 102912 c:\windows\system32\dllcache\occache.dll
+ 2004-08-12 14:02 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
+ 2004-08-12 14:01 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
- 2004-08-12 14:01 . 2008-12-20 23:15 671232 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-12 14:01 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2004-08-12 14:01 . 2008-12-20 23:15 193024 c:\windows\system32\dllcache\msrating.dll
+ 2004-08-12 14:00 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2004-08-12 14:00 . 2008-12-20 23:15 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2007-11-11 17:56 . 2008-12-20 23:15 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2007-11-11 17:56 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2009-03-21 14:06 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 512000 c:\windows\system32\dllcache\jscript.dll
+ 2005-12-29 01:37 . 2009-02-28 04:54 636072 c:\windows\system32\dllcache\iexplore.exe
+ 2007-11-11 17:56 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2007-11-11 17:56 . 2008-12-20 23:15 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2007-11-11 17:56 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2004-08-12 13:57 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
- 2004-08-12 13:57 . 2008-12-19 05:23 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-05-07 09:07 . 2008-05-07 09:07 135168 c:\windows\system32\dllcache\cscript.exe
- 2004-08-12 13:55 . 2008-12-20 23:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-12 13:55 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-12 13:56 . 2008-05-07 09:07 135168 c:\windows\system32\cscript.exe
+ 2004-08-12 13:55 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
- 2004-08-12 13:55 . 2008-12-20 23:15 124928 c:\windows\system32\advpack.dll
+ 2006-01-13 00:45 . 2009-04-16 09:02 409600 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 409600 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 286720 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 286720 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 249856 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 249856 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 794624 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 794624 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 135168 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 135168 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-04-16 09:07 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-04-16 09:07 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-04-16 09:07 . 2008-12-19 05:25 634024 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-04-16 09:07 . 2008-12-19 05:23 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
+ 2004-08-12 14:08 . 2009-02-20 18:09 1160192 c:\windows\system32\urlmon.dll
- 2004-08-12 14:08 . 2008-12-20 23:15 1160192 c:\windows\system32\urlmon.dll
- 2004-08-12 14:03 . 2008-05-07 05:12 1288192 c:\windows\system32\quartz.dll
+ 2004-08-12 14:03 . 2008-12-20 22:14 1288192 c:\windows\system32\quartz.dll
+ 2009-04-09 20:08 . 2008-09-10 01:14 1307648 c:\windows\system32\msxml6.dll
+ 2004-08-12 14:00 . 2009-02-20 18:09 3595264 c:\windows\system32\mshtml.dll
+ 2006-08-23 06:31 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
+ 2006-08-11 01:44 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
- 2006-08-11 01:44 . 2007-04-17 09:32 2455488 c:\windows\system32\ieapfltr.dat
- 2004-08-12 14:08 . 2008-12-20 23:15 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-12 14:08 . 2009-02-20 18:09 1160192 c:\windows\system32\dllcache\urlmon.dll
- 2008-05-07 05:12 . 2008-05-07 05:12 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2008-05-07 05:12 . 2008-12-20 22:14 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2009-04-09 20:08 . 2008-09-10 01:14 1307648 c:\windows\system32\dllcache\msxml6.dll
+ 2004-08-12 14:00 . 2009-02-20 18:09 3595264 c:\windows\system32\dllcache\mshtml.dll
+ 2007-11-11 17:56 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
- 2007-11-11 17:56 . 2007-04-17 09:32 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2007-11-11 17:56 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-04-16 09:07 . 2008-12-20 23:15 1160192 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-04-16 09:07 . 2009-01-17 03:35 3594752 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 6066688 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-04-16 09:07 . 2007-04-17 09:32 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
+ 2009-04-09 19:53 . 2009-02-06 11:08 2189056 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2009-04-09 19:53 . 2008-08-14 09:33 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-04-09 19:53 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-04-09 19:53 . 2008-08-14 09:33 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-04-09 19:53 . 2009-02-08 01:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-04-09 19:53 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2009-04-09 19:53 . 2008-08-14 10:09 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2006-09-05 01:43 . 2009-04-06 14:57 24921544 c:\windows\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe" [2005-05-09 192512]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-10 1830128]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\program files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-19 86016]
"SigmaTel StacMon"="c:\program files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2004-04-29 90169]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 66680]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-09 1932568]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-26 4632576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil9f.exe" [2008-03-25 218496]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-01-13 22:17 110592 —-a-w c:\windows\system32\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-09 17:12 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140474985\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140474985\\ee\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2004-03-12 169192]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-09 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-09 108552]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-10 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-02-17 55024]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-09 298264]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]

.
Contents of the 'Scheduled Tasks' folder

2009-03-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 18:34]

2009-04-21 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 18:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://qwest.live.com/
mStart Page = hxxp://qwest.live.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Family\Application Data\Mozilla\Firefox\Profiles\c85z28qn.default\
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-21 16:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{20E1148B-A9DB-4678-82AB-E3E72B0F2959}\1.0]
@DACL=(02 0000)
@="bgrqfetx"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(804)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\LgNotify.dll
.
Completion time: 2009-04-21 16:43
ComboFix-quarantined-files.txt 2009-04-21 22:43
ComboFix2.txt 2009-04-16 05:35
ComboFix3.txt 2009-04-15 21:16

Pre-Run: 18,670,415,872 bytes free
Post-Run: 18,720,776,192 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=1 Sets=1,2,3,4
527 — E O F — 2009-04-16 09:08

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Tuesday, April 21, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, April 22, 2009 02:42:33
Records in database: 2067570
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 89203
Threat name: 21
Infected objects: 96
Suspicious objects: 0
Duration of the scan: 02:08:18


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00A00000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00A00001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00B00000.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00B00001.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02F80000.VBN Infected: Trojan-Downloader.Win32.Zlob.aeg 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03E80000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04040000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04040001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04040002.VBN Infected: Trojan-Downloader.Win32.Zlob.aeg 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0002.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04500000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04500001.VBN Infected: Trojan-Downloader.Win32.Zlob.agv 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04500002.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04500003.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04500004.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04540000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04680000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04800000.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04900000.VBN Infected: Trojan-Downloader.Win32.Agent.acd 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C40000.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.clk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C40001.VBN Infected: Packed.Win32.Krap.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C40002.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.kit 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C40003.VBN Infected: Packed.Win32.Krap.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05600000.VBN Infected: Trojan-Downloader.Win32.Zlob.ahd 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05600001.VBN Infected: Hoax.Win32.Renos.fh 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0002.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0003.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0004.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0005.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06240000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740000.VBN Infected: Trojan-Downloader.Win32.VB.aeq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740001.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740002.VBN Infected: Trojan-Downloader.Win32.Small.cpt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740003.VBN Infected: Trojan-Downloader.Win32.Small.cjk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740004.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740005.VBN Infected: Trojan-Downloader.Win32.Small.dam 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740006.VBN Infected: Trojan-Downloader.Win32.Small.ciw 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740007.VBN Infected: Trojan-Downloader.Win32.Zlob.ael 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740008.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740009.VBN Infected: Trojan-Downloader.Win32.Zlob.agv 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0674000A.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0674000B.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06A80000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06A80001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06E00000.VBN Infected: Trojan.Win32.Agent.qe 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06F00000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07280000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07280001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07280002.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07280003.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07500000.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07540000.VBN Infected: Trojan-Downloader.Win32.Zlob.aeg 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07640000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07940000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0000.VBN Infected: Trojan-Downloader.Win32.Zlob.ahd 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0002.VBN Infected: Packed.Win32.Krap.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0003.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.kit 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0004.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.clk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0005.VBN Infected: Packed.Win32.Krap.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0006.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.kit 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07B80000.VBN Infected: Trojan-Downloader.Win32.Zlob.ael 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07C40000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07E00000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08E00000.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.kit 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09640000.VBN Infected: Trojan-Downloader.Win32.Small.dam 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A200000.VBN Infected: Trojan.Win32.Vapsup.kew 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A5C0000.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A5C0001.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A780000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B740000.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B8C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B8C0001.VBN Infected: Trojan-Downloader.Win32.Zlob.aeg 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B8C0002.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BCC0000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BCC0001.VBN Infected: Trojan-Downloader.Win32.Zlob.agv 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C080000.VBN Infected: Hoax.Win32.Renos.fh 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680000.VBN Infected: Trojan-Downloader.Win32.VB.aeq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680001.VBN Infected: Trojan-Downloader.Win32.VB.aeq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680002.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680003.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680004.VBN Infected: Trojan-Downloader.Win32.Small.cpt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680005.VBN Infected: Trojan-Downloader.Win32.Small.cpt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680006.VBN Infected: Trojan-Downloader.Win32.Small.cjk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680008.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680009.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C68000A.VBN Infected: Trojan-Downloader.Win32.Small.dam 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C68000B.VBN Infected: Trojan-Downloader.Win32.Small.dam 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C68000C.VBN Infected: Trojan-Downloader.Win32.Small.ciw 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C68000D.VBN Infected: Trojan-Downloader.Win32.Small.ciw 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F4C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F680000.VBN Infected: Trojan-Downloader.Win32.VB.aan 1
C:\WINDOWS\system32\ayonkyyu.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ewt 1

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:24:13 PM, on 4/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\1XConfig.exe
C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Qwest Live - {3A97D3DF-91B6-4557-BCFB-381872254C87} - http://qwest.live.com (file missing) (HKCU)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 9818 bytes
Hi,

Follow instructions from this link to clean the contents of your Symantec Quarantine folder.

Please run another CFScript as before, using this code:
File::
C:\WINDOWS\system32\ayonkyyu.dll

RegLockDel::
[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{20E1148B-A9DB-4678-82AB-E3E72B0F2959}]

After that, post the ComboFix log and a new HijackThis log, and let me know how things are running.
I wanted to thank you for all the help you gave to fix this laptop. I cleared out all the quarantines and re-ran all programs and nothing was picked up. I had to give the laptop back to my buddy. It seems to be working absolutely perfect! Thanks again for all the help, feel free to close the thread.
No problem, glad I could help :thumbup:

If you do get a chance, I recommend you do this:
Click Start >> Run, and then type ComboFix /u and hit enter.

No problem, glad I could help :thumbup:

If you do get a chance, I recommend you do this:
Click Start >> Run, and then type ComboFix /u and hit enter.


great! will do.

Thanks again!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI