This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] I think I'm nearly there...

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there folks :D

Recently I've had some serious slow downs on my PC, a Dell Inspiron l9100 Pentium 4 - 3.2GHz with 1 GB RAM and 100 GB HD laptop.running XP sp3.
I also use 400 GB external storage split over two HDs on an AD-Hoc Basis for backups etc.

I even ended up losing one of the external drives… completely wiped due to corruption/crash.
(I found an absolutely excellent software suite with the right tools to reclaim pretty much all of my 75 Gb and bringing the drive back as good as new. Even the free trial was able to tell me within minutes what was on the drive and how I could get it back… I bought the "Enterprise Edition" of "Active FIle Recovery" and also installed a handy HD monitoring applet they supply for free and I'm feeling like a new man… after all the drives I've seen go to waste over the years, in various companies and always having the worry of what if… or when will it die on me… both as a techie and private user).

It also turned out that I was "sharing" my PC with some pretty unwelcome critters such as trojandropper and various trojans and other malware…

Sadly my expensive and cumbersome McAfee "Security Suite" and LavaSoft's ""Adwatch" had let me down really badly.

Since I've been let down by other big names like Norton in the past…
I did some research… and apart from having some stuff removed by running Ad-Aware SE Pro and Spybot Search & Destroy scans, I ended up downloading COMODO Free Firewall and AV suite as well as VIPRE AV trial (from Sunbelt).

I have since purchased a 3 year license for VIPRE which turned out to be very nice and light on resources and quite capable of finding and weeding out quite a few "Critters"… The free COMODO AV did pretty good too and got rid of a few other probs.

I believe my system is pretty much back to normal now but… a bit of paranoia has set in :pullhair:

Now two weeks later I'm finding myself still running scans that take for ever (approx.1/2 TB including external drives) with various tools and looking at stuff such as "Spyware Doctor" and "Registry Mechanic" from PC Tools to add to my "utility belt".

However, I feel quite opposed to spending more money on more of these tools since most of them including Spyware Doctor are very "gung ho" about their approach both to getting your money quick and about their blanket method of removal of various cookies etc.

I am tempted to spend the reasonably low amount of money on the "Registry Mechanic" since I don't have time to go trawling through the registry too much myself these days but…
yesterday I stumbled upon TWO major resources firstly "www.file.net" in Germany and later your good selves at this forum…

Another thing I did in the last couple of weeks was to run the various on-line tests at PC Pitstop which helped me clear up a few updatte issues etc. but I never joined the forum there…

Also bought and installed: eMailTrackerPro, Caller IP and Visual Trace 2008, all advanced/Pro edition, from Visualware.
As I said I'm getting paranoid these days and want to start fighting back to some extent :rant2: LOL

ONE newish problem that has occurred after the initial problems and following removal of various malware etc. is that I seem to have a problem with newly added bookmarks not staying around after close and re-open of my Firefox browser.

Anything you guys can do to help me make sure I'm rid of the pesky critters?

I very much appreciate any help you can offer.

The following is my HJT logfile after running it today:

________________________________________________________________________________
___

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:43:13, on 08/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\eMailTrackerPro 2008\eMailTrackerPro.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe
C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\LVComsX.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\1-Click Answers\answers.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\PROGRA~1\COMMON~1\GURUNE~1\agtserv.exe
C:\WINDOWS\system32\java.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\32RedMPP\MPPoker.exe
C:\Program Files\Tournament Indicator\Indicator.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\regedit.exe
C:\WINDOWS\system32\dllhost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: VIPTToolbarManager Class - {1A2641AE-2C42-4C51-A05F-8ECEC3FDC94D} - C:\Program Files\Visual IP Trace 2008\VisualIPTraceIE.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: Kwyshell MidpX BHO - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Visual IP Trace - {E70C26AE-DFF1-40A8-8D37-19180F56F0AA} - C:\Program Files\Visual IP Trace 2008\VisualIPTraceIE.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [kdx] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [eMailTrackerPro] "C:\Program Files\eMailTrackerPro 2008\eMailTrackerPro" -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Call Soft] "C:\Program Files\Call Soft Pro\CallSoftPro.exe"
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Message Centre.lnk = C:\Program Files\iflow technologies\iflow Message Centre\MessageCentre.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: 32Red Poker - {437F7F6F-FFCC-47e1-8A4B-C992493CF6C3} - C:\Program Files\32RedMPP\MPPoker.exe
O9 - Extra button: Poker Million Online Poker - {47C16927-7BDE-465a-8E68-CE9C2CBB15B7} - C:\Program Files\pokermillionMPP\MPPoker.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PacificPoker - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - C:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{06A2F0A3-0E88-45F7-9908-4237F9AAAFA3}: NameServer = 159.134.237.6,159.134.248.17
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\cssdll32.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 16595 bytes

________________________________________________________________________________
_____

I hope that's of some use.

Look forward to hearing from you.

Cheers,

Flinky :D
[external image: Posted Image]

DO NOT use any TOOLS such as Combofix, SmitfraudFix, MBAM, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.




Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
Hi LDTate,
Sorry about the slight delay in response… been quite busy the last couple of days…

Thanks for your help.

The following are the steps I have taken since my last HJT log and before your response.

Installed a trial version of PcTools Registry Mechanic… Found 1600+ problems etc. (DID NOT purchase license to get it to "fix" any problems as per Doug's advice in the meet & Greet thread)… Left "Registry Monitor" running (auto starts at boot time and sits in "Quick Launch Bar").

While waiting to see if anyone could give me a hand here I trawled your forum a bit for helpful hints etc. and came across the Kaspersky online scan which I ran 3 times before it completed (this should should have told me to stay away from their software perhaps… please read on) wasting a lot of time.
I ran this scan only on my internal C: drive in order to keep the load and time down to a minimum.

The fact that this scan came back with some positives prompted me to sign up for and install a trial version of "Kaspersky AV 2009" in order to clean out the infected files etc.

Here is part of the original online scan report:
_______________________________________________________________________________
VIRUS: C:\Documents and Settings\Flinky\Local Settings\Application Data\Microsoft\Outlook\archive.pst [294601728 : Trojan-Spy.HTML.Fraud.gen]
VIRUS: C:\Documents and Settings\Flinky\Local Settings\Application Data\Microsoft\Outlook\archive.pst [294601728 : Trojan-Spy.HTML.Fraud.gen]
_______________________________________________________________________________

Once I installed "Kaspersky AV 2009" I ran an extensive "Full" scan with every setting set to most advanced (Deep/High) with my two external Firewire Harddisks connected (one 320Gb Lacie and one 80Gb Maxtor) the scan ended up running for over 24 hours (the timer started back at 00:00 after 24 hours).

In the end I had to concede that it had somehow gone into some kind of loop since it was repeatedly showing the same .Vob files (DVD content) being scanned for a number of hours at which point I stopped the scan.

The previous day during the early stages of the scan the scan somehow managed to make the Windows "Delayed Write Failed" message appear repeatedly informing me that writing to my I:\$mft file (Maxtor Master File Table) had failed etc.

The end result was that about 75Gb of data had again been "wiped off" that drive… In my Meet & Greet message I mention having salvaged this drive using "Active@File Recovery" only a week or two ago. The problems prior to the "death" of the drive then, was also seemingly to do with Windows "Delayed Write" caching… since I got some of those messages at that time too. The drive has been working flawlessly since the recovery until Kaspersky came along.

This leads me to beg you for a piece of advice.
How do I force Windows XP Pro (sp3) to stop ALL write caching to a firewire external drive (having set the "optimized for quick disconnect" option already on both external drives obviously did NOT stop Windows from using write caching!)?


Also, could you recommend any utility which would restore just the MFT file without having to restore all the individual files?

Either way this "EXTENDED SCAN" left me with a couple of threats identified, the following is a copy of the relevant lines from the Kaspersky Trial Version scan:

______________________________________________________________________________

10/05/2009 18:00:15 Detected: Trojan-Spy.HTML.Fraud.gen C:\Documents and Settings\Flinky\Local Settings\Application Data\Microsoft\Outlook\archive.pst/Archive Folders\Top of Personal Folders\Inbox\[From:[removed]][Subject:Message from PayPal Customer Support:Community Support (KMM17392588V31937L0KM)][Time:2006/01/12 02:02:14]/HTMLBody
10/05/2009 18:00:16 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Documents and Settings\Flinky\Local Settings\Application Data\Microsoft\Outlook\archive.pst/Archive Folders\Top of Personal Folders\Inbox\[From:[removed]][Subject:Message from PayPal Customer Support:Community Support (KMM17392588V31937L0KM)][Time:2006/01/12 02:02:14]/HTMLBody Postponed
10/05/2009 18:05:24 Detected: Trojan-Spy.HTML.Fraud.gen C:\Documents and Settings\Flinky\Local Settings\Application Data\Microsoft\Outlook\archive.pst/Archive Folders\Top of Personal Folders\Inbox\[From:PayPal][Subject:Your Account Access Has Been Limited][Time:2006/09/06 01:22:22]/HTMLBody
10/05/2009 18:05:24 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Documents and Settings\Flinky\Local Settings\Application Data\Microsoft\Outlook\archive.pst/Archive Folders\Top of Personal Folders\Inbox\[From:PayPal][Subject:Your Account Access Has Been Limited][Time:2006/09/06 01:22:22]/HTMLBody Postponed
——————
snip snip
——————
10/05/2009 22:54:47 Detected: Exploit.HTML.Iframe.FileDownload J:\Maxtor Recovery\! Lost & Found !\FOLDER0000F3F4\mailbox.pst/LocalMailbox-Martin Flink\Top of Personal Folders\Fusion PigsFly List\[From:[removed]][Subject:Re: Your password!][Time:2002/07/15 15:24:41]/RichBody//Html2Rtf
10/05/2009 22:54:48 Untreated: Exploit.HTML.Iframe.FileDownload J:\Maxtor Recovery\! Lost & Found !\FOLDER0000F3F4\mailbox.pst/LocalMailbox-Martin Flink\Top of Personal Folders\Fusion PigsFly List\[From:[removed]][Subject:Re: Your password!][Time:2002/07/15 15:24:41]/RichBody//Html2Rtf Postponed
10/05/2009 22:57:10 Detected: Exploit.HTML.Iframe.FileDownload J:\Maxtor Recovery\! Lost & Found !\FOLDER0000F3F4\mailbox.pst/LocalMailbox-Martin Flink\Top of Personal Folders\Fusion PigsFly List\[From:Torsten Thimm, digi mice gmbh][Subject:AW: ACTR/ACCELS Transcriptions][Time:2003/01/17 09:31:55]/RichBody//Html2Rtf
10/05/2009 22:57:11 Untreated: Exploit.HTML.Iframe.FileDownload J:\Maxtor Recovery\! Lost & Found !\FOLDER0000F3F4\mailbox.pst/LocalMailbox-Martin Flink\Top of Personal Folders\Fusion PigsFly List\[From:Torsten Thimm, digi mice gmbh][Subject:AW: ACTR/ACCELS Transcriptions][Time:2003/01/17 09:31:55]/RichBody//Html2Rtf Postponed
10/05/2009 23:02:05 Detected: Exploit.HTML.Iframe.FileDownload J:\Maxtor Recovery\! Lost & Found !\FOLDER0000F3F4\mailbox.pst/LocalMailbox-Martin Flink\Top of Personal Folders\Inbox\[From:David.Cox][Subject:ERTU Urgent Issues][Time:2002/10/07 11:13:26]/RichBody//Html2Rtf
10/05/2009 23:02:05 Untreated: Exploit.HTML.Iframe.FileDownload J:\Maxtor Recovery\! Lost & Found !\FOLDER0000F3F4\mailbox.pst/LocalMailbox-Martin Flink\Top of Personal Folders\Inbox\[From:David.Cox][Subject:ERTU Urgent Issues][Time:2002/10/07 11:13:26]/RichBody//Html2Rtf Postponed
10/05/2009 23:02:48 Detected: HEUR:Worm.Win32.Generic J:\Maxtor Recovery\! Lost & Found !\FOLDER0000F3F4\mailbox.pst/LocalMailbox-Martin Flink\Top of Personal Folders\Inbox\[From:Luka Jaki][Subject:Re: According to Purge's Statement][Time:2003/01/20 11:42:00]/EntradoDePer.exe
10/05/2009 23:02:49 Untreated: HEUR:Worm.Win32.Generic J:\Maxtor Recovery\! Lost & Found !\FOLDER0000F3F4\mailbox.pst/LocalMailbox-Martin Flink\Top of Personal Folders\Inbox\[From:Luka Jaki][Subject:Re: According to Purge's Statement][Time:2003/01/20 11:42:00]/EntradoDePer.exe Postponed
11/05/2009 20:19:05 Task stopped
______________________________________________________________________________

As you can see in the above excerpt the malware was found in my Outlook archive file on the internal C: drive as well as the RECOVERED (from the the Maxtor drive) Outlook Archive on the Lacie Drive J:…

So, anything I do seems to need me to scan nearly 500 Gb worth of data…

In addition I've got warnings about a "Keylogger" at boot time:
13/05/2009 17:42:02 Detected: Keylogger DMXLAUNCHER.EXE Keylogger activity C:\PROGRAM FILES\DELL\MEDIA EXPERIENCE\DMXLAUNCHER.EXE
This I (Kaspersky) have now Quarantined (where the quarantine file is located etc. seems like a major riddle so far…)

As well as:
13/05/2009 17:21:01 Detected: Hidden object Spooler SubSystem App

This I wasn't notified about and just happened to find in one of the many reports etc. hiding inside the Kaspersky interface.

Suffice it to say I have now switched off all real-time features on Kaspersky AV even though it managed to clean most of the above threats (some reported "Not Found" when I was doing the "Disinfect" after the mammoth scan.

Kaspersky seems power hungry, cumbersome to use and somewhat unstable… is that a reasonable assumption to your knowledge? I'm asking since the fact that it found some additional infected files that all my other AV & Anti Spyware gear had missed, makes me think that it might be worth having a licence just for occasional scans - NOT Real-time protection (seems to slow down the PC quite a bit)…
One major plus however seems to be the "Parse Email" option in the scanning parameters which seems to have helped identify a few trojans as well as saved me from having to lose my whole Outlook archive files in order to clean them out :D

For Clarity I have copied the mbam and new HJT logs into a separate message to follow after this one.

Many thanks for your help and
Best regards,

Flinky :thumbup:
Hi again LDTate,

The options mentioned in your post re. file management views are my normal settings so that's Done… check.

Ran the ATF Cleaner, Didn't get any prompt even though I run FireFox (IE8 installed as well) so I went to the "FireFox" menu and went with select all… Got Prompt - left saved passwords alone.

Opened FirFox shortly after, following reboot… cookies seem unaffected when I opened them in "Tools - Options - Privacy - Show cookies"?! Doesn't worry me too much since I think I'll need some of them again for easy surfing. I just thought I'd mention it to you for info.

Did the Malwarebytes' Anti-Malware scan with the following result:

_______________________________________________________________________
Malwarebytes' Anti-Malware 1.36
Database version: 2124
Windows 5.1.2600 Service Pack 3

13/05/2009 17:17:50
mbam-log-2009-05-13 (17-17-50).txt

Scan type: Quick Scan
Objects scanned: 97521
Time elapsed: 7 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
_______________________________________________________________________

Reboot was quicker than normal but I assume part of this was due to the fact that I disabled all the real-time protection in Kaspersky prior to running mbam etc.

Interesting point perhaps was the fact that COMODO wanted to install 2-3 software updates after the reboot could this perhaps be related to the Registry data above having been removed? COMODO is hooked into MS Firewall and AV settings etc. (option during install).
I don't use COMODO AV except for occasional scans, use their Firewall - use VIPRE for active security.

The following is the new HJT log:

_________________________________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:17:38, on 14/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\eMailTrackerPro 2008\eMailTrackerPro.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\WINDOWS\system32\LVComsX.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\WINDOWS\system32\java.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: VIPTToolbarManager Class - {1A2641AE-2C42-4C51-A05F-8ECEC3FDC94D} - C:\Program Files\Visual IP Trace

2008\VisualIPTraceIE.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus

2009\ievkbd.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program

Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google

Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program

Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar

Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google

Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON

Web-To-Page.dll
O2 - BHO: Kwyshell MidpX BHO - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program

Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file

missing)
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar

Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON

Web-To-Page.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program

Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file

missing)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Visual IP Trace - {E70C26AE-DFF1-40A8-8D37-19180F56F0AA} - C:\Program Files\Visual IP Trace

2008\VisualIPTraceIE.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [kdx] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [eMailTrackerPro] "C:\Program Files\eMailTrackerPro 2008\eMailTrackerPro" -startup
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Call Soft] "C:\Program Files\Call Soft Pro\CallSoftPro.exe"
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Message Centre.lnk = C:\Program Files\iflow technologies\iflow Message Centre\MessageCentre.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar

Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky

Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: 32Red Poker - {437F7F6F-FFCC-47e1-8A4B-C992493CF6C3} - C:\Program Files\32RedMPP\MPPoker.exe
O9 - Extra button: Poker Million Online Poker - {47C16927-7BDE-465a-8E68-CE9C2CBB15B7} - C:\Program

Files\pokermillionMPP\MPPoker.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PacificPoker - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - C:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program

Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth

Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth

Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -

https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{06A2F0A3-0E88-45F7-9908-4237F9AAAFA3}: NameServer = 159.134.237.6,159.134.248.17
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google

Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs:

C:\WINDOWS\system32\cssdll32.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet

Security\cmdagent.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common

Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony

Shared\AVLib\SSScsiSV.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 16935 bytes

_________________________________________________________________________


The PC is running reasonably ok but is still a bit slower than I remember.

Sure there are quite a few various apps and utilities loaded up during start-up… I even exit some manually once booting is finished most of the times. AD Watch is one example which strangely runs up to over 200 Mb according to Task Manager so I unload that one after the initial boot is finished.

That's all I can think of right now.

Thanks again for your help LD.

Best regards,

Flinky :thumbup:
Some late breaking info for you LD…

The problem with adding bookmarks in FireFox is still present (adding ok… but gone after closing and re-starting FireFox).

FireFox is still taking quite a while to boot up… more so than I remember prior to infestation being found.

I have installed quite a few "Add-ons" recently, most of which would be script blockers and similar but I am still surprised that the FireFox app these days is clocking up 130+ Mb and often quite a bit more in Task Mgr while running…

Will disable all but the most important Add-Ons and see if there is a difference…

UPDATE: Tried the above - Less add-ons and found FireFox now using just under 93 Mb…

The Maxtor 80 Gb drive is back…?!
I decided to boot up with the external drives today to see if there was any difference in system performance…
Boot took a while longer than yesterday but otherwise same performance.

I would still really value your help forcing XPs "Delayed Write" to fully off so I don't have to worry about the small hardware cache available etc. on the Maxtor drive any more. This drive is if nothing else of sentimental value apart from a handy backup unit. It still performs very well apart from the mentioned problems.

I look forward to hearing from you again in due course.

Cheers,

Flinky :thumbup:
I can help you with the Malware/Virus issues but the rest you'll need to use our Tech Team for.
Once I feel you are clean of any Malware/Virus, I'll give you a link to the Tech Team.


Click: Start > All Programs> Accessories
Open Notepad, click on Format and uncheck Word Wrap.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".

Also please describe how your computer behaves at the moment.
Hi LDTate,

The PC is definitely a lot zippier after the ComboFix run.
Apps open and close a fair bit quicker for example.

I also seem to have a bit more Physical memory available after booting as well as a slightly smaller pagefile…

Its very early days since the scan only finished some 20-30 minutes ago and I haven't had time to run any heavy duty apps & tasks yet but there is certainly an improvement…

Again its too early to comment but one of the things that seems to have been very sluggish lately has been the graphic redraws etc. of things like icons on the desktop and overlapping windows etc. particularly under higher CPU loads.
Seems quite a bit better at first glance though…

As can be seen in the top part of the ComboFix log:
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
This is a bit strange… it started the download and after a short while a message came up stating that there was an error in downloading it. It also stated that it would continue wiith scan without deleting any files…

It did however delete a number of files according to the running text echo in the DOS window.

I thought Recovery was the option to start up with Last Known Good etc. during a re-boot (F8)? This I have as an option a.f.a.i.k.

Could you give me a download link and I'll try manually to get it installed in any case?


The following is the ComboFix Log:

_____________________________________________________________
ComboFix 09-05-14.03 - Flinky 14/05/2009 23:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.358 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Flinky\LOCALS~1\Temp\X99FC0\hswin32v13.dll
c:\docume~1\Flinky\LOCALS~1\Temp\X99FC0\TrayIcon12.dll
c:\documents and settings\Flinky\Local Settings\Temp\X99FC0\hswin32v13.dll
c:\documents and settings\Flinky\Local Settings\Temp\X99FC0\TrayIcon12.dll
c:\documents and settings\Flinky\x.exe
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\IE4 Error Log.txt
c:\windows\system32\azip32.dll
c:\windows\system32\dzgtactx.dll
c:\windows\system32\FTPx.dll
c:\windows\system32\MabryObj.dll

.
((((((((((((((((((((((((( Files Created from 2009-04-14 to 2009-05-14 )))))))))))))))))))))))))))))))
.

2009-05-13 17:35 . 2009-05-13 17:35 272 —-a-w c:\windows\system32\drivers\sfi.dat
2009-05-13 16:06 . 2009-05-13 16:06 ——– d—–w c:\documents and settings\Flinky\Application Data\Malwarebytes
2009-05-13 16:06 . 2009-04-06 14:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-13 16:06 . 2009-04-06 14:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-13 16:06 . 2009-05-13 16:06 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-13 16:06 . 2009-05-13 16:06 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-10 13:37 . 2009-05-10 13:37 ——– d-sh–w c:\documents and settings\NetworkService\IETldCache
2009-05-10 13:36 . 2009-05-10 13:46 101287 —-a-w c:\windows\system32\drivers\klin.dat
2009-05-10 13:36 . 2009-05-10 13:46 89601 —-a-w c:\windows\system32\drivers\klick.dat
2009-05-10 13:34 . 2009-05-14 22:40 10300448 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-10 13:34 . 2009-05-14 22:40 966688 –sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-10 13:34 . 2009-05-10 13:34 ——– d—–w c:\program files\Kaspersky Lab
2009-05-10 13:34 . 2009-05-14 22:44 ——– d—–w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-05-10 13:22 . 2009-05-10 13:22 ——– d—–w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-09 08:51 . 2009-05-09 08:51 ——– d-sh–w c:\documents and settings\Flinky\IETldCache
2009-05-09 08:22 . 2009-05-09 08:22 ——– d—–w c:\windows\ie8updates
2009-05-09 08:21 . 2009-04-25 05:30 102400 ——w c:\windows\system32\dllcache\iecompat.dll
2009-05-09 08:16 . 2009-05-09 08:21 ——– dc-h–w c:\windows\ie8
2009-05-08 16:14 . 2009-05-08 16:14 ——– d—–w c:\program files\ERUNT
2009-05-08 13:54 . 2009-05-08 13:54 ——– d—–w c:\program files\Trend Micro
2009-05-07 15:31 . 2009-05-07 15:44 ——– d—–w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-05-07 15:30 . 2009-05-07 15:30 ——– d—–w c:\program files\Security Task Manager
2009-05-06 22:51 . 2009-05-06 22:51 ——– d—–w c:\documents and settings\Flinky\Visual IP Trace
2009-05-06 22:51 . 2009-05-06 22:51 ——– d—–w c:\program files\Visual IP Trace 2008
2009-05-06 03:25 . 2009-05-06 03:25 ——– d—–w c:\documents and settings\Flinky\CallerIP
2009-05-06 03:11 . 2009-05-06 03:11 ——– d—–w c:\documents and settings\Flinky\dsc
2009-05-06 02:39 . 2009-05-06 02:39 ——– d—–w c:\documents and settings\Flinky\VisualRoute
2009-05-06 02:39 . 2009-05-06 02:39 ——– d—–w c:\program files\VisualRoute Lite Edition
2009-05-06 02:33 . 2009-05-06 22:51 ——– d—–w c:\documents and settings\Flinky\vw
2009-05-06 02:33 . 2009-05-06 02:33 ——– d—–w c:\documents and settings\Flinky\eMailTrackerPro
2009-05-06 02:33 . 2009-05-08 13:21 ——– d—–w c:\program files\eMailTrackerPro 2008
2009-05-06 02:32 . 2009-05-08 13:21 ——– d—–w c:\program files\CallerIP
2009-05-05 12:10 . 2009-05-05 12:10 ——– d—–w c:\documents and settings\All Users\Application Data\Free Labs
2009-05-04 22:23 . 2009-05-04 22:23 ——– d—–w c:\documents and settings\Flinky\Local Settings\Application Data\www.pkrgen.com
2009-05-04 22:18 . 2009-05-04 22:18 ——– d—–w c:\program files\PKRGEN.com
2009-05-04 21:57 . 2009-05-04 21:59 ——– d—–w C:\89bd038585aee080a68a
2009-05-04 13:33 . 2009-05-04 13:33 ——– d—–w c:\temp\852810837
2009-05-03 23:28 . 2009-05-03 23:28 ——– d—–w c:\temp\111884575
2009-05-03 06:38 . 2009-05-03 06:38 ——– d—–w c:\documents and settings\Flinky\Local Settings\Application Data\COMODO
2009-04-26 05:06 . 2009-04-26 05:06 253688 —-a-w c:\windows\system32\cssdll32.dll
2009-04-26 05:06 . 2009-04-26 05:06 ——– d—–w c:\program files\AskBarDis
2009-04-26 05:04 . 2009-04-26 11:42 ——– d—–w c:\documents and settings\All Users\Application Data\Comodo
2009-04-26 05:04 . 2009-05-13 16:49 168208 —-a-w c:\windows\system32\guard32.dll
2009-04-26 05:04 . 2009-05-13 16:49 132640 —-a-w c:\windows\system32\drivers\cmdguard.sys
2009-04-26 05:04 . 2009-05-13 16:49 24096 —-a-w c:\windows\system32\drivers\cmdhlp.sys
2009-04-26 05:04 . 2009-04-26 05:06 ——– d—–w c:\program files\COMODO
2009-04-26 04:26 . 2009-05-10 12:37 108 —-a-w c:\documents and settings\Flinky\Application Data\netstat.bat
2009-04-25 13:10 . 2009-03-04 22:30 69936 —-a-w c:\windows\system32\drivers\sbapifs.sys
2009-04-25 13:10 . 2008-09-12 08:38 13360 —-a-w c:\windows\system32\drivers\sbaphd.sys
2009-04-25 12:46 . 2009-04-25 12:46 ——– d—–w c:\documents and settings\Flinky\Application Data\Sunbelt
2009-04-25 12:45 . 2009-04-25 12:45 ——– d—–w c:\documents and settings\All Users\Application Data\Sunbelt
2009-04-25 12:40 . 2008-10-09 08:48 202928 —-a-w c:\windows\system32\drivers\sbtis.sys
2009-04-25 12:40 . 2009-04-25 12:40 ——– d—–w c:\program files\Sunbelt Software
2009-04-25 12:11 . 2006-11-01 11:48 33664 —-a-w c:\windows\system32\drivers\BCMWLNPF.SYS
2009-04-25 12:11 . 2006-11-01 11:48 86016 —-a-w c:\windows\system32\preflib.dll
2009-04-25 12:11 . 2006-11-01 11:48 44032 —-a-w c:\windows\system32\wltrynt.dll
2009-04-25 12:11 . 2006-11-01 11:48 69632 —-a-w c:\windows\system32\bcmwlpkt.dll
2009-04-25 12:11 . 2006-11-01 11:48 1392640 —-a-w c:\windows\system32\WLTRAY.EXE
2009-04-25 12:11 . 2006-11-01 11:48 2129920 —-a-w c:\windows\system32\WLBCGCBPRO731.DLL
2009-04-25 12:11 . 2006-11-01 11:48 757760 —-a-w c:\windows\system32\bcm1xsup.dll
2009-04-23 09:59 . 2009-04-23 09:59 ——– d—–w c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-04-23 09:59 . 2009-04-23 09:59 ——– d—–w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-04-23 09:59 . 2009-04-23 09:59 ——– d—–w c:\program files\SDHelper (Spybot - Search & Destroy)
2009-04-23 09:59 . 2009-04-23 09:59 ——– d—–w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-04-23 03:36 . 2009-04-23 03:36 ——– d—–w c:\program files\PCPitstop
2009-04-18 10:32 . 2009-04-18 10:32 ——– d—–w c:\program files\Active Data Recovery Services
2009-04-18 03:23 . 2009-05-14 22:44 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-18 03:23 . 2009-04-18 03:23 ——– d—–w c:\program files\LSoft Technologies Inc
2009-04-18 03:18 . 2009-04-18 03:18 ——– d—–w c:\documents and settings\All Users\Application Data\ParetoLogic
2009-04-18 03:15 . 2009-04-18 03:15 ——– d—–w c:\documents and settings\All Users\Application Data\Cached Installations
2009-04-16 12:32 . 2009-03-06 14:22 284160 ——w c:\windows\system32\dllcache\pdh.dll
2009-04-16 12:32 . 2009-02-06 10:39 35328 ——w c:\windows\system32\dllcache\sc.exe
2009-04-16 12:32 . 2009-02-09 12:10 401408 ——w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 12:32 . 2009-02-06 11:11 110592 ——w c:\windows\system32\dllcache\services.exe
2009-04-16 12:32 . 2009-02-09 12:10 473600 ——w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 12:32 . 2009-02-06 10:10 227840 ——w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 12:32 . 2009-02-09 12:10 453120 ——w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 12:32 . 2009-02-09 12:10 729088 ——w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 12:32 . 2009-02-09 12:10 617472 ——w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 12:32 . 2009-02-09 12:10 714752 ——w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 12:29 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 12:29 . 2008-04-21 12:08 215552 ——w c:\windows\system32\dllcache\wordpad.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-14 22:43 . 2005-12-06 14:37 ——– d—–w c:\program files\Plaxo
2009-05-14 22:40 . 2009-05-10 13:34 83648 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-14 22:40 . 2009-05-10 13:34 5432 –sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-14 20:51 . 2006-04-30 18:11 ——– d—–w c:\program files\32RedMPP
2009-05-14 20:48 . 2007-05-27 19:59 ——– d—–w c:\program files\Tournament Indicator
2009-05-10 13:46 . 2008-01-29 16:29 33808 —-a-w c:\windows\system32\drivers\klbg.sys
2009-05-10 13:28 . 2005-05-12 20:35 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-09 13:53 . 2008-11-08 14:18 ——– d—–w c:\program files\PokerStars
2009-05-08 13:35 . 2005-01-27 12:15 ——– d—–w c:\program files\Java
2009-05-06 21:11 . 2008-10-01 03:47 ——– d—–w c:\program files\Ultra Fractal 5
2009-05-06 21:11 . 2005-09-12 09:04 ——– d—–w c:\program files\PacificPoker
2009-05-05 14:33 . 2006-11-18 18:09 ——– d—–w c:\program files\Holdem Indicator
2009-05-04 23:00 . 2005-08-17 10:29 ——– d—–w c:\program files\Winamp
2009-05-04 22:22 . 2005-02-03 19:56 94552 —-a-w c:\documents and settings\Flinky\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-04 14:46 . 2007-02-25 20:59 ——– d—–w c:\program files\McAfee
2009-05-04 00:19 . 2005-01-27 12:16 ——– d–h–w c:\program files\InstallShield Installation Information
2009-05-04 00:19 . 2006-09-03 08:20 ——– d—–w c:\program files\Pinnacle
2009-05-02 13:36 . 2006-07-19 14:33 ——– d—–w c:\program files\PartyGaming
2009-04-30 21:43 . 2005-05-12 20:56 ——– d—–w c:\program files\Google
2009-04-29 21:25 . 2005-12-06 17:30 ——– d—–w c:\program files\FinePixViewer
2009-04-25 12:11 . 2005-01-27 12:17 ——– d—–w c:\program files\Dell
2009-04-18 21:56 . 2006-03-15 12:26 ——– d—–w c:\program files\NCH Swift Sound
2009-04-18 21:31 . 2007-09-12 01:16 ——– d—–w c:\program files\SoundSpectrum
2009-04-18 21:06 . 2009-01-11 02:40 ——– d—–w c:\program files\Call Soft Pro
2009-04-18 21:05 . 2006-02-23 07:18 ——– d—–w c:\program files\BitLord
2009-04-18 02:18 . 2008-10-10 17:24 ——– d—–w c:\program files\Apophysis 2.0
2009-04-16 11:43 . 2008-10-22 05:40 ——– d—–w c:\program files\Nero
2009-04-14 16:15 . 2009-04-14 16:15 ——– d—–w c:\program files\Multimedia Card Reader
2009-04-13 14:59 . 2008-12-03 00:47 ——– d—–w c:\program files\XenoDream22
2009-04-09 15:29 . 2006-01-25 01:06 ——– d—–w c:\program files\BrainWave Generator
2009-04-06 17:58 . 2009-04-06 17:58 ——– d—–w c:\program files\TomTom International B.V
2009-04-06 17:57 . 2008-07-06 13:03 ——– d—–w c:\program files\TomTom HOME 2
2009-03-17 12:26 . 2009-03-17 12:26 65320 —-a-w c:\windows\system32\sbbd.exe
2009-03-09 04:19 . 2008-11-26 00:12 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-08 03:34 . 2004-08-04 05:00 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 03:34 . 2004-08-04 05:00 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 03:33 . 2004-08-04 05:00 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 03:33 . 2004-08-04 05:00 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 03:32 . 2004-08-04 05:00 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 03:32 . 2004-08-04 05:00 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 03:31 . 2004-08-04 05:00 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 03:31 . 2004-08-04 05:00 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 03:31 . 2004-08-04 05:00 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 03:22 . 2004-08-04 05:00 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-08-04 05:00 284160 —-a-w c:\windows\system32\pdh.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-06 14:20 279944 —-a-w c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"PlaxoUpdate"="c:\program files\Plaxo\3.19.0.16\PlaxoHelper_en.exe" [2009-02-09 371271]
"PlaxoSysTray"="c:\program files\Plaxo\3.19.0.16\PlaxoSysTray.exe" [2009-02-09 20480]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-04-08 251240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-10 68856]
"Start WingMan Profiler"="c:\program files\Logitech\Profiler\lwemon.exe" [2005-04-18 73728]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2007-02-05 476728]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eMailTrackerPro"="c:\program files\eMailTrackerPro 2008\eMailTrackerPro -startup" [X]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-08-21 155648]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2004-10-07 610304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"BuildBU"="c:\dell\bldbubg.exe" [2004-02-19 61440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"AWMON"="c:\progra~1\Lavasoft\AD-AWA~1\Ad-Watch.exe" [2005-05-25 517632]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-02-21 155648]
"NBKeyScan"="c:\program files\Nero\Nero BackItUp 4\NBKeyScan.exe" [2008-09-24 2254120]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-12-14 217088]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-12-14 458752]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-01 1392640]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2009-03-17 955688]
"COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2009-04-26 278264]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-05-13 1794320]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-10 406016]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-05-10 206088]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\SYSTEM32\bthprops.cpl [2008-04-14 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336]

c:\documents and settings\Flinky\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
1-Click Answers.lnk - c:\program files\1-Click Answers\answers.exe [2005-7-15 626688]
BTTray.lnk - c:\program files\Belkin\Bluetooth Software\BTTray.exe [2003-9-16 499779]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-1-27 24576]
EPSON Status Monitor 3 Environment Check(2).lnk - c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE [2005-10-16 131584]
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2008-11-30 303104]
Message Centre.lnk - c:\program files\iflow technologies\iflow Message Centre\MessageCentre.exe [2006-12-1 2891776]
Windows Desktop Search.lnk - c:\program files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe [2005-9-20 238080]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Autodesk\\3dsMax8\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\backburner\\server.exe"=
"c:\\Program Files\\Avid\\Avid Liquid 7\\Liquid_Components\\programs\\RM.exe"=
"c:\\Program Files\\Avid\\Avid Liquid 7\\Liquid_Components\\programs\\umi.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\NovaLogic\\MiG-29 Fulcrum\\Update.exe"=
"c:\\Program Files\\Macromedia\\Contribute 3\\Contribute.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver 8\\Dreamweaver.exe"=
"c:\\Program Files\\Ahead\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Quantum Intech\\emWave\\emwave.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Tournament Indicator\\Indicator.exe"=
"c:\\Program Files\\Holdem Indicator\\HoldemIndicator.exe"=
"c:\\WINDOWS\\SYSTEM32\\java.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\SYSTEM32\DRIVERS\klbg.sys [29/01/2008 17:29 33808]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\SYSTEM32\DRIVERS\cmdguard.sys [26/04/2009 06:04 132640]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\SYSTEM32\DRIVERS\cmdhlp.sys [26/04/2009 06:04 24096]
R1 sbaphd;sbaphd;c:\windows\SYSTEM32\DRIVERS\sbaphd.sys [25/04/2009 14:10 13360]
R1 sbtis;sbtis;c:\windows\SYSTEM32\DRIVERS\sbtis.sys [25/04/2009 13:40 202928]
R2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [17/03/2009 13:26 894248]
R2 sbapifs;sbapifs;c:\windows\SYSTEM32\DRIVERS\sbapifs.sys [25/04/2009 14:10 69936]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [08/04/2009 11:38 92008]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\SYSTEM32\DRIVERS\klim5.sys [30/04/2008 17:06 24592]
S1 CorexCardScan;CardScan USB Scanner;c:\windows\SYSTEM32\DRIVERS\slcorex.sys [22/11/2005 12:16 8448]
S2 Cubase32;Cubase32;c:\windows\SYSTEM32\DRIVERS\Cubase32.sys [13/08/2005 18:55 11808]
S2 IWPORT;IWPORT;\??\c:\windows\SYSTEM32\DRIVERS\IWPORT.SYS –> c:\windows\SYSTEM32\DRIVERS\IWPORT.SYS [?]
S3 ATIXPGAA;ATIXPGAA;c:\dell\drivers\R75495\atixpgaa.sys [10/03/2007 23:21 11648]
S3 SBRE;SBRE;c:\windows\SYSTEM32\DRIVERS\SBREDrv.sys [22/10/2008 17:08 92464]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0c65616-4b59-11dd-8ee0-000a3a5158e4}]
\Shell\AutoRun\command - L:\InstallTomTomHOME.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Call Soft - c:\program files\Call Soft Pro\CallSoftPro.exe
HKLM-Run-DMXLauncher - c:\program files\Dell\Media Experience\DMXLauncher.exe


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: {{437F7F6F-FFCC-47e1-8A4B-C992493CF6C3} - c:\program files\32RedMPP\MPPoker.exe
IE: {{47C16927-7BDE-465a-8E68-CE9C2CBB15B7} - c:\program files\pokermillionMPP\MPPoker.exe
TCP: {06A2F0A3-0E88-45F7-9908-4237F9AAAFA3} = 159.134.237.6,159.134.248.17
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath - c:\documents and settings\Flinky\Application Data\Mozilla\Firefox\Profiles\m8xnvcx7.default\
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ie/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

—- FIREFOX POLICIES —-
pref(dom.disable_open_during_load, true);.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-14 23:44
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,b6,2c,fe,77,e3,
b8,25,80,e2,63,26,f1,3f,c8,ff,68,5d,7a,30,f0,c8,80,1a,11,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,89,e7,7c,6f,34,
33,45,66,6a,9c,d6,61,af,45,84,18,a7,39,ce,5c,a2,06,dc,78,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,98,bc,fa,50,c0,
b5,b5,47,ff,7c,85,e0,43,d4,0e,fe,79,5c,be,9f,94,94,52,6e,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,11,8c,22,44,43,
e7,9e,6c,86,8c,21,01,be,91,eb,e7,d9,42,a0,3a,37,57,b3,a7,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,91,47,5f,02,e1,
b9,40,5c,f5,1d,4d,73,a8,13,5c,05,e8,e6,ff,3b,8e,d2,d0,a8,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,f6,4c,60,06,16,
8e,a4,4c,df,20,58,62,78,6b,cf,c8,de,4d,1d,85,41,61,93,91,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,19,87,ae,7a,08,
32,75,d9,fb,a7,78,e6,12,2f,9a,ea,db,2a,78,8d,26,35,6c,5e,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,9e,89,b6,8f,e7,
05,ce,75,01,3a,48,fc,e8,04,4a,f1,c7,75,16,ef,54,df,f2,83,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,69,05,89,b8,6c,
8e,cc,7d,f6,0f,4e,58,98,5b,89,c9,3c,3f,c8,95,b5,b5,10,71,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,12,65,5b,8a,8e,
cf,2c,96,3d,ce,ea,26,2d,45,aa,78,a8,c7,11,b9,f0,04,1f,d5,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:f8,31,0f,a9,5f,a0,ec,fb,03,53,60,9c,61,
0b,8a,3e,2a,b7,cc,b5,b9,7f,41,e7,cc,35,95,a2,7b,84,3d,41,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,42,d8,84,be,c0,
db,3e,48,6c,43,2d,1e,aa,22,2f,9c,a4,77,b8,83,8c,1c,e6,b9,6c,43,2d,1e,aa,22,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1432)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(1488)
c:\windows\system32\guard32.dll

- - - - - - - > 'explorer.exe'(188)
c:\windows\system32\guard32.dll
c:\program files\Plaxo\3.19.0.16\plx_hook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\SYSTEM32\WLTRYSVC.EXE
c:\windows\SYSTEM32\BCMWLTRY.EXE
c:\windows\SYSTEM32\LEXBCES.EXE
c:\windows\SYSTEM32\LEXPPS.EXE
c:\program files\Common Files\EPSON\EBAPI\eEBSvc.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Belkin\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\Nero\Nero BackItUp 4\IoctlSvc.exe
c:\windows\SYSTEM32\snmp.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\windows\SYSTEM32\wscntfy.exe
c:\windows\SYSTEM32\rundll32.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\windows\SYSTEM32\LVCOMSX.EXE
c:\program files\eMailTrackerPro 2008\eMailTrackerPro.exe
c:\windows\SYSTEM32\java.exe
.
**************************************************************************
.
Completion time: 2009-05-14 23:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-14 22:56

Pre-Run: 18,360,848,384 bytes free
Post-Run: 18,408,943,616 bytes free

415 — E O F — 2009-05-05 17:07

_____________________________________________________________



AND HERE IS THE HJT LOG run just before this post:


______________________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:22:51, on 15/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\LVComsX.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\eMailTrackerPro 2008\eMailTrackerPro.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe
C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\WINDOWS\system32\java.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: VIPTToolbarManager Class - {1A2641AE-2C42-4C51-A05F-8ECEC3FDC94D} - C:\Program Files\Visual IP Trace 2008\VisualIPTraceIE.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: Kwyshell MidpX BHO - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Visual IP Trace - {E70C26AE-DFF1-40A8-8D37-19180F56F0AA} - C:\Program Files\Visual IP Trace 2008\VisualIPTraceIE.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [kdx] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [eMailTrackerPro] "C:\Program Files\eMailTrackerPro 2008\eMailTrackerPro" -startup
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Message Centre.lnk = C:\Program Files\iflow technologies\iflow Message Centre\MessageCentre.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: 32Red Poker - {437F7F6F-FFCC-47e1-8A4B-C992493CF6C3} - C:\Program Files\32RedMPP\MPPoker.exe
O9 - Extra button: Poker Million Online Poker - {47C16927-7BDE-465a-8E68-CE9C2CBB15B7} - C:\Program Files\pokermillionMPP\MPPoker.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{06A2F0A3-0E88-45F7-9908-4237F9AAAFA3}: NameServer = 159.134.237.6,159.134.248.17
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 16627 bytes

______________________________________________________________

=====================
END OF LOGS
=====================

Again many thanks for your help :D


Cheers,

Flinky :thumbup:
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated) {964FCE60-0B18-4D30-ADD6-EB178909041C}

Never install more than one Antivirus or Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously!
The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time.
Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown.



Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

Folder::
c:\temp\852810837
c:\temp\111884575
c:\program files\AskBarDis

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
[-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Hi LDTate,

Sadly I fell asleep on top of my PC ( :blush: ) in the early hours of Friday morning and it was my wife's birthday too so I couldn't post again until now.

Update regarding PC behaviour:

Outlook 2003 with "Business Contact Manager" no longer has any Business Contact Manager!
I get error messages about not being able to connect with the database… etc. and they keep popping up now and again but Outlook works (the BCM parts etc. are all gone!). However, it takes quite a while to load OUTLOOK now and it does some blanking out of the interface except the bordering window, before coming back… followed by the error messages mentioned above.

Since I never actually got around to start using the BCM yet I might just live with a complete un-install of it… the problem is that I might not be able to find my original installation CD for it when I finally need it (which I am expecting to be a possibility).

The RECOVERY CONSOLE might also be an important enough app to install… do you have a link that works or is it just a matter of hitting Microsuck and search.

FireFox is still not keeping any bookmarks I add for some reason!?

Apart from that the PC seems a lot less sluggish at this point.

Regarding my multiple AV apps.:
I'm fully aware of the possibility of clashes and other horrors but as I mentioned previously I am only using VIPRE AV for active protection and COMODO Firewall (the COMODO combo with AV is installed with all AV etc. switched off) The COMODO AV has only been used to clean up some of my infections using AD-HOC scanning.

Kaspersky is a trial version I installed to get rid of some pesky trojans etc. particularly in my Outlook archives (following an online scan which found these in the first place) and I have switched all its activities to off.

I'm thinking of getting rid of it rather than paying for another license fee for a piece of kit I would only rarely use and then only for maintenance scanning… Kaspersky seemed to make the PC quite sluggish when I tried using its various AV features in realtime (having switched off VIPRE of course).

I would value your opinions on my choices? So far I'm very happy with COMODO firewall and VIPRE…
McAfee was what I was using until I discovered all the crud that had been let in by it, obviously over quite a long period of time.
So my current security solutions are new to me and I went with this pairing after a fair bit of web research but any info/advice you can give would be very much appreciated.

Here are the logs…

COMBOFIX LOG
_______________________________________________________________
ComboFix 09-05-14.03 - Flinky 15/05/2009 1:42.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.400 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Flinky\Desktop\CFScript.txt
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Flinky\LOCALS~1\Temp\X9EAD4\hswin32v13.dll
c:\docume~1\Flinky\LOCALS~1\Temp\X9EAD4\TrayIcon12.dll
c:\documents and settings\Flinky\Local Settings\Temp\X9EAD4\hswin32v13.dll
c:\documents and settings\Flinky\Local Settings\Temp\X9EAD4\TrayIcon12.dll
c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Cache\020B60EC
c:\program files\AskBarDis\bar\Cache\020B6AC0.bin
c:\program files\AskBarDis\bar\Cache\020B6F54.bin
c:\program files\AskBarDis\bar\Cache\020B74F1.bin
c:\program files\AskBarDis\bar\Cache\020B782D.bin
c:\program files\AskBarDis\bar\Cache\020B7B0C.bin
c:\program files\AskBarDis\bar\Cache\020B7E19.bin
c:\program files\AskBarDis\bar\Cache\0238766D.bin
c:\program files\AskBarDis\bar\Cache\023892FE.bin
c:\program files\AskBarDis\bar\Cache\0238ACCF.bin
c:\program files\AskBarDis\bar\Cache\files.ini
c:\program files\AskBarDis\bar\History\search
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\bar\Settings\prevcfg.htm
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
c:\temp\111884575
c:\temp\111884575\helper.ssm
c:\temp\852810837
c:\temp\852810837\helper.ssm

.
((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
.

2009-05-13 17:35 . 2009-05-13 17:35 272 —-a-w c:\windows\system32\drivers\sfi.dat
2009-05-13 16:06 . 2009-05-13 16:06 ——– d—–w c:\documents and settings\Flinky\Application Data\Malwarebytes
2009-05-13 16:06 . 2009-04-06 14:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-13 16:06 . 2009-04-06 14:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-13 16:06 . 2009-05-13 16:06 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-13 16:06 . 2009-05-13 16:06 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-10 13:37 . 2009-05-10 13:37 ——– d-sh–w c:\documents and settings\NetworkService\IETldCache
2009-05-10 13:36 . 2009-05-10 13:46 101287 —-a-w c:\windows\system32\drivers\klin.dat
2009-05-10 13:36 . 2009-05-10 13:46 89601 —-a-w c:\windows\system32\drivers\klick.dat
2009-05-10 13:34 . 2009-05-15 00:49 10300448 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-10 13:34 . 2009-05-15 00:49 1007648 –sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-10 13:34 . 2009-05-10 13:34 ——– d—–w c:\program files\Kaspersky Lab
2009-05-10 13:34 . 2009-05-15 02:27 ——– d—–w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-05-10 13:22 . 2009-05-10 13:22 ——– d—–w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-09 08:51 . 2009-05-09 08:51 ——– d-sh–w c:\documents and settings\Flinky\IETldCache
2009-05-09 08:22 . 2009-05-09 08:22 ——– d—–w c:\windows\ie8updates
2009-05-09 08:21 . 2009-04-25 05:30 102400 ——w c:\windows\system32\dllcache\iecompat.dll
2009-05-09 08:16 . 2009-05-09 08:21 ——– dc-h–w c:\windows\ie8
2009-05-08 16:14 . 2009-05-08 16:14 ——– d—–w c:\program files\ERUNT
2009-05-08 13:54 . 2009-05-08 13:54 ——– d—–w c:\program files\Trend Micro
2009-05-07 15:31 . 2009-05-07 15:44 ——– d—–w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-05-07 15:30 . 2009-05-07 15:30 ——– d—–w c:\program files\Security Task Manager
2009-05-06 22:51 . 2009-05-06 22:51 ——– d—–w c:\documents and settings\Flinky\Visual IP Trace
2009-05-06 22:51 . 2009-05-06 22:51 ——– d—–w c:\program files\Visual IP Trace 2008
2009-05-06 03:25 . 2009-05-06 03:25 ——– d—–w c:\documents and settings\Flinky\CallerIP
2009-05-06 03:11 . 2009-05-06 03:11 ——– d—–w c:\documents and settings\Flinky\dsc
2009-05-06 02:39 . 2009-05-06 02:39 ——– d—–w c:\documents and settings\Flinky\VisualRoute
2009-05-06 02:39 . 2009-05-06 02:39 ——– d—–w c:\program files\VisualRoute Lite Edition
2009-05-06 02:33 . 2009-05-06 22:51 ——– d—–w c:\documents and settings\Flinky\vw
2009-05-06 02:33 . 2009-05-06 02:33 ——– d—–w c:\documents and settings\Flinky\eMailTrackerPro
2009-05-06 02:33 . 2009-05-08 13:21 ——– d—–w c:\program files\eMailTrackerPro 2008
2009-05-06 02:32 . 2009-05-08 13:21 ——– d—–w c:\program files\CallerIP
2009-05-05 12:10 . 2009-05-05 12:10 ——– d—–w c:\documents and settings\All Users\Application Data\Free Labs
2009-05-04 22:23 . 2009-05-04 22:23 ——– d—–w c:\documents and settings\Flinky\Local Settings\Application Data\www.pkrgen.com
2009-05-04 22:18 . 2009-05-04 22:18 ——– d—–w c:\program files\PKRGEN.com
2009-05-04 21:57 . 2009-05-04 21:59 ——– d—–w C:\89bd038585aee080a68a
2009-05-03 06:38 . 2009-05-03 06:38 ——– d—–w c:\documents and settings\Flinky\Local Settings\Application Data\COMODO
2009-04-26 05:06 . 2009-04-26 05:06 253688 —-a-w c:\windows\system32\cssdll32.dll
2009-04-26 05:04 . 2009-04-26 11:42 ——– d—–w c:\documents and settings\All Users\Application Data\Comodo
2009-04-26 05:04 . 2009-05-13 16:49 168208 —-a-w c:\windows\system32\guard32.dll
2009-04-26 05:04 . 2009-05-13 16:49 132640 —-a-w c:\windows\system32\drivers\cmdguard.sys
2009-04-26 05:04 . 2009-05-13 16:49 24096 —-a-w c:\windows\system32\drivers\cmdhlp.sys
2009-04-26 05:04 . 2009-04-26 05:06 ——– d—–w c:\program files\COMODO
2009-04-26 04:26 . 2009-05-10 12:37 108 —-a-w c:\documents and settings\Flinky\Application Data\netstat.bat
2009-04-25 13:10 . 2009-03-04 22:30 69936 —-a-w c:\windows\system32\drivers\sbapifs.sys
2009-04-25 13:10 . 2008-09-12 08:38 13360 —-a-w c:\windows\system32\drivers\sbaphd.sys
2009-04-25 12:46 . 2009-04-25 12:46 ——– d—–w c:\documents and settings\Flinky\Application Data\Sunbelt
2009-04-25 12:45 . 2009-04-25 12:45 ——– d—–w c:\documents and settings\All Users\Application Data\Sunbelt
2009-04-25 12:40 . 2008-10-09 08:48 202928 —-a-w c:\windows\system32\drivers\sbtis.sys
2009-04-25 12:40 . 2009-04-25 12:40 ——– d—–w c:\program files\Sunbelt Software
2009-04-25 12:11 . 2006-11-01 11:48 33664 —-a-w c:\windows\system32\drivers\BCMWLNPF.SYS
2009-04-25 12:11 . 2006-11-01 11:48 86016 —-a-w c:\windows\system32\preflib.dll
2009-04-25 12:11 . 2006-11-01 11:48 44032 —-a-w c:\windows\system32\wltrynt.dll
2009-04-25 12:11 . 2006-11-01 11:48 69632 —-a-w c:\windows\system32\bcmwlpkt.dll
2009-04-25 12:11 . 2006-11-01 11:48 1392640 —-a-w c:\windows\system32\WLTRAY.EXE
2009-04-25 12:11 . 2006-11-01 11:48 2129920 —-a-w c:\windows\system32\WLBCGCBPRO731.DLL
2009-04-25 12:11 . 2006-11-01 11:48 757760 —-a-w c:\windows\system32\bcm1xsup.dll
2009-04-23 09:59 . 2009-04-23 09:59 ——– d—–w c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-04-23 09:59 . 2009-04-23 09:59 ——– d—–w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-04-23 09:59 . 2009-04-23 09:59 ——– d—–w c:\program files\SDHelper (Spybot - Search & Destroy)
2009-04-23 09:59 . 2009-04-23 09:59 ——– d—–w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-04-23 03:36 . 2009-04-23 03:36 ——– d—–w c:\program files\PCPitstop
2009-04-18 10:32 . 2009-04-18 10:32 ——– d—–w c:\program files\Active Data Recovery Services
2009-04-18 03:23 . 2009-05-15 02:28 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-18 03:23 . 2009-04-18 03:23 ——– d—–w c:\program files\LSoft Technologies Inc
2009-04-18 03:18 . 2009-04-18 03:18 ——– d—–w c:\documents and settings\All Users\Application Data\ParetoLogic
2009-04-18 03:15 . 2009-04-18 03:15 ——– d—–w c:\documents and settings\All Users\Application Data\Cached Installations
2009-04-16 12:32 . 2009-03-06 14:22 284160 ——w c:\windows\system32\dllcache\pdh.dll
2009-04-16 12:32 . 2009-02-06 10:39 35328 ——w c:\windows\system32\dllcache\sc.exe
2009-04-16 12:32 . 2009-02-09 12:10 401408 ——w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 12:32 . 2009-02-06 11:11 110592 ——w c:\windows\system32\dllcache\services.exe
2009-04-16 12:32 . 2009-02-09 12:10 473600 ——w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 12:32 . 2009-02-06 10:10 227840 ——w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 12:32 . 2009-02-09 12:10 453120 ——w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 12:32 . 2009-02-09 12:10 729088 ——w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 12:32 . 2009-02-09 12:10 617472 ——w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 12:32 . 2009-02-09 12:10 714752 ——w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 12:29 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 12:29 . 2008-04-21 12:08 215552 ——w c:\windows\system32\dllcache\wordpad.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 02:27 . 2005-12-06 14:37 ——– d—–w c:\program files\Plaxo
2009-05-15 00:49 . 2009-05-10 13:34 83648 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-15 00:49 . 2009-05-10 13:34 5572 –sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-15 00:40 . 2006-04-30 18:11 ——– d—–w c:\program files\32RedMPP
2009-05-15 00:30 . 2007-05-27 19:59 ——– d—–w c:\program files\Tournament Indicator
2009-05-10 13:46 . 2008-01-29 16:29 33808 —-a-w c:\windows\system32\drivers\klbg.sys
2009-05-10 13:28 . 2005-05-12 20:35 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-09 13:53 . 2008-11-08 14:18 ——– d—–w c:\program files\PokerStars
2009-05-08 13:35 . 2005-01-27 12:15 ——– d—–w c:\program files\Java
2009-05-06 21:11 . 2008-10-01 03:47 ——– d—–w c:\program files\Ultra Fractal 5
2009-05-06 21:11 . 2005-09-12 09:04 ——– d—–w c:\program files\PacificPoker
2009-05-05 14:33 . 2006-11-18 18:09 ——– d—–w c:\program files\Holdem Indicator
2009-05-04 23:00 . 2005-08-17 10:29 ——– d—–w c:\program files\Winamp
2009-05-04 22:22 . 2005-02-03 19:56 94552 —-a-w c:\documents and settings\Flinky\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-04 14:46 . 2007-02-25 20:59 ——– d—–w c:\program files\McAfee
2009-05-04 00:19 . 2005-01-27 12:16 ——– d–h–w c:\program files\InstallShield Installation Information
2009-05-04 00:19 . 2006-09-03 08:20 ——– d—–w c:\program files\Pinnacle
2009-05-02 13:36 . 2006-07-19 14:33 ——– d—–w c:\program files\PartyGaming
2009-04-30 21:43 . 2005-05-12 20:56 ——– d—–w c:\program files\Google
2009-04-29 21:25 . 2005-12-06 17:30 ——– d—–w c:\program files\FinePixViewer
2009-04-25 12:11 . 2005-01-27 12:17 ——– d—–w c:\program files\Dell
2009-04-18 21:56 . 2006-03-15 12:26 ——– d—–w c:\program files\NCH Swift Sound
2009-04-18 21:31 . 2007-09-12 01:16 ——– d—–w c:\program files\SoundSpectrum
2009-04-18 21:06 . 2009-01-11 02:40 ——– d—–w c:\program files\Call Soft Pro
2009-04-18 21:05 . 2006-02-23 07:18 ——– d—–w c:\program files\BitLord
2009-04-18 02:18 . 2008-10-10 17:24 ——– d—–w c:\program files\Apophysis 2.0
2009-04-16 11:43 . 2008-10-22 05:40 ——– d—–w c:\program files\Nero
2009-04-14 16:15 . 2009-04-14 16:15 ——– d—–w c:\program files\Multimedia Card Reader
2009-04-13 14:59 . 2008-12-03 00:47 ——– d—–w c:\program files\XenoDream22
2009-04-09 15:29 . 2006-01-25 01:06 ——– d—–w c:\program files\BrainWave Generator
2009-04-06 17:58 . 2009-04-06 17:58 ——– d—–w c:\program files\TomTom International B.V
2009-04-06 17:57 . 2008-07-06 13:03 ——– d—–w c:\program files\TomTom HOME 2
2009-03-17 12:26 . 2009-03-17 12:26 65320 —-a-w c:\windows\system32\sbbd.exe
2009-03-09 04:19 . 2008-11-26 00:12 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-08 03:34 . 2004-08-04 05:00 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 03:34 . 2004-08-04 05:00 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 03:33 . 2004-08-04 05:00 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 03:33 . 2004-08-04 05:00 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 03:32 . 2004-08-04 05:00 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 03:32 . 2004-08-04 05:00 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 03:31 . 2004-08-04 05:00 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 03:31 . 2004-08-04 05:00 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 03:31 . 2004-08-04 05:00 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 03:22 . 2004-08-04 05:00 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-08-04 05:00 284160 —-a-w c:\windows\system32\pdh.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-14_22.44.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-15 00:23 . 2009-05-15 00:23 16384 c:\windows\Temp\Perflib_Perfdata_dcc.dat
- 2009-05-14 17:16 . 2009-05-14 17:16 16384 c:\windows\Temp\Perflib_Perfdata_7cc.dat
+ 2009-05-15 00:51 . 2009-05-15 00:51 16384 c:\windows\Temp\Perflib_Perfdata_7cc.dat
+ 2009-05-15 00:51 . 2009-05-15 00:51 16384 c:\windows\Temp\Perflib_Perfdata_56c.dat
+ 2009-05-15 00:51 . 2009-05-15 00:51 16384 c:\windows\Temp\Perflib_Perfdata_4e4.dat
+ 2005-02-03 19:03 . 2009-05-15 02:12 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2005-02-03 19:03 . 2009-05-14 22:42 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2005-02-03 19:03 . 2009-05-14 22:42 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2005-02-03 19:03 . 2009-05-15 02:12 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-02-03 19:03 . 2009-05-14 22:42 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2005-02-03 19:03 . 2009-05-15 02:12 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2009-05-15 02:28 . 2009-05-15 02:28 544768 c:\windows\ERDNT\AutoBackup\15-05-2009\Users\00000002\UsrClass.dat
+ 2009-05-15 02:28 . 2005-10-20 11:02 163328 c:\windows\ERDNT\AutoBackup\15-05-2009\ERDNT.EXE
+ 2009-05-15 02:28 . 2009-05-15 02:28 11382784 c:\windows\ERDNT\AutoBackup\15-05-2009\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"PlaxoUpdate"="c:\program files\Plaxo\3.19.0.16\PlaxoHelper_en.exe" [2009-02-09 371271]
"PlaxoSysTray"="c:\program files\Plaxo\3.19.0.16\PlaxoSysTray.exe" [2009-02-09 20480]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-04-08 251240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-10 68856]
"Start WingMan Profiler"="c:\program files\Logitech\Profiler\lwemon.exe" [2005-04-18 73728]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2007-02-05 476728]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eMailTrackerPro"="c:\program files\eMailTrackerPro 2008\eMailTrackerPro -startup" [X]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-08-21 155648]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2004-10-07 610304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"BuildBU"="c:\dell\bldbubg.exe" [2004-02-19 61440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"AWMON"="c:\progra~1\Lavasoft\AD-AWA~1\Ad-Watch.exe" [2005-05-25 517632]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-02-21 155648]
"NBKeyScan"="c:\program files\Nero\Nero BackItUp 4\NBKeyScan.exe" [2008-09-24 2254120]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-12-14 217088]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-12-14 458752]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-01 1392640]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2009-03-17 955688]
"COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2009-04-26 278264]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-05-13 1794320]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-10 406016]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-05-10 206088]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\SYSTEM32\bthprops.cpl [2008-04-14 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336]

c:\documents and settings\Flinky\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
1-Click Answers.lnk - c:\program files\1-Click Answers\answers.exe [2005-7-15 626688]
BTTray.lnk - c:\program files\Belkin\Bluetooth Software\BTTray.exe [2003-9-16 499779]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-1-27 24576]
EPSON Status Monitor 3 Environment Check(2).lnk - c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE [2005-10-16 131584]
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2008-11-30 303104]
Message Centre.lnk - c:\program files\iflow technologies\iflow Message Centre\MessageCentre.exe [2006-12-1 2891776]
Windows Desktop Search.lnk - c:\program files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe [2005-9-20 238080]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Autodesk\\3dsMax8\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\backburner\\server.exe"=
"c:\\Program Files\\Avid\\Avid Liquid 7\\Liquid_Components\\programs\\RM.exe"=
"c:\\Program Files\\Avid\\Avid Liquid 7\\Liquid_Components\\programs\\umi.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\NovaLogic\\MiG-29 Fulcrum\\Update.exe"=
"c:\\Program Files\\Macromedia\\Contribute 3\\Contribute.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver 8\\Dreamweaver.exe"=
"c:\\Program Files\\Ahead\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Quantum Intech\\emWave\\emwave.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Tournament Indicator\\Indicator.exe"=
"c:\\Program Files\\Holdem Indicator\\HoldemIndicator.exe"=
"c:\\WINDOWS\\SYSTEM32\\java.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\SYSTEM32\DRIVERS\klbg.sys [29/01/2008 17:29 33808]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\SYSTEM32\DRIVERS\cmdguard.sys [26/04/2009 06:04 132640]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\SYSTEM32\DRIVERS\cmdhlp.sys [26/04/2009 06:04 24096]
R1 sbaphd;sbaphd;c:\windows\SYSTEM32\DRIVERS\sbaphd.sys [25/04/2009 14:10 13360]
R1 sbtis;sbtis;c:\windows\SYSTEM32\DRIVERS\sbtis.sys [25/04/2009 13:40 202928]
R2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [17/03/2009 13:26 894248]
R2 sbapifs;sbapifs;c:\windows\SYSTEM32\DRIVERS\sbapifs.sys [25/04/2009 14:10 69936]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [08/04/2009 11:38 92008]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\SYSTEM32\DRIVERS\klim5.sys [30/04/2008 17:06 24592]
S1 CorexCardScan;CardScan USB Scanner;c:\windows\SYSTEM32\DRIVERS\slcorex.sys [22/11/2005 12:16 8448]
S2 Cubase32;Cubase32;c:\windows\SYSTEM32\DRIVERS\Cubase32.sys [13/08/2005 18:55 11808]
S2 IWPORT;IWPORT;\??\c:\windows\SYSTEM32\DRIVERS\IWPORT.SYS –> c:\windows\SYSTEM32\DRIVERS\IWPORT.SYS [?]
S3 ATIXPGAA;ATIXPGAA;c:\dell\drivers\R75495\atixpgaa.sys [10/03/2007 23:21 11648]
S3 SBRE;SBRE;c:\windows\SYSTEM32\DRIVERS\SBREDrv.sys [22/10/2008 17:08 92464]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0c65616-4b59-11dd-8ee0-000a3a5158e4}]
\Shell\AutoRun\command - L:\InstallTomTomHOME.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: {{437F7F6F-FFCC-47e1-8A4B-C992493CF6C3} - c:\program files\32RedMPP\MPPoker.exe
IE: {{47C16927-7BDE-465a-8E68-CE9C2CBB15B7} - c:\program files\pokermillionMPP\MPPoker.exe
TCP: {06A2F0A3-0E88-45F7-9908-4237F9AAAFA3} = 159.134.237.6,159.134.248.17
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath - c:\documents and settings\Flinky\Application Data\Mozilla\Firefox\Profiles\m8xnvcx7.default\
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ie/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

—- FIREFOX POLICIES —-
pref(dom.disable_open_during_load, true);.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-15 03:27
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,b6,2c,fe,77,e3,
b8,25,80,e2,63,26,f1,3f,c8,ff,68,5d,7a,30,f0,c8,80,1a,11,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,89,e7,7c,6f,34,
33,45,66,6a,9c,d6,61,af,45,84,18,a7,39,ce,5c,a2,06,dc,78,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,98,bc,fa,50,c0,
b5,b5,47,ff,7c,85,e0,43,d4,0e,fe,79,5c,be,9f,94,94,52,6e,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,11,8c,22,44,43,
e7,9e,6c,86,8c,21,01,be,91,eb,e7,d9,42,a0,3a,37,57,b3,a7,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,91,47,5f,02,e1,
b9,40,5c,f5,1d,4d,73,a8,13,5c,05,e8,e6,ff,3b,8e,d2,d0,a8,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,f6,4c,60,06,16,
8e,a4,4c,df,20,58,62,78,6b,cf,c8,de,4d,1d,85,41,61,93,91,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,19,87,ae,7a,08,
32,75,d9,fb,a7,78,e6,12,2f,9a,ea,db,2a,78,8d,26,35,6c,5e,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,9e,89,b6,8f,e7,
05,ce,75,01,3a,48,fc,e8,04,4a,f1,c7,75,16,ef,54,df,f2,83,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,69,05,89,b8,6c,
8e,cc,7d,f6,0f,4e,58,98,5b,89,c9,3c,3f,c8,95,b5,b5,10,71,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,12,65,5b,8a,8e,
cf,2c,96,3d,ce,ea,26,2d,45,aa,78,a8,c7,11,b9,f0,04,1f,d5,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:f8,31,0f,a9,5f,a0,ec,fb,03,53,60,9c,61,
0b,8a,3e,2a,b7,cc,b5,b9,7f,41,e7,cc,35,95,a2,7b,84,3d,41,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,42,d8,84,be,c0,
db,3e,48,6c,43,2d,1e,aa,22,2f,9c,a4,77,b8,83,8c,1c,e6,b9,6c,43,2d,1e,aa,22,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1428)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(1484)
c:\windows\system32\guard32.dll

- - - - - - - > 'explorer.exe'(1376)
c:\windows\system32\guard32.dll
c:\program files\Plaxo\3.19.0.16\plx_hook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\SYSTEM32\WLTRYSVC.EXE
c:\windows\SYSTEM32\BCMWLTRY.EXE
c:\windows\SYSTEM32\LEXBCES.EXE
c:\windows\SYSTEM32\LEXPPS.EXE
c:\program files\Common Files\EPSON\EBAPI\eEBSvc.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Belkin\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\Nero\Nero BackItUp 4\IoctlSvc.exe
c:\windows\SYSTEM32\snmp.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\windows\SYSTEM32\wscntfy.exe
c:\program files\Apoint\ApntEx.exe
c:\windows\SYSTEM32\rundll32.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\eMailTrackerPro 2008\eMailTrackerPro.exe
c:\windows\SYSTEM32\LVCOMSX.EXE
c:\windows\SYSTEM32\java.exe
c:\progra~1\COMMON~1\GURUNE~1\agtserv.exe
.
**************************************************************************
.
Completion time: 2009-05-15 3:39 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-15 02:39
ComboFix2.txt 2009-05-14 22:57

Pre-Run: 18,380,423,168 bytes free
Post-Run: 18,295,259,136 bytes free

442 — E O F — 2009-05-05 17:07

_______________________________________________________________



Here's the most current HJT log file:

________________________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:38:35, on 16/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\eMailTrackerPro 2008\eMailTrackerPro.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe
C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\WINDOWS\system32\LVComsX.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\1-Click Answers\answers.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\COMMON~1\GURUNE~1\agtserv.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\WINDOWS\system32\java.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: VIPTToolbarManager Class - {1A2641AE-2C42-4C51-A05F-8ECEC3FDC94D} - C:\Program Files\Visual IP Trace 2008\VisualIPTraceIE.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: Kwyshell MidpX BHO - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Visual IP Trace - {E70C26AE-DFF1-40A8-8D37-19180F56F0AA} - C:\Program Files\Visual IP Trace 2008\VisualIPTraceIE.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [kdx] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [eMailTrackerPro] "C:\Program Files\eMailTrackerPro 2008\eMailTrackerPro" -startup
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Message Centre.lnk = C:\Program Files\iflow technologies\iflow Message Centre\MessageCentre.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: 32Red Poker - {437F7F6F-FFCC-47e1-8A4B-C992493CF6C3} - C:\Program Files\32RedMPP\MPPoker.exe
O9 - Extra button: Poker Million Online Poker - {47C16927-7BDE-465a-8E68-CE9C2CBB15B7} - C:\Program Files\pokermillionMPP\MPPoker.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{06A2F0A3-0E88-45F7-9908-4237F9AAAFA3}: NameServer = 159.134.237.6,159.134.248.17
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 16526 bytes

________________________________________________________________

==================
END OF LOGS
==================

I look forward to hearing from you again.

Many thanks.

Flinky :thumbup:
We need to do a little cleanup.

Here's a link to the Tech Team area for the software issues you're having. Start a new topic and add a link to your link here.
Explain what issues still exist.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

Close ALL windows and browsers except HijackThis and click "Fix checked"


After the above:

Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    To be on the safe side, I would also change all my passwords.


    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Thank You LDTate! :D

I decided to dump the Business Contact Manager for now since I found the original Office Installation CDs…
This sorted out the Outlook problem properly (tried "repair" options etc. first but this didn't work).
I can't even remember having seen Outlook quite this fast before :D

The PC is generally running very well now, so far so good :thumbup:

I used your link and posted on the Windows Forum re. the hard disk problems and the Recovery Console.

Do you think I should be checking every app. I have for any problems similar to the BCM just to be sure… before I go ahead and delete my old backup and replace it with a backup of this nice "clean" PC?

The bookmark problem in FireFox I mentioned was sorted out after a bit of research on the web.

When you say "Update all these programs regularly - Make sure you update all the programs I have listed regularly." what are you referring to? The utilities I used to do the various scan & fix jobs while we were taking out the malware?

That leads me to my last question… Should I use any of the apps. we used for this clean up job, again, for maintenance scans or similar?

A couple of little details I found regarding the final run of ComboFix that might be worth a mention… The standard windows convention of "Don't show:" hidden or system files and "don't show known file extensions" is automatically applied as part of this procedure (a bit of a surprise to me… and I found myself wondering what happened to my .exe files etc. :rofl: ). No Biggie… I put it all back the way I like it…

The other more important issue to perhaps be aware of is the automatic application of the MAX setting in the Windows Restore settings for all your drives… That could be quite a significant amount of diskspace being reserved… and in my case it would (over time) have used up approx. 75% of the remaining space (quite limited currently) on my C: drive and on my 320 Gb drive it was reserving something like 35 Gb. A bit wasteful I'd say :oops:

Thank you so much for all your help LDTate… you Rock! :notworthy:


Cheers :pepsi:

Flinky :thumbup:

Do you think I should be checking every app. I have for any problems similar to the BCM just to be sure… before I go ahead and delete my old backup and replace it with a backup of this nice "clean" PC?

It wouldn't hurt.

When you say "Update all these programs regularly - Make sure you update all the programs I have listed regularly." what are you referring to? The utilities I used to do the various scan & fix jobs while we were taking out the malware?

Your anti-virus program and Windows updates.

That leads me to my last question… Should I use any of the apps. we used for this clean up job, again, for maintenance scans or similar?

I would keep ATF Cleaner and MBAM. Run them once a week.

Great job :thumbup:

You're more then welcome.
Glad we were able to help

Peace be with you :wavey:
Hello again LDTate :D

Sadly I found a "Backdoor" virus during a routine VIPRE quick scan on Wednesday :(

I had been doing very little regarding internet activity, just downloading the suggested spyware utilities (in the linked: "So how did I get infected in the first place? - by Tony Klein" message.

BTW, it seems that two of the utilities he recommends: "SpywareBlaster" & "SpywareGuard" are quite old with no updates past 2004 or something… I installed them but I'm just wondering how useful they might be? Do you know?

The only other real changes on the PC was to do with installation of a PCMCIA pro audio card (Audigy from Creative Labs)… this included a very longwinded (extremely slow download speed) update proceedure of all the installed software (I ended up having to try again after a reboot before this worked).

So I'm now wondering if there might be something else (OLD or NEW) hidden on the PC that we might have missed… something that perhaps is pretending (very well) to be a part of the MS arsenal of dlls and executables or something similar?

For example I have found "system" and "Svchost" activities on some ports that my research suggests might be malware related: 137, 138 and 445… I also found out that these ports are stealthed outside my system by my service provider by using the port scan features at:
http://www.grc.com/port_137.htm (and 445.htm)… So I wonder what this might be.
I also see a fair bit of blocked 192.168.1.255 traffic from my PC which I also wonder about (I know it should be relating to your local network but I'm worried now…LOL).

FYI I do have a wireless router in case some of this has to do with that and this would be the only "networking" I am currently doing.
I see quite a bit of UDP and ICMP stuff being blocked at the above mentioned ports, currently incoming from the router's address… would this be normal activity which should be allowed for handshaking etc.?

I have set my COMODO firewall to alert me and block just about anything at this point (including if a fly farts in our backgarden…) since I'm getting seriously paranoid at this point. :pullhair:

I'm sorry if this is all seem a bit overly paranoid but it is just worrying me that I found serious malware popping up so soon again…

Any help or comforting words you can offer would be greatly appreciated as usual :D

Cheers,

Flinky :thumbup:
You have tech questions that I can't answer. After we see what this scan finds I'll give you a like to the Tech Forums

http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
Hello again LDTate :D Thanks for the swift answer! I left my external drives on so it was quite a long time scanning… All it reported was 2 occurences of AskSBar application from Nero install packs… Here's the log: _____________________________________________________________________ ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.5863 # api_version=3.0.2 # EOSSerial=df8ccf68631c84489fb74892a3c9b2fd # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-05-23 06:49:06 # local_time=2009-05-23 07:49:06 (+0000, GMT Daylight Time) # country="Ireland" # lang=9 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=258 61 100 100 524454375000 # compatibility_mode=1281 61 100 99 10981671718750 # compatibility_mode=3073 61 80 88 573710468750 # scanned=1081 # found=0 # cleaned=0 # scan_time=282 esets_scanner_update returned -1 esets_gle=53251 # version=6 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.5863 # api_version=3.0.2 # EOSSerial=df8ccf68631c84489fb74892a3c9b2fd # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-05-23 11:46:13 # local_time=2009-05-23 12:46:13 (+0000, GMT Daylight Time) # country="Ireland" # lang=9 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=258 61 100 100 184936562500 # compatibility_mode=1281 61 100 99 11159943281250 # compatibility_mode=3073 61 80 88 177048593750 # scanned=396998 # found=2 # cleaned=0 # scan_time=17568 C:\Downloads\Nero\Nero-9.0.9.4c_update.exe Win32/Toolbar.AskSBar application 00000000000000000000000000000000 C:\Downloads\Nero\Nero_BackItUp-4.0.38.0c_update.exe Win32/Toolbar.AskSBar application 00000000000000000000000000000000 ________________________________________________________________________________ __________________________ Anything else I can do? Cheers, Flinky :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI