This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] pc running real slow and getting loads of ads and porn p

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, i have a problem with cpu usage it only started recently. Something seems to be running that i can't see in the task manager and it's taking up a lot of cpu usage. Say i have a normally low cpu usage app running like alcohol 120 or winrar they normally only use a few percent but it goes upto 100% and everything starts to freeze even turning firefox on does it like now i can see that firefox is only using 7% and nothing else is taking up any cpu but it's upto 100% and running really slow. Winrar takes like 30 minutes to unrar a 700MB movie when before it took less than a minute. Even running word freezes the pc. This computer has athlon 3500 running xp and it's normally pretty quick running apps even a few at once but now if i try to burn a dvd using ashampoo and use the internet at the same time it comes to a standstill! And encoding a movie has gone from 30 minutes to over 3 hours. I had a fragment problem as my hdd was full and i had 120,000 fragments but deleted 25% of hdd and defragged it now i have only a few hundred fragments even though diskeeper reports also that i have 79% data and 64% volume fragmentation and in the file structure display its nearly all red and red is for fragmented but in the file performance display its nearly all blue for high performing files! I haven't got a clue but something is seriously affecting the performance of this pc can anybody please help? I have given as much info as ive got and it didn't start after installing a new app also doing a restore doesn't make any difference and there aren't any viruses that i can find. I didn't know if this is part of the same problem but when ive done a search in google and open the link it goes to a different page like ads or porn it sometimes does it a few times before getting to the right page. Also i get a ton of pages coming up when i use sites like mediafire like with one link i get 5 pages even though im running ad-aware, stopzilla, avast a/v and sygate firewall. I've done av scans with avast, ad-aware and anti trojan elite they didn't find anything. Thanks for any help Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:27:49, on 16/07/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\WINDOWS\system32\oodag.exe C:\WINDOWS\SOUNDMAN.EXE C:\PROGRA~1\FlashGet\FlashGet.exe C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\WINDOWS\system32\slserv.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\System32\TUProgSt.exe C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\mmc.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Program Files\Anti Trojan Elite\TJEnder.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\system32\StopzillaBHO.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Flashget] C:\PROGRA~1\FlashGet\FlashGet.exe /min O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net" O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe :NO O4 - HKCU\..\Run: [DriverCure] C:\Program Files\ParetoLogic\DriverCure\DriverCure.exe -scan O8 - Extra context menu item: &Download All with FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm O8 - Extra context menu item: &Download with FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm O8 - Extra context menu item: Download Using &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{83D4213B-CD1F-472C-9B9E-BD9A974C257C}: NameServer = 85.255.112.232,85.255.112.234 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.232,85.255.112.234 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.232,85.255.112.234 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.232,85.255.112.234 O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe O23 - Service: Google Update Service (gupdate1c9fd087ed56610) (gupdate1c9fd087ed56610) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
Hi,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.

Please do the following:


  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O17 - HKLM\System\CCS\Services\Tcpip\..\{83D4213B-CD1F-472C-9B9E-BD9A974C257C}: NameServer = 85.255.112.232,85.255.112.234
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.232,85.255.112.234
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.232,85.255.112.234
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.232,85.255.112.234

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.


NEXT


STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
hi there thanks for your help i have done a combofix scan before i seen your post ill post the log to this then do what you say although it found and deleted quite a few infections including the net.net one you mentioned. I am still having problems though with slow pc and popups but not as much.

combofix log:

ComboFix 09-07-14.08 - home 16/07/2009 14:26.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.447.128 [GMT 1:00]
Running from: c:\downloads\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\home\Application Data\inst.exe
c:\windows\32827.exe
c:\windows\system32\drivers\UACkvytgpkhkvlydnnab.sys
c:\windows\system32\img_utils.dll
c:\windows\system32\imgscaler.dll
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXiadewnduncnjcbornwvkaxroctwcgwqo.dll
c:\windows\system32\net.net
c:\windows\system32\UACnroumxoqelukkjpnf.dll
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_MSIVXSERV.SYS
——-\Service_MSIVXserv.sys


((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.

2009-07-16 12:56 . 2009-07-16 12:56 ——– d—–w- c:\documents and settings\home\Application Data\Malwarebytes
2009-07-16 12:56 . 2009-07-13 12:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-16 12:56 . 2009-07-16 12:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-16 12:56 . 2009-07-13 12:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-16 12:56 . 2009-07-16 12:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-15 23:23 . 2009-07-15 23:26 ——– d—–w- c:\program files\Anti Trojan Elite
2009-07-15 23:16 . 2009-07-15 23:16 ——– d—–w- c:\program files\Trend Micro
2009-07-15 00:14 . 2009-07-15 00:14 ——– d—–w- c:\windows\system32\oodag
2009-07-15 00:11 . 2009-07-15 00:11 ——– d—–w- c:\documents and settings\home\Local Settings\Application Data\O&O
2009-07-15 00:09 . 2009-07-15 00:09 ——– d—–w- c:\program files\OO Software
2009-07-14 23:55 . 2009-07-14 23:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Raxco
2009-07-14 23:51 . 2009-07-14 23:55 ——– d—–w- c:\program files\Raxco
2009-07-13 18:06 . 2009-07-13 18:06 ——– d—–w- c:\documents and settings\home\Application Data\DriverCure
2009-07-13 18:05 . 2009-07-16 03:43 ——– d—–w- c:\documents and settings\All Users\Application Data\DriverCure
2009-07-13 18:05 . 2009-07-13 18:05 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-07-13 17:46 . 2009-07-13 17:46 ——– d—–w- C:\Inetpub
2009-07-13 17:37 . 2009-07-13 17:37 603904 —-a-w- c:\windows\system32\TUProgSt.exe
2009-07-13 17:36 . 2008-11-12 15:44 27904 —-a-w- c:\windows\system32\uxtuneup.dll
2009-07-13 17:36 . 2009-07-13 17:36 362240 —-a-w- c:\windows\system32\TuneUpDefragService.exe
2009-07-13 17:36 . 2009-07-13 17:36 ——– d—–w- c:\documents and settings\home\Application Data\TuneUp Software
2009-07-13 17:35 . 2009-07-13 17:35 ——– d—–w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-07-13 17:35 . 2009-07-13 17:36 ——– d—–w- c:\program files\TuneUp Utilities 2009
2009-07-13 17:33 . 2009-07-13 17:33 ——– d-sh–w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-07-13 04:54 . 2009-07-13 17:28 ——– d-sh–w- C:\Diskeeper
2009-07-13 00:23 . 2009-07-13 00:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Diskeeper Corporation
2009-07-13 00:23 . 2009-07-13 00:23 ——– d—–w- c:\program files\Diskeeper Corporation
2009-07-12 15:00 . 2009-07-12 15:00 ——– d—–w- c:\program files\Lavalys
2009-07-11 22:14 . 2009-07-11 22:14 ——– d—–w- c:\program files\Sateira
2009-07-09 19:39 . 2009-07-09 19:39 ——– d—–w- c:\documents and settings\home\Local Settings\Application Data\ZattooPlayer
2009-07-09 19:38 . 2009-07-09 20:01 ——– d—–w- c:\documents and settings\home\Local Settings\Application Data\Zattoo
2009-07-09 19:38 . 2009-07-09 19:38 ——– d—–w- c:\program files\Zattoo
2009-07-07 16:38 . 2009-07-07 16:38 ——– d—–w- c:\documents and settings\home\Application Data\Desktopicon
2009-07-07 16:38 . 2009-07-07 16:39 ——– d—–w- c:\program files\Unlocker
2009-07-07 11:39 . 2009-07-07 11:39 ——– d—–w- c:\program files\DVDTool
2009-07-06 03:22 . 2009-07-06 04:04 ——– d—–w- c:\program files\Dziobas Rar Player
2009-07-05 21:43 . 2009-07-05 21:43 ——– d—–w- c:\program files\VIA
2009-07-05 21:42 . 2005-03-08 09:52 1871872 —-a-w- c:\windows\system32\vticd.dll
2009-07-05 21:42 . 2005-03-08 09:50 172544 —-a-w- c:\windows\system32\drivers\vtmini.sys
2009-07-05 21:42 . 2005-03-08 09:50 3453824 —-a-w- c:\windows\system32\vtdisp.dll
2009-07-05 21:42 . 2005-03-08 02:33 53248 —-a-w- c:\windows\system32\VTTimer.exe
2009-07-05 21:42 . 2005-01-11 05:34 360448 —-a-w- c:\windows\system32\VTGamma2.dll
2009-07-05 21:42 . 2005-01-11 02:29 487424 —-a-w- c:\windows\system32\VTDisply.dll
2009-07-05 21:42 . 2005-01-11 02:24 389120 —-a-w- c:\windows\system32\VTovrlay.dll
2009-07-05 21:42 . 2004-12-08 08:03 253952 —-a-w- c:\windows\system32\VTInfo2.dll
2009-07-05 21:00 . 2001-08-17 13:02 9600 -c–a-w- c:\windows\system32\dllcache\hidusb.sys
2009-07-05 21:00 . 2001-08-17 13:02 9600 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-07-05 00:55 . 2009-07-05 00:55 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-07-05 00:35 . 2009-07-05 00:35 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-07-05 00:35 . 2009-07-05 00:37 ——– d—–w- c:\documents and settings\home\Local Settings\Application Data\Google
2009-07-05 00:35 . 2009-07-05 00:37 ——– d—–w- c:\program files\Google
2009-07-02 12:44 . 2009-07-02 12:44 4096 —-a-w- c:\windows\d3dx.dat
2009-07-02 12:41 . 2009-07-02 12:41 ——– d—–w- c:\program files\mupen64 0.5
2009-07-02 12:35 . 2009-07-02 12:35 ——– d—–w- c:\program files\1964
2009-07-02 11:58 . 2009-07-02 11:58 552 —-a-w- c:\windows\system32\d3d8caps.dat
2009-07-02 00:34 . 2009-07-02 00:34 8854 —-a-r- c:\documents and settings\home\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe
2009-07-02 00:34 . 2009-07-02 00:34 40960 —-a-r- c:\documents and settings\home\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2009-07-02 00:34 . 2009-07-02 00:34 40960 —-a-r- c:\documents and settings\home\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2009-07-02 00:34 . 2009-07-05 22:10 ——– d—–w- c:\program files\Project64 1.6
2009-06-29 19:25 . 2009-06-29 19:25 ——– d—–w- c:\program files\Rar Repair Tool
2009-06-27 10:02 . 2009-06-27 10:02 ——– d—–w- c:\windows\system32\LogFiles
2009-06-25 21:49 . 2009-06-25 21:49 ——– d—–w- c:\documents and settings\home\Local Settings\Application Data\Womble
2009-06-25 21:48 . 2009-06-25 21:48 ——– d—–w- c:\program files\Womble Multimedia
2009-06-25 03:14 . 2009-07-02 03:04 629072 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-25 03:14 . 2009-07-02 03:04 520024 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-25 03:13 . 2009-07-02 03:04 1029456 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-25 03:04 . 2009-06-26 03:04 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-25 03:03 . 2009-06-25 03:03 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-06-25 03:03 . 2009-01-18 21:43 2892112 -c–a-w- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
2009-06-25 03:02 . 2009-06-25 03:02 ——– d—–w- c:\program files\Lavasoft
2009-06-25 02:53 . 2009-06-25 02:53 ——– d—–w- c:\documents and settings\home\Application Data\URSoft
2009-06-25 02:52 . 2009-06-25 03:08 ——– d—–w- c:\program files\Your Uninstaller 2008
2009-06-25 02:15 . 2009-06-25 03:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-25 00:29 . 2009-06-25 00:29 ——– d—–w- c:\documents and settings\home\Application Data\STOPzilla!
2009-06-25 00:29 . 2009-06-25 04:42 ——– d—–w- c:\program files\STOPzilla!
2009-06-25 00:14 . 2009-06-25 00:14 ——– d—–w- c:\program files\Alwil Software
2009-06-25 00:12 . 2005-09-27 11:16 14944 —-a-w- c:\windows\system32\drivers\wg6n.sys
2009-06-25 00:12 . 2005-09-27 11:16 14944 —-a-w- c:\windows\system32\drivers\wg5n.sys
2009-06-25 00:12 . 2005-09-27 11:16 14944 —-a-w- c:\windows\system32\drivers\wg4n.sys
2009-06-25 00:12 . 2005-09-27 11:16 14944 —-a-w- c:\windows\system32\drivers\wg3n.sys
2009-06-25 00:12 . 2005-09-27 10:43 61008 —-a-w- c:\windows\system32\drivers\Teefer.sys
2009-06-25 00:12 . 2005-09-27 10:44 21075 —-a-w- c:\windows\system32\drivers\wpsdrvnt.sys
2009-06-25 00:12 . 2005-09-27 11:15 83592 —-a-w- c:\windows\system32\SSSensor.dll
2009-06-25 00:12 . 2009-06-25 00:12 ——– d—–w- c:\program files\Sygate
2009-06-25 00:12 . 2009-06-25 02:56 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-06-24 18:37 . 2009-06-24 19:07 ——– d—–w- c:\documents and settings\home\Application Data\avidemux
2009-06-24 18:37 . 2009-06-24 18:58 ——– d—–w- c:\program files\Avidemux 2.4
2009-06-24 18:33 . 2009-06-24 18:33 ——– d—–w- c:\documents and settings\home\Application Data\LEAPS
2009-06-24 18:32 . 2009-06-24 18:32 ——– d—–w- c:\documents and settings\home\Application Data\Pegasys Inc
2009-06-24 18:19 . 1999-11-19 14:49 265797 —-a-w- c:\windows\system32\pdvcodec.dll
2009-06-23 13:56 . 2009-07-04 15:54 ——– d—–w- c:\documents and settings\home\Application Data\Azureus
2009-06-23 13:31 . 2009-06-23 13:31 ——– d—–w- c:\program files\Azureus
2009-06-23 13:29 . 2009-06-23 13:32 ——– d—–w- c:\program files\BitSpirit
2009-06-23 13:14 . 2009-06-23 13:15 ——– d—–w- c:\program files\BitLord
2009-06-21 22:43 . 2009-06-21 22:43 ——– d—–w- c:\program files\CCleaner
2009-06-20 13:11 . 2009-06-20 13:11 ——– d—–w- c:\program files\Boilsoft Video Splitter
2009-06-20 00:55 . 2009-06-20 00:55 ——– d—–w- c:\program files\DVD Audio Extractor
2009-06-20 00:54 . 2009-06-20 00:54 ——– d—–w- c:\program files\AC3Filter
2009-06-20 00:54 . 2009-06-20 00:54 ——– d—–w- c:\program files\Audacity
2009-06-18 16:39 . 2009-06-18 16:39 ——– d—–w- c:\documents and settings\All Users\Application Data\UDL
2009-06-18 16:36 . 2009-06-18 16:36 ——– d—–w- c:\program files\EPSON Print CD
2009-06-18 16:30 . 2009-06-18 16:36 ——– d—–w- c:\program files\EPSON
2009-06-18 16:29 . 2004-08-03 22:01 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2009-06-18 16:29 . 2004-08-03 22:01 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2009-06-17 00:47 . 2009-06-17 00:53 ——– d—–w- c:\documents and settings\home\Application Data\SumatraPDF
2009-06-17 00:46 . 2009-06-17 00:46 ——– d—–w- c:\program files\SumatraPDF
2009-06-17 00:28 . 2009-06-17 00:28 ——– d—–w- c:\program files\Cool PDF Reader

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-16 13:43 . 2009-05-23 15:21 ——– d—–w- c:\program files\FlashGet
2009-07-16 08:19 . 2008-10-05 19:31 ——– d—–w- c:\documents and settings\home\Application Data\Vso
2009-07-16 03:38 . 2008-09-07 03:46 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-16 03:26 . 2009-05-24 23:04 ——– d—–w- c:\documents and settings\home\Application Data\uTorrent
2009-07-11 22:32 . 2009-07-11 22:32 ——– d—–w- c:\program files\Cheetah Burner
2009-07-11 22:32 . 2009-05-01 01:37 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-07 05:49 . 2009-05-29 11:47 ——– d—–w- c:\documents and settings\home\Application Data\Apple Computer
2009-07-05 19:33 . 2008-10-05 19:33 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-07-05 00:36 . 2009-05-24 22:13 ——– d—–w- c:\program files\DivX
2009-06-26 03:04 . 2009-06-26 03:04 1865064 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ToolBox\LT\ProcessWatch.exe
2009-06-24 19:14 . 2009-05-23 22:47 ——– d—–w- c:\program files\virtualdub
2009-06-24 18:22 . 2009-05-27 18:09 ——– d—–w- c:\program files\Pegasys Inc
2009-06-19 00:25 . 2009-06-02 22:48 ——– d—–w- c:\documents and settings\home\Application Data\Creative
2009-06-18 16:40 . 2009-05-01 00:21 ——– d—–w- c:\program files\Common Files\InstallShield
2009-06-18 16:34 . 2009-06-18 16:34 ——– d—–w- c:\documents and settings\home\Application Data\InstallShield
2009-06-18 16:34 . 2009-06-18 16:34 ——– d—–w- c:\documents and settings\All Users\Application Data\EPSON
2009-06-15 23:57 . 2009-06-15 23:57 ——– d—–w- c:\documents and settings\home\Application Data\ImgBurn
2009-06-15 23:32 . 2009-06-15 23:31 ——– d—–w- c:\program files\ImgBurn
2009-06-15 23:19 . 2009-06-15 23:19 ——– d—–w- c:\program files\DVD Decrypter
2009-06-15 23:15 . 2009-06-15 23:15 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-06-15 23:14 . 2009-06-15 23:14 ——– d—–w- c:\program files\DVD Shrink
2009-06-12 02:01 . 2009-06-12 02:01 ——– d—–w- c:\program files\MSXML 4.0
2009-06-09 21:20 . 2009-06-09 21:20 ——– d—–w- c:\program files\AVIJOINER
2009-06-09 21:08 . 2009-06-09 21:08 ——– d—–w- c:\program files\Boilsoft Video Joiner
2009-06-08 11:07 . 2009-06-08 11:07 232200 —-a-w- c:\windows\system32\PDBoot.exe
2009-06-08 09:00 . 2009-06-08 09:00 71696 —-a-w- c:\windows\system32\drivers\DefragFs.sys
2009-06-05 22:01 . 2008-11-03 12:03 ——– d—–w- c:\documents and settings\home\Application Data\Ahead
2009-06-05 02:30 . 2009-05-03 20:06 ——– d—–w- c:\program files\Ultra Video Joiner
2009-06-04 18:59 . 2009-06-04 18:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Thinstall
2009-06-04 18:59 . 2009-06-04 18:59 ——– d—–w- c:\program files\Adobe Audition 3.0 (Thinstalled)
2009-06-02 21:56 . 2009-06-02 21:56 ——– d—–w- c:\program files\Real Alternative
2009-06-02 21:44 . 2009-06-02 21:21 ——– d—–w- c:\program files\Creative
2009-05-30 13:39 . 2009-05-30 13:31 ——– d—–w- c:\program files\XtoDVDbot 2
2009-05-29 16:39 . 2009-05-29 16:39 ——– d—–w- c:\documents and settings\home\Application Data\Xilisoft Corporation
2009-05-29 11:47 . 2009-05-29 11:45 ——– d—–w- c:\program files\iTunes
2009-05-29 11:47 . 2009-05-29 11:45 ——– d—–w- c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-05-29 11:46 . 2009-05-29 11:46 ——– d—–w- c:\program files\iPod
2009-05-29 11:46 . 2009-05-29 11:42 ——– d—–w- c:\program files\Common Files\Apple
2009-05-29 11:45 . 2009-05-29 11:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-05-29 11:44 . 2009-05-29 11:44 ——– d—–w- c:\program files\Bonjour
2009-05-29 11:44 . 2008-10-05 21:35 ——– d—–w- c:\program files\QuickTime
2009-05-29 11:43 . 2009-05-29 11:43 ——– d—–w- c:\program files\Apple Software Update
2009-05-29 11:42 . 2009-05-29 11:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-05-29 01:59 . 2009-05-29 01:59 ——– d—–w- c:\program files\Amadis Software
2009-05-29 01:59 . 2009-05-29 01:59 ——– d—–w- c:\program files\Smallvideosoft
2009-05-29 01:55 . 2009-05-29 01:55 ——– d—–w- c:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2009-05-28 03:46 . 2009-05-28 03:46 ——– d—–w- c:\program files\Audio File Cutter
2009-05-28 01:46 . 2009-05-28 01:45 ——– d—–w- c:\program files\virtualdubmod
2009-05-27 16:15 . 2009-05-27 15:07 ——– d—–w- c:\program files\ZC Video Converter
2009-05-27 15:07 . 2009-05-27 15:07 ——– d—–w- c:\program files\Tipard Studio
2009-05-27 13:29 . 2009-05-27 13:29 ——– d—–w- c:\program files\OJOsoft
2009-05-27 13:24 . 2009-05-27 13:21 ——– d—–w- c:\program files\Ultra MKV Converter
2009-05-26 22:58 . 2009-05-26 22:58 ——– d—–w- c:\documents and settings\home\Application Data\VCDEasy
2009-05-26 22:58 . 2009-05-26 22:58 ——– d—–w- c:\program files\VCDEasy
2009-05-26 22:15 . 2009-05-18 05:01 ——– d—–w- c:\program files\Magic Burning ToolBox
2009-05-26 15:06 . 2009-05-25 22:54 ——– d—–w- c:\documents and settings\home\Application Data\LimeWire
2009-05-26 00:46 . 2009-05-26 00:46 ——– d—–w- c:\program files\Image Grabber II
2009-05-25 22:54 . 2009-05-25 22:48 ——– d—–w- c:\program files\LimeWire
2009-05-25 22:54 . 2009-05-25 22:52 ——– d—–w- c:\program files\Java
2009-05-25 22:49 . 2009-05-25 22:49 ——– d—–w- c:\program files\Common Files\Java
2009-05-25 01:14 . 2009-05-25 01:14 ——– d—–w- c:\documents and settings\home\Application Data\DivX
2009-05-24 22:14 . 2009-05-24 22:13 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-05-24 16:55 . 2009-05-24 16:55 ——– d—–w- c:\program files\GSpot
2009-05-24 00:09 . 2009-05-24 00:09 ——– d—–w- c:\documents and settings\home\Application Data\MCMPEGEnc
2009-05-24 00:08 . 2009-05-24 00:08 ——– d—–w- c:\program files\MainConcept
2009-05-24 00:03 . 2009-05-23 22:14 5 —-a-w- c:\windows\system32\SySMP3CutJoin.dat
2009-05-23 22:14 . 2009-05-23 22:14 ——– d—–w- c:\program files\AudioToolsFactory
2009-05-23 22:06 . 2009-05-23 22:06 ——– d—–w- c:\program files\Flv Audio Extractor
2009-05-23 15:24 . 2009-05-23 15:24 167376 —-a-w- c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\nm4h0lre.default\FlashGot.exe
2009-05-20 22:43 . 2009-05-20 22:43 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-05-20 22:43 . 2009-05-20 22:43 ——– d—–w- c:\program files\NCH Swift Sound
2009-05-20 21:59 . 2009-05-20 21:59 0 -c–a-w- c:\windows\nsreg.dat
2009-05-20 21:58 . 2009-05-20 21:48 ——– d—–w- c:\documents and settings\home\Application Data\GetRightToGo
2009-05-18 04:57 . 2009-05-18 04:55 ——– d—–w- c:\documents and settings\home\Application Data\DeepBurner
2009-05-18 04:54 . 2009-05-18 04:54 ——– d—–w- c:\program files\Astonsoft
2009-05-18 04:47 . 2009-05-18 04:47 ——– d—–w- c:\program files\gBurner
2009-05-18 04:41 . 2009-05-18 04:41 ——– d—–w- c:\program files\AnvSoft
2009-05-07 15:44 . 2004-08-04 06:56 344064 —-a-w- c:\windows\system32\localspl.dll
2009-05-01 01:37 . 2009-05-01 01:37 69361 —-a-w- c:\windows\Huawei ModemsUninstall.exe
2009-04-29 04:52 . 2004-08-04 06:56 659456 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:52 . 2004-08-04 06:56 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-06-12 07:27 . 2009-05-20 21:59 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Flashget"="c:\progra~1\FlashGet\FlashGet.exe" [2007-09-25 2007088]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-02 520024]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2009-04-08 2553088]
"Anti Trojan Elite"="c:\program files\Anti Trojan Elite\TJEnder.exe" [2008-10-26 3579904]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2007-04-16 577536]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck PDBoot.exe\0autocheck autochk *\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Update Agent.lnk
backup=c:\windows\pss\Update Agent.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"STOPzilla Local Service"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Huawei technologies\\Huawei UMTS Data Card\\3 USB Modem.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Documents and Settings\\home\\My Documents\\utorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\BitSpirit\\BitSpirit.exe"=
"c:\\Program Files\\Java\\jre1.5.0_03\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [25/06/2009 04:04 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 22:34 1029456]
R2 mdvrmng;Mobile IP Route Manager;c:\windows\system32\drivers\mdvrmng.sys [01/05/2009 02:37 10240]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [13/07/2009 18:37 603904]
R3 ATE_PROCMON;ATE_PROCMON;c:\program files\Anti Trojan Elite\ATEPMON.sys [16/07/2009 00:23 5969]
S2 gupdate1c9fd087ed56610;Google Update Service (gupdate1c9fd087ed56610);c:\program files\Google\Update\GoogleUpdate.exe [05/07/2009 01:35 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [16/07/2009 13:56 38160]
S4 STOPzilla Local Service;STOPzilla Local Service;c:\program files\STOPzilla!\SZNTSvc.exe [09/11/2003 11:34 45056]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-07-16 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 15:28]

2009-07-16 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 03:04]

2009-07-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-05 00:35]

2009-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-05 00:35]

2009-07-16 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-06-13 21:18]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-DriverCure - c:\program files\ParetoLogic\DriverCure\DriverCure.exe
HKLM-Run-net - c:\windows\system32\net.net


.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &Download All with FlashGet - c:\progra~1\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\progra~1\FlashGet\jc_link.htm
IE: Download Using &BitSpirit - c:\program files\BitSpirit\bsurl.htm
IE: ÓñÈÌØ¾«ÁéÏÂÔØ(&B)
FF - ProfilePath - c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\nm4h0lre.default\
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJPI150_03.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-16 14:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-606747145-1417001333-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D270F101-F2A5-6D8F-D424-86B68784E991}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abbhmaohjdnnpoemdddhihcpjlndndchmo"=hex:70,61,64,68,6f,61,64,67,65,65,6f,69,
61,67,69,61,64,6f,67,63,68,63,6e,68,64,65,68,63,69,6f,70,70,00,00
"maoglaekkjlbhehahdmakmdgnl"=hex:6f,61,62,62,6f,68,68,6f,70,6d,65,6e,67,6e,63,
67,6b,64,68,61,65,6d,64,6e,6f,6f,70,6c,69,69,00,70

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="75A6A5F539BC655CC48194B16C897D57267CE505E2FE23329CB16D1EA0544F91115930DE2D8
EACD15DA2DC01079CB336ABA187DC648D0EB7A0473BB8CF4FD8D3D9EC591D8584A179B86F4E51AB65
467BFED58C4FD2331D173E9360D55138698D8EC8108761DDA64620274B19184C218A18536C102920D
E46B8670A0FFC2755E2DF76D53694BA75ADD42CCA133D1C804963F4B59B15E7B53B4AB77BC05E1B45
7D74A3410729241AA787065A3C4204772340B80732F8FEBC9E127BECC74CFEBC9E127BECC74CFEBC9
E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AE
CB7A5D1407A6A0AC4980AC79338EDD5E5BE2F6E6673E7D0BE2EFF9410D858138CDFA9BA25D609EB6C
5E4D3B77F0D3DD3BBD2633008640CE59FB0C3E7947915F7C19EE0280C50279A7DEAB3F4B59B8EB537
9917EB1C919C70A5857F30C3CF842473027D6FACC9F9E7A59D0566AAD23625DD67198B87A4B5BBE1C
BB232758DD83E7B7D074E589E4630257016C5D66B276502E68D4ABFDFAE5FB187F246BD21F04E650B
AA625E828E0D5276C70F64042A3FE9E3A823EBE8B3F3E7DD6B0B61577E5E31CBA989410C2999FB698
F81349D5A004F51B7D86A4BC617CD1CDB64D86585FCD304D7E6B7BA4174E3A5F621581D28795F4696
EECAF4BBEA1C2F18F553E1E1BCB39B9CE12BECD541BC2D993819CC577E3EFAB8B0D1383B1502AB862
BB047C135AD1D75253B66392931242BCFF0D9FE6880CEA32AF64CC33EA447233288F6A48092BAF1A0
3A521257DD52EEB991D40B9430C1722C694A2494985D7C7DA2B3613C25C5B5862EBA5BFB54A63F8AD
CB33B62CBFB53CC86B082C9E9ECB6C1FC24220D9D38FACED11164C719B1889A6AD0A33645C407E3E4
E3D694171709F9C854649729AD0C3514294F76A427CD8407E7AC7A020DE5104C286EAC94A6BDE5EC3
3FA08E6E44A3797BB92C064E02229B09B111BDCE4D8B03928E951C70334058195890DE9C22A19B2E4
7AE63ADB30AC9B716087A3825FECDB73BC438D3CE09F55B00AD7BCCD3361EFA6A4AE7A3935F7AFD0F
E3618BF8A2D997BB1C83305CABE68A0CC9FD7B382DB0DE2045C6E3C82360889259E6F9A011E8B96E4
2B7CB48C307165F09FAFC34717FC63DEBED1CEFC5873CBDD3ED5B4FD317CFEC6389FC6D407D8E2EE9
6247246E667D45022D77F1D9176AD0A95E7544E1BED541D40C8586919BDDE8D46105658622546C7DD
A4FB71DAC8285BA8B863D45614187E1B962D1F8070076C763EAB69E3C52E0847CF1B1B6FD418DB7F4
C70871E58B0D9229B2DE11CF5E7FBF06ED2F98A0C6227B968564FD1BBBFE5A81F2BF17555E9EF3160
E2B10C0A770484D5501DBB6D228F166F4957C2CE4529B31D6BB09F5DEF53ABDD7B20B8170C1C059BC
AFB1B150C0240D7B40FCC98AFAAB5"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3396)
c:\windows\system32\msi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Raxco\PerfectDisk10\PDAgent.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Raxco\PerfectDisk10\PDEngine.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\taskmgr.exe
.
**************************************************************************
.
Completion time: 2009-07-16 14:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-16 13:49

Pre-Run: 28,255,473,664 bytes free
Post-Run: 28,285,259,776 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

353 — E O F — 2009-06-17 18:31
DDS log DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 18:27:19.54 on 16/07/2009 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.447.215 [GMT 1:00] FW: Sygate Personal Firewall Pro *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Ashampoo\Ashampoo Burning Studio 2009\burningstudio.exe C:\Program Files\Ashampoo\Ashampoo Burning Studio 2009\CancelAutoplay.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\home\Desktop\Portable MS Office 2003 Word-Excel\Thinstall\Office 2003\10000001600002i\msiexec.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\home\My Documents\covers\dds.pif ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\progra~1\flashget\jccatch.dll BHO: STOPzilla Browser Helper Object: {e3215f20-3212-11d6-9f8b-00d0b743919d} - c:\windows\system32\StopzillaBHO.dll BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\program files\flashget\getflash.dll TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll mRun: [SoundMan] SOUNDMAN.EXE mRun: [Flashget] c:\progra~1\flashget\FlashGet.exe /min mRun: [OODefragTray] c:\windows\system32\oodtray.exe mRun: [Anti Trojan Elite] c:\program files\anti trojan elite\TJEnder.exe :NO IE: &Download; All with FlashGet - c:\progra~1\flashget\jc_all.htm IE: &Download; with FlashGet - c:\progra~1\flashget\jc_link.htm IE: Download Using &BitSpirit; - c:\program files\bitspirit\bsurl.htm IE: ÓñÈÌØ¾«ÁéÏÂÔØ(&B;) IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\home\applic~1\mozilla\firefox\profiles\nm4h0lre.default\ FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre1.5.0_03\bin\NPJava11.dll FF - plugin: c:\program files\java\jre1.5.0_03\bin\NPJava12.dll FF - plugin: c:\program files\java\jre1.5.0_03\bin\NPJava13.dll FF - plugin: c:\program files\java\jre1.5.0_03\bin\NPJava14.dll FF - plugin: c:\program files\java\jre1.5.0_03\bin\NPJava32.dll FF - plugin: c:\program files\java\jre1.5.0_03\bin\NPJPI150_03.dll FF - plugin: c:\program files\java\jre1.5.0_03\bin\NPOJI610.dll ============= SERVICES / DRIVERS =============== R2 mdvrmng;Mobile IP Route Manager;c:\windows\system32\drivers\mdvrmng.sys [2009-5-1 10240] R3 ATE_PROCMON;ATE_PROCMON;c:\program files\anti trojan elite\ATEPMON.sys [2009-7-16 5969] S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?] S2 gupdate1c9fd087ed56610;Google Update Service (gupdate1c9fd087ed56610);c:\program files\google\update\GoogleUpdate.exe [2009-7-5 133104] S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-7-13 603904] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-7-16 38160] S4 STOPzilla Local Service;STOPzilla Local Service;c:\program files\stopzilla!\SZNTSvc.exe [2003-11-9 45056] S4 vsdatant;vsdatant; [x] =============== Created Last 30 ================ 2009-07-16 18:27 –d-h— c:\windows\PIF 2009-07-16 14:47 -cd—– c:\windows\system32\dllcache\cache 2009-07-16 14:23 a-dshr– C:\cmdcons 2009-07-16 14:19 219,648 a——- c:\windows\PEV.exe 2009-07-16 14:19 161,792 a——- c:\windows\SWREG.exe 2009-07-16 14:19 98,816 a——- c:\windows\sed.exe 2009-07-16 13:56 –d—– c:\docume~1\home\applic~1\Malwarebytes 2009-07-16 13:56 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-16 13:56 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-16 13:56 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-16 13:56 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-16 00:23 –d—– c:\program files\Anti Trojan Elite 2009-07-16 00:16 –d—– c:\program files\Trend Micro 2009-07-15 21:48 4,107 a——- c:\windows\system32\oodbs.lor 2009-07-15 01:51 20 a——- c:\windows\system32\PDBootState 2009-07-15 01:14 –d—– c:\windows\system32\oodag 2009-07-15 01:09 –d—– c:\program files\OO Software 2009-07-15 00:51 –d—– c:\program files\Raxco 2009-07-13 19:06 –d—– c:\docume~1\home\applic~1\DriverCure 2009-07-13 19:05 –d—– c:\docume~1\alluse~1\applic~1\ParetoLogic 2009-07-13 19:05 –d—– c:\docume~1\alluse~1\applic~1\DriverCure 2009-07-13 18:46 –d—– C:\Inetpub 2009-07-13 18:37 603,904 a——- c:\windows\system32\TUProgSt.exe 2009-07-13 18:36 27,904 a——- c:\windows\system32\uxtuneup.dll 2009-07-13 18:36 362,240 a——- c:\windows\system32\TuneUpDefragService.exe 2009-07-13 18:36 –d—– c:\docume~1\home\applic~1\TuneUp Software 2009-07-13 18:35 –d—– c:\docume~1\alluse~1\applic~1\TuneUp Software 2009-07-13 18:35 –d—– c:\program files\TuneUp Utilities 2009 2009-07-13 18:33 –dsh— c:\docume~1\alluse~1\applic~1\{55A29068-F2CE-456C-9148-C869879E2357} 2009-07-13 05:54 –dsh— C:\Diskeeper 2009-07-13 01:23 –d—– c:\docume~1\alluse~1\applic~1\Diskeeper Corporation 2009-07-13 01:23 –d—– c:\program files\Diskeeper Corporation 2009-07-12 16:00 –d—– c:\program files\Lavalys 2009-07-11 23:32 –d—– c:\program files\Cheetah Burner 2009-07-11 23:14 –d—– c:\program files\Sateira 2009-07-09 20:38 –d—– c:\program files\Zattoo 2009-07-07 17:38 –d—– c:\docume~1\home\applic~1\Desktopicon 2009-07-07 17:38 –d—– c:\program files\Unlocker 2009-07-07 12:39 –d—– c:\program files\DVDTool 2009-07-06 04:22 –d—– c:\program files\Dziobas Rar Player 2009-07-05 22:43 –d—– c:\program files\VIA 2009-07-05 22:00 9,600 ac—— c:\windows\system32\dllcache\hidusb.sys 2009-07-05 22:00 9,600 a——- c:\windows\system32\drivers\hidusb.sys 2009-07-02 13:44 4,096 a——- c:\windows\d3dx.dat 2009-07-02 13:41 –d—– c:\program files\mupen64 0.5 2009-07-02 13:35 –d—– c:\program files\1964 2009-07-02 12:58 552 a——- c:\windows\system32\d3d8caps.dat 2009-07-02 01:34 –d—– c:\program files\Project64 1.6 2009-06-29 20:25 –d—– c:\program files\Rar Repair Tool 2009-06-27 11:02 –d—– c:\windows\system32\LogFiles 2009-06-25 22:48 –d—– c:\program files\Womble Multimedia 2009-06-25 04:03 -cd-h— c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-06-25 04:02 –d—– c:\program files\Lavasoft 2009-06-25 03:53 –d—– c:\docume~1\home\applic~1\URSoft 2009-06-25 03:52 –d—– c:\program files\Your Uninstaller 2008 2009-06-25 01:29 –d—– c:\docume~1\home\applic~1\STOPzilla! 2009-06-25 01:29 –d—– c:\program files\STOPzilla! 2009-06-25 01:12 14,944 a——- c:\windows\system32\drivers\wg6n.sys 2009-06-25 01:12 14,944 a——- c:\windows\system32\drivers\wg5n.sys 2009-06-25 01:12 14,944 a——- c:\windows\system32\drivers\wg4n.sys 2009-06-25 01:12 61,008 a——- c:\windows\system32\drivers\Teefer.sys 2009-06-25 01:12 14,944 a——- c:\windows\system32\drivers\wg3n.sys 2009-06-25 01:12 21,075 a——- c:\windows\system32\drivers\wpsdrvnt.sys 2009-06-25 01:12 83,592 a——- c:\windows\system32\SSSensor.dll 2009-06-25 01:12 –d—– c:\program files\Sygate 2009-06-25 01:12 –d—– c:\program files\common files\Wise Installation Wizard 2009-06-24 19:37 –d—– c:\docume~1\home\applic~1\avidemux 2009-06-24 19:37 –d—– c:\program files\Avidemux 2.4 2009-06-24 19:33 –d—– c:\docume~1\home\applic~1\LEAPS 2009-06-24 19:32 –d—– c:\docume~1\home\applic~1\Pegasys Inc 2009-06-24 19:19 265,797 a——- c:\windows\system32\pdvcodec.dll 2009-06-24 19:19 1,199 a——- c:\windows\system32\panadv.inf 2009-06-23 14:56 –d—– c:\docume~1\home\applic~1\Azureus 2009-06-23 14:31 –d—– c:\program files\Azureus 2009-06-23 14:29 –d—– c:\program files\BitSpirit 2009-06-23 14:14 –d—– c:\program files\BitLord 2009-06-21 23:43 –d—– c:\program files\CCleaner 2009-06-20 14:11 –d—– c:\program files\Boilsoft Video Splitter 2009-06-20 01:55 –d—– c:\program files\DVD Audio Extractor 2009-06-20 01:54 538,624 a——- c:\windows\system32\ac3filter.acm 2009-06-20 01:54 –d—– c:\program files\AC3Filter 2009-06-20 01:54 –d—– c:\program files\Audacity 2009-06-18 18:37 172,247 a——- C:\Sherman_'s_Way_(2009)_R0_CUSTOM-[Front]-[www.FreeCovers.net].jpg 2009-06-18 17:39 –d—– c:\docume~1\alluse~1\applic~1\UDL 2009-06-18 17:36 –d—– c:\program files\EPSON Print CD 2009-06-18 17:34 –d—– c:\docume~1\alluse~1\applic~1\EPSON 2009-06-18 17:33 1,220 a——- c:\windows\wininit.ini 2009-06-18 17:30 –d—– c:\program files\EPSON 2009-06-18 17:29 41 a——- c:\windows\CDER285DEFGIPS.ini 2009-06-18 17:29 25,856 ac—— c:\windows\system32\dllcache\usbprint.sys 2009-06-18 17:29 25,856 a——- c:\windows\system32\drivers\usbprint.sys 2009-06-17 19:31 –d—– c:\windows\system32\ReinstallBackups 2009-06-17 19:30 118 a——- c:\windows\system32\MRT.INI 2009-06-17 01:47 –d—– c:\docume~1\home\applic~1\SumatraPDF 2009-06-17 01:46 –d—– c:\program files\SumatraPDF 2009-06-17 01:28 49 a——- c:\windows\CoolRead.ini 2009-06-17 01:28 –d—– c:\program files\Cool PDF Reader ==================== Find3M ==================== 2009-06-08 12:07 232,200 a——- c:\windows\system32\PDBoot.exe 2009-06-08 10:00 71,696 a——- c:\windows\system32\drivers\DefragFs.sys 2009-05-07 16:44 344,064 a——- c:\windows\system32\localspl.dll 2009-05-01 02:37 69,361 a——- c:\windows\Huawei ModemsUninstall.exe 2009-04-29 05:52 659,456 a——- c:\windows\system32\wininet.dll 2009-04-29 05:52 81,920 a——- c:\windows\system32\ieencode.dll 2008-10-05 20:31 47,360 a——- c:\docume~1\home\applic~1\pcouffin.sys ============= FINISH: 18:27:57.39 ===============

Attachments:

Hi,

P2P - I see you have P2P software Azureus, BitLord 1.1, BitSpirit v3.2.2.076 Beta, LimeWire PRO 4.12.11 installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Malwarebytes' Anti-Malware 1.39 Database version: 2421 Windows 5.1.2600 Service Pack 2 16/07/2009 21:55:28 mbam-log-2009-07-16 (21-55-28).txt Scan type: Quick Scan Objects scanned: 80682 Time elapsed: 8 minute(s), 45 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\DVDTool (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDTool (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\ByteLinker (Pup.BitSpirit) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\home\Start Menu\Programs\DVDTool (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Program Files\DVDTool (Trojan.DNSChanger) -> Quarantined and deleted successfully. Files Infected: c:\downloads\AdobeFlashPlayer.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully. c:\documents and settings\home\start menu\Programs\DVDTool\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully. c:\program files\DVDTool\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Kaspersky scan: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Friday, July 17, 2009 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Thursday, July 16, 2009 22:34:42 Records in database: 2477034 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 47350 Threat name: 15 Infected objects: 19 Suspicious objects: 0 Duration of the scan: 04:53:55 File name / Threat name / Threats count C:\Documents and Settings\home\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-7f8373e4-6e2ee532.zip Infected: Exploit.Java.Gimsh.b 1 C:\Documents and Settings\home\Desktop\UltimateDefragSetUpTrial.exe Infected: Trojan.Win32.Monder.gen 1 C:\Downloads\2sharefiles.com.Your.Uninstaller.Pro.v6.2.1347.Uploadede.18.06.09.rar Infected: Trojan.Win32.Buzus.bmyk 1 C:\Downloads\AdAware2008_by_joshpk\Lavasoft Ad-Aware 2008 Pro 7.1.0.10\aaw2008Pro.exe Infected: Trojan.Win32.Agent.ckeq 1 C:\Downloads\AdAware2008_by_joshpk.rar Infected: Trojan.Win32.Agent.ckeq 1 C:\Downloads\MFWarez.org.real.spy.monitor.2.85.by.s-master.rar Infected: not-a-virus:Monitor.Win32.RealSpy.b 1 C:\Downloads\MFWarez.org.real.spy.monitor.2.85.by.s-master.rar Infected: not-a-virus:Monitor.Win32.RealSpy.a 1 C:\Downloads\SRS1.9.rar Infected: Trojan.Win32.Agent.cqci 2 C:\Downloads\Ultimate_Defrag_2008_v2.0.0.51.rar Infected: Trojan.Win32.Monder.gen 1 C:\Downloads\VSO.Software.ConvertXtoDVD.3.v3.1.3.40-TE\Crack\ConvertXtoDvd.exe Infected: Trojan-Downloader.Win32.Delf.oxt 1 C:\Downloads\Xilisoft_YouTube_Video_Converter_3.1.0.0.1__Portable_.rar Infected: Trojan.Win32.Agent.ckeq 1 C:\Downloads\Xilib.rar Infected: Trojan.BAT.Agent.ms 1 C:\Downloads\Xili.rar Infected: not-a-virus:PSWTool.Win32.IEPassView.ae 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACkvytgpkhkvlydnnab.sys.vir Infected: Rootkit.Win32.Pakes.ud 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\MSIVXiadewnduncnjcbornwvkaxroctwcgwqo.dll.vir Infected: Packed.Win32.Tdss.w 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\net.net.vir Infected: Trojan-Clicker.Win32.VBiframe.vs 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\UACnroumxoqelukkjpnf.dll.vir Infected: Packed.Win32.Tdss.m 1 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\PYTZ6Y86\pore[1] Infected: Trojan-Downloader.JS.LuckySploit.q 1 The selected area was scanned. Are they false positives or real trojans because one of them is just a trial. I know it looks like i'm a thieving b'stard but i honestly don't use most of the stuff i download my pc is filled with carp** well 3/4 full now. When i do use the software it's just for testing out and i go out and buy it if i like it if not i uninstall it.

Are they false positives

No

I know it looks like i'm a thieving b'stard

Azureus, BitLord 1.1, BitSpirit v3.2.2.076 Beta, LimeWire PRO 4.12.11 <– tools of the trade
C:\Downloads\VSO.Software.ConvertXtoDVD.3.v3.1.3.40-TE\Crack\ConvertXtoDvd.exe <– evidence

When i do use the software it's just for testing out

Lesson learned - is it worth destroying your computer over?


Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Files
C:\Documents and Settings\home\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-7f8373e4-6e2ee532.zip 
C:\Documents and Settings\home\Desktop\UltimateDefragSetUpTrial.exe 
C:\Downloads\2sharefiles.com.Your.Uninstaller.Pro.v6.2.1347.Uploadede.18.06.09.rar 
C:\Downloads\AdAware2008_by_joshpk\Lavasoft Ad-Aware 2008 Pro 7.1.0.10\aaw2008Pro.exe 
C:\Downloads\AdAware2008_by_joshpk.rar 
C:\Downloads\MFWarez.org.real.spy.monitor.2.85.by.s-master.rar 
C:\Downloads\SRS1.9.rar
C:\Downloads\Ultimate_Defrag_2008_v2.0.0.51.rar
C:\Downloads\VSO.Software.ConvertXtoDVD.3.v3.1.3.40-TE\Crack\ConvertXtoDvd.exe
C:\Downloads\Xilisoft_YouTube_Video_Converter_3.1.0.0.1__Portable_.rar 
C:\Downloads\Xilib.rar 
C:\Downloads\Xili.rar 
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\PYTZ6Y86\pore[1] 

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


NEXT

Post a fresh HJT log and advise how your computer is running now and if there are any outstanding issues

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI