This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Antimalware Doctor infection

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
On startup my computer shows two popups that say that there are dll errors which are then followed by a number of antivirus popups telling me I need to be protected. IE redirects most websites. I can't run trend micro housecall or hijackthis in the regular mode. I am currently in safe mode. Norton internet security is installed but after a full scan in safe mode it is not able to delete 9 detections labeled as trojan horses or mystic!gen6.

Thanks for your help in advance.

Here is the Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:38:05 PM, on 12/27/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Compaq_Administrator.YOUR-4DACD0EA75\My Documents\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8074
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: C:\WINDOWS\system32\mbbn6pn5v.dll - {B2B220C1-A503-59BD-F413-01B53A2C8953} - C:\WINDOWS\system32\mbbn6pn5v.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [sxromcewan.tmp] "C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\sxromcewan.tmp"
O4 - HKLM\..\Run: [uPc+MV0NbOZJsiv] rundll32.exe C:\WINDOWS\system32\q1qgj28mh.dll, SystemServer
O4 - HKLM\..\Run: [HNULQKOXRqbPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\oq7cajl09.exe
O4 - HKLM\..\Run: [MKaZ] C:\WINDOWS\cmd.exe
O4 - HKLM\..\Run: [HNULQKOXRsPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\win16.exe
O4 - HKLM\..\Run: [MKdw+] C:\WINDOWS\nvsvc32.exe
O4 - HKLM\..\Run: [HNULQKOXRnsc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\drweb.exe
O4 - HKLM\..\Run: [HNULQKOXRssc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\winlogon.exe
O4 - HKLM\..\Run: [HNULQKOXRpw+] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\nvsvc32.exe
O4 - HKLM\..\Run: [HNULQKOXRpZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\mdm.exe
O4 - HKLM\..\Run: [HNULQKOXRnZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\cmd.exe
O4 - HKLM\..\Run: [Efakozececisuwa] rundll32.exe "C:\WINDOWS\omociwiq.dll",Startup
O4 - HKLM\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe
O4 - HKLM\..\Run: [MKWPwpc] C:\WINDOWS\TEMP\services.exe
O4 - HKLM\..\Run: [MKWPqe] C:\WINDOWS\TEMP\login.exe
O4 - HKLM\..\Run: [MKfPc] C:\WINDOWS\win32.exe
O4 - HKLM\..\Run: [MKZSc] C:\WINDOWS\avp32.exe
O4 - HKLM\..\Run: [HNULQKOXRrrb] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\taskmgr.exe
O4 - HKLM\..\Run: [HNULQKOXRnyc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\csrss.exe
O4 - HKLM\..\Run: [HNULQKOXRotc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\hexdump.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Rrefihepayuka] rundll32.exe "C:\WINDOWS\fcntmp.dll",Startup
O4 - HKCU\..\Run: [hiber70700conf.exe] C:\Documents and Settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\35ECFD20E47A01FC9173CD0CF37212D3\hiber70700conf.exe
O4 - HKCU\..\Run: [odkwhhap] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\krfbyvqyh\syiiasjlajb.exe
O4 - HKCU\..\Run: [uPc+MV0NbOZJsiv] rundll32.exe C:\WINDOWS\system32\q1qgj28mh.dll, SystemServer
O4 - HKCU\..\Run: [HNULQKOXRqbPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\oq7cajl09.exe
O4 - HKCU\..\Run: [MKaZ] C:\WINDOWS\cmd.exe
O4 - HKCU\..\Run: [HNULQKOXRsPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\win16.exe
O4 - HKCU\..\Run: [MKdw+] C:\WINDOWS\nvsvc32.exe
O4 - HKCU\..\Run: [HNULQKOXRnsc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\drweb.exe
O4 - HKCU\..\Run: [HNULQKOXRssc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\winlogon.exe
O4 - HKCU\..\Run: [HNULQKOXRpw+] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\nvsvc32.exe
O4 - HKCU\..\Run: [HNULQKOXRpZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\mdm.exe
O4 - HKCU\..\Run: [HNULQKOXRnZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\cmd.exe
O4 - HKCU\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe
O4 - HKCU\..\Run: [MKWPwpc] C:\WINDOWS\TEMP\services.exe
O4 - HKCU\..\Run: [MKWPqe] C:\WINDOWS\TEMP\login.exe
O4 - HKCU\..\Run: [MKfPc] C:\WINDOWS\win32.exe
O4 - HKCU\..\Run: [MKZSc] C:\WINDOWS\avp32.exe
O4 - HKCU\..\Run: [HNULQKOXRrrb] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\taskmgr.exe
O4 - HKCU\..\Run: [HNULQKOXRnyc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\csrss.exe
O4 - HKCU\..\Run: [HNULQKOXRotc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\hexdump.exe
O4 - HKUS\S-1-5-18\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MKWPwpc] C:\WINDOWS\TEMP\services.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MKWPqe] C:\WINDOWS\TEMP\login.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MKfPc] C:\WINDOWS\win32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Hewlett-Packard Recorder.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\FRU\Remind32.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 2.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: iwuiahf87sfy8ushfijsjgfgf - {B2B220C1-A503-59BD-F413-01B53A2C8953} - C:\WINDOWS\system32\mbbn6pn5v.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 11254 bytes
Posted Image

You have a badly infected computer that I don't know if it can be cleaned or not.


Please don't attach the scans / logs, use "copy/paste".


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Next:

Internet Explorer (Windows)
1. Click "Tools", then click "Internet Options". This will bring up the Internet Options window.

2. Click the "Connections" tab, then click the "LAN Settings" button.

3. Uncheck the box labeled "Use a proxy server for your LAN". Click "OK", and click "OK" in the previous window. This will remove the proxy server settings in Internet Explorer.



Firefox (Windows)
1. Click "Tools", then click "Options" to bring up the Options window.

2. Click the "Advanced" button, then click the "Network" tab.

3. Click the "Settings" button, located next to "Configure how Firefox connects to the Internet".

4. Click the radio button labeled "No proxy". Click "OK" twice. This will remove the proxy server settings in Firefox.

Next:

Disable Internet Explorer Proxy Settings and Reset TCP/IP and Winsock

Disable Internet Explorer Proxy Settings and Reset TCP/IP

It is very important that these steps be carried out exactly as shown otherwise the fix will not work.
If you have any questions please ask before moving on.
  • Please start Notepad and using your mouse make sure you select and copy all the information below in the Code box into your new document.
  • Then save the file as "fixme.bat" to your Desktop
  • In the drop down box for Save as type: make sure you select All Files (*.*) and keep the quotes on the name as well. Then close the new file.
    @ECHO OFF
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyServer /f
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyOverride /f
    reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyEnable  /t REG_DWORD /d 0 /f
    reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v GlobalUserOffline /t REG_DWORD /d 0 /f
    netsh int ip reset resetlog.txt
    netsh winsock reset catalog
  • On Windows XP you can double-click the file to run it.
  • On Vista/Win7 you need to Right click the file and choose Run as administrator to run it. With User Account Control on it should ask permission to run it. Click Yes
  • This will flash a black DOS box very quickly and go away, this is normal.
  • Restart your computer now.
  • Launch Internet Explorer and see if you can connect to the Internet.
  • Launch MBAM and check for Updates
Ok, I completed the tasks stated above. I did them in safe mode. I don't know if that was poblem After the restart, neither IE nor Firefox could connect to the internet and MBAM didn't run but gave two errors that read "Run time error '0'" and "Run time error '440' Automation Error". The Rundll errors are still popping up on startup and there are still antivirus 'software' popups. I restarted again then ran the fixme.bat again in normal mode. IE and Firefox then connected to the internet. This second time I ran the batch, however, the first two operations said that they couldn't find the registry key. MBAM gave the same two errors and did not run. Where do we go from here? Thanks.
Here's the new Hijackthis log. It is now able to run in normal mode (instead of only in safe mode).

Log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:57:25 AM, on 12/28/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DISC\DiscGui.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\35ECFD20E47A01FC9173CD0CF37212D3\hiber70700conf.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\FRU\Remind32.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Compaq_Administrator.YOUR-4DACD0EA75\My Documents\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: C:\WINDOWS\system32\mbbn6pn5v.dll - {B2B220C1-A503-59BD-F413-01B53A2C8953} - C:\WINDOWS\system32\mbbn6pn5v.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [sxromcewan.tmp] "C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\sxromcewan.tmp"
O4 - HKLM\..\Run: [uPc+MV0NbOZJsiv] rundll32.exe C:\WINDOWS\system32\q1qgj28mh.dll, SystemServer
O4 - HKLM\..\Run: [HNULQKOXRqbPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\oq7cajl09.exe
O4 - HKLM\..\Run: [MKaZ] C:\WINDOWS\cmd.exe
O4 - HKLM\..\Run: [HNULQKOXRsPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\win16.exe
O4 - HKLM\..\Run: [MKdw+] C:\WINDOWS\nvsvc32.exe
O4 - HKLM\..\Run: [HNULQKOXRnsc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\drweb.exe
O4 - HKLM\..\Run: [HNULQKOXRssc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\winlogon.exe
O4 - HKLM\..\Run: [HNULQKOXRpw+] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\nvsvc32.exe
O4 - HKLM\..\Run: [HNULQKOXRpZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\mdm.exe
O4 - HKLM\..\Run: [HNULQKOXRnZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\cmd.exe
O4 - HKLM\..\Run: [Efakozececisuwa] rundll32.exe "C:\WINDOWS\omociwiq.dll",Startup
O4 - HKLM\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe
O4 - HKLM\..\Run: [MKWPwpc] C:\WINDOWS\TEMP\services.exe
O4 - HKLM\..\Run: [MKWPqe] C:\WINDOWS\TEMP\login.exe
O4 - HKLM\..\Run: [MKfPc] C:\WINDOWS\win32.exe
O4 - HKLM\..\Run: [MKZSc] C:\WINDOWS\avp32.exe
O4 - HKLM\..\Run: [HNULQKOXRrrb] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\taskmgr.exe
O4 - HKLM\..\Run: [HNULQKOXRnyc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\csrss.exe
O4 - HKLM\..\Run: [HNULQKOXRotc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\hexdump.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Rrefihepayuka] rundll32.exe "C:\WINDOWS\fcntmp.dll",Startup
O4 - HKCU\..\Run: [hiber70700conf.exe] C:\Documents and Settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\35ECFD20E47A01FC9173CD0CF37212D3\hiber70700conf.exe
O4 - HKCU\..\Run: [odkwhhap] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\krfbyvqyh\syiiasjlajb.exe
O4 - HKCU\..\Run: [uPc+MV0NbOZJsiv] rundll32.exe C:\WINDOWS\system32\q1qgj28mh.dll, SystemServer
O4 - HKCU\..\Run: [HNULQKOXRqbPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\oq7cajl09.exe
O4 - HKCU\..\Run: [MKaZ] C:\WINDOWS\cmd.exe
O4 - HKCU\..\Run: [HNULQKOXRsPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\win16.exe
O4 - HKCU\..\Run: [MKdw+] C:\WINDOWS\nvsvc32.exe
O4 - HKCU\..\Run: [HNULQKOXRnsc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\drweb.exe
O4 - HKCU\..\Run: [HNULQKOXRssc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\winlogon.exe
O4 - HKCU\..\Run: [HNULQKOXRpw+] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\nvsvc32.exe
O4 - HKCU\..\Run: [HNULQKOXRpZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\mdm.exe
O4 - HKCU\..\Run: [HNULQKOXRnZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\cmd.exe
O4 - HKCU\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe
O4 - HKCU\..\Run: [MKWPwpc] C:\WINDOWS\TEMP\services.exe
O4 - HKCU\..\Run: [MKWPqe] C:\WINDOWS\TEMP\login.exe
O4 - HKCU\..\Run: [MKfPc] C:\WINDOWS\win32.exe
O4 - HKCU\..\Run: [MKZSc] C:\WINDOWS\avp32.exe
O4 - HKCU\..\Run: [HNULQKOXRrrb] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\taskmgr.exe
O4 - HKCU\..\Run: [HNULQKOXRnyc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\csrss.exe
O4 - HKCU\..\Run: [HNULQKOXRotc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\hexdump.exe
O4 - HKUS\S-1-5-18\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MKWPwpc] C:\WINDOWS\TEMP\services.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MKWPqe] C:\WINDOWS\TEMP\login.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MKfPc] C:\WINDOWS\win32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Hewlett-Packard Recorder.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\FRU\Remind32.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 2.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: iwuiahf87sfy8ushfijsjgfgf - {B2B220C1-A503-59BD-F413-01B53A2C8953} - C:\WINDOWS\system32\mbbn6pn5v.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 13602 bytes
Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Search Toolbar


1. All tools MUST be run from the executable. (.exe)
With Admin Rights (Right click on HijackTHis each time you use it, choose "Run as Administrator")




Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O2 - BHO: C:\WINDOWS\system32\mbbn6pn5v.dll - {B2B220C1-A503-59BD-F413-01B53A2C8953} - C:\WINDOWS\system32\mbbn6pn5v.dll (file missing)
O3 - Toolbar: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll
O4 - HKLM\..\Run: [sxromcewan.tmp] "C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\sxromcewan.tmp"
O4 - HKLM\..\Run: [uPc+MV0NbOZJsiv] rundll32.exe C:\WINDOWS\system32\q1qgj28mh.dll, SystemServer
O4 - HKLM\..\Run: [HNULQKOXRqbPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\oq7cajl09.exe
O4 - HKLM\..\Run: [MKaZ] C:\WINDOWS\cmd.exe
O4 - HKLM\..\Run: [HNULQKOXRsPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\win16.exe
O4 - HKLM\..\Run: [MKdw+] C:\WINDOWS\nvsvc32.exe
O4 - HKLM\..\Run: [HNULQKOXRnsc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\drweb.exe
O4 - HKLM\..\Run: [HNULQKOXRssc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\winlogon.exe
O4 - HKLM\..\Run: [HNULQKOXRpw+] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\nvsvc32.exe
O4 - HKLM\..\Run: [HNULQKOXRpZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\mdm.exe
O4 - HKLM\..\Run: [HNULQKOXRnZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\cmd.exe
O4 - HKLM\..\Run: [Efakozececisuwa] rundll32.exe "C:\WINDOWS\omociwiq.dll",Startup
O4 - HKLM\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe
O4 - HKLM\..\Run: [MKWPwpc] C:\WINDOWS\TEMP\services.exe
O4 - HKLM\..\Run: [MKWPqe] C:\WINDOWS\TEMP\login.exe
O4 - HKLM\..\Run: [MKfPc] C:\WINDOWS\win32.exe
O4 - HKLM\..\Run: [MKZSc] C:\WINDOWS\avp32.exe
O4 - HKLM\..\Run: [HNULQKOXRrrb] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\taskmgr.exe
O4 - HKLM\..\Run: [HNULQKOXRnyc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\csrss.exe
O4 - HKLM\..\Run: [HNULQKOXRotc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\hexdump.exe
O4 - HKCU\..\Run: [Rrefihepayuka] rundll32.exe "C:\WINDOWS\fcntmp.dll",Startup
O4 - HKCU\..\Run: [odkwhhap] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\krfbyvqyh\syiiasjlajb.exe
O4 - HKCU\..\Run: [uPc+MV0NbOZJsiv] rundll32.exe C:\WINDOWS\system32\q1qgj28mh.dll, SystemServer
O4 - HKCU\..\Run: [HNULQKOXRqbPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\oq7cajl09.exe
O4 - HKCU\..\Run: [MKaZ] C:\WINDOWS\cmd.exe
O4 - HKCU\..\Run: [HNULQKOXRsPc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\win16.exe
O4 - HKCU\..\Run: [MKdw+] C:\WINDOWS\nvsvc32.exe
O4 - HKCU\..\Run: [HNULQKOXRnsc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\drweb.exe
O4 - HKCU\..\Run: [HNULQKOXRssc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\winlogon.exe
O4 - HKCU\..\Run: [HNULQKOXRpw+] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\nvsvc32.exe
O4 - HKCU\..\Run: [HNULQKOXRpZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\mdm.exe
O4 - HKCU\..\Run: [HNULQKOXRnZ] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\cmd.exe
O4 - HKCU\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe
O4 - HKCU\..\Run: [MKWPwpc] C:\WINDOWS\TEMP\services.exe
O4 - HKCU\..\Run: [MKWPqe] C:\WINDOWS\TEMP\login.exe
O4 - HKCU\..\Run: [MKfPc] C:\WINDOWS\win32.exe
O4 - HKCU\..\Run: [MKZSc] C:\WINDOWS\avp32.exe
O4 - HKCU\..\Run: [HNULQKOXRrrb] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\taskmgr.exe
O4 - HKCU\..\Run: [HNULQKOXRnyc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\csrss.exe
O4 - HKCU\..\Run: [HNULQKOXRotc] C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\hexdump.exe
O4 - HKUS\S-1-5-18\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MKWPwpc] C:\WINDOWS\TEMP\services.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MKWPqe] C:\WINDOWS\TEMP\login.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MKfPc] C:\WINDOWS\win32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MKWPqg] C:\WINDOWS\TEMP\hexdump.exe (User 'Default user')

Close ALL windows and browsers except HijackThis and click "Fix checked"



Delete these Files if listed:
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\sxromcewan.tmp
C:\WINDOWS\system32\q1qgj28mh.dll
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\oq7cajl09.exe
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\win16.exe
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\drweb.exe
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\winlogon.exe
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\nvsvc32.exe
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\mdm.exe
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\cmd.exe
C:\WINDOWS\omociwiq.dll
C:\WINDOWS\TEMP\hexdump.exe
C:\WINDOWS\TEMP\services.exe
C:\WINDOWS\TEMP\login.exe
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\taskmgr.exe
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\csrss.exe
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\hexdump.exe
C:\WINDOWS\fcntmp.dll


Delete these files ONLY FROM THIS LOCATION if listed
C:\WINDOWS\cmd.exe
C:\WINDOWS\nvsvc32.exe
C:\WINDOWS\win32.exe
C:\WINDOWS\avp32.exe
C:\WINDOWS\win32.exe


DO NOT Delete these Folders. Delete only the FILES in these temp folders.
C:\WINDOWS\TEMP\
C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Before I do this. Norton Antivirus is giving me these popups saying that it found a Trojan.FakeAV!gen42 in this file. C:\Documents and Settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\35ECFD20E47A01FC9173CD0CF37212D3\hiber70700conf.exe I went to inspect said folder and in it there was icon identical to the antimalware doctor shortcut currently on my desktop as well as .txt and .bat files with instructions that were identical to the popups currently plagueing my computer. I also noticed that there is a RUN process with that exact file on my current Hijackthis log: O4 - HKCU\..\Run: [hiber70700conf.exe] C:\Documents and Settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\35ECFD20E47A01FC9173CD0CF37212D3\hiber70700conf.exe Should I just continue as outlined above or can this new info be taken into account as well?
I completed all the prescribed tasks. I couldn't find any of the files that were to be deleted "if listed". I hope that's a good thing.
Upon reboot, the computer gave no RUNDLL errors and none of the popups showed up. Norton Antivirus is giving me little status messages saying "a recent attack on your computer has been blocked" but that's about it. MBAM is still not running, giving me the same run time errors.
Here's the Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:25:10 PM, on 12/29/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
C:\Program Files\DISC\DiscGui.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\FRU\Remind32.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Compaq_Administrator.YOUR-4DACD0EA75\My Documents\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Efakozececisuwa] rundll32.exe "C:\WINDOWS\omociwiq.dll",Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Hewlett-Packard Recorder.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\FRU\Remind32.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 2.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: iwuiahf87sfy8ushfijsjgfgf - {B2B220C1-A503-59BD-F413-01B53A2C8953} - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 9679 bytes
Lets try combofix.

DO NOT use any TOOLS such as Combofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


Next:

Close all browsers before running ATF: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
I can't enable viewing of hidden files. There's no "folder options" option in the "tools" dropdown menu nor can I find it on the control panel…
Current computer behavior: no more antimalware doctor popups. There are still some browser redirections and a random RUNDLL error came up.

Here is the combofix log:

ComboFix 10-12-29.01 - Compaq_Administrator 12/29/2010 19:19:05.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.455 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security 2006 *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security 2006 *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\COMPAQ~1.YOU\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\All Users\Documents\Server\admin.txt
c:\documents and settings\All Users\Documents\Server\server.dat
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\35ECFD20E47A01FC9173CD0CF37212D3
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\35ECFD20E47A01FC9173CD0CF37212D3\enemies-names.txt
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\35ECFD20E47A01FC9173CD0CF37212D3\local.ini
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\35ECFD20E47A01FC9173CD0CF37212D3\lsrslt.ini
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\Microsoft\Internet Explorer\Quick Launch\Antimalware Doctor.lnk
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\{CA03FF91-B43B-4788-B9DA-D2D1199BF0C5}
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\{CA03FF91-B43B-4788-B9DA-D2D1199BF0C5}\chrome.manifest
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\{CA03FF91-B43B-4788-B9DA-D2D1199BF0C5}\chrome\content\_cfg.js
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\{CA03FF91-B43B-4788-B9DA-D2D1199BF0C5}\chrome\content\overlay.xul
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\{CA03FF91-B43B-4788-B9DA-D2D1199BF0C5}\install.rdf
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Local Settings\Temp\IadHide5.dll
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Start Menu\Antimalware Doctor.lnk
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Start Menu\Programs\Antimalware Doctor
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk
c:\documents and settings\Compaq_Administrator\Application Data\download2
c:\documents and settings\Compaq_Administrator\err.log
c:\documents and settings\Compaq_Administrator\GoToAssistDownloadHelper.exe
c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\{50E29D8A-961F-41F0-B404-A2FD905682AA}
c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\{50E29D8A-961F-41F0-B404-A2FD905682AA}\chrome.manifest
c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\{50E29D8A-961F-41F0-B404-A2FD905682AA}\chrome\content\_cfg.js
c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\{50E29D8A-961F-41F0-B404-A2FD905682AA}\chrome\content\overlay.xul
c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\{50E29D8A-961F-41F0-B404-A2FD905682AA}\install.rdf
c:\documents and settings\Compaq_Administrator\ResErrors.log
c:\program files\Common Files\Real\WeatherBug\MiniBugTransporter.dll
c:\program files\Common Files\System\Uninstall
c:\windows\izibemobelisuz.dll
c:\windows\MailSwitch.ocx
c:\windows\ocikaleg.dll
c:\windows\omociwiq.dll
c:\windows\onomisun.dll
c:\windows\oquhulal.dll
c:\windows\system32\Oeminfo.ini
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
c:\windows\ulejunehohiceki.dll
c:\windows\win16.exe
D:\Autorun.inf

Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\winlogon.exe

Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe

.
((((((((((((((((((((((((( Files Created from 2010-11-28 to 2010-12-30 )))))))))))))))))))))))))))))))
.

2010-12-29 22:52 . 2010-12-29 22:52 ——– d—–w- c:\windows\LastGood.Tmp
2010-12-27 19:37 . 2010-12-27 19:37 ——– d—–w- c:\windows\system32\LogFiles
2010-12-27 05:10 . 2010-12-30 00:28 758272 —-a-w- c:\windows\system32\drivers\azhjicc.sys
2010-12-20 18:24 . 2010-12-20 18:24 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\HP
2010-12-20 18:24 . 2010-12-20 18:24 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\IsolatedStorage
2010-12-20 18:24 . 2010-12-20 18:24 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\HP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2004-08-10 04:00 94784 –sh–w- c:\windows\twain.dll
2004-08-10 04:00 50688 –sh–w- c:\windows\twain_32.dll
2004-08-10 04:00 1028096 –sh–w- c:\windows\system32\mfc42.dll
2004-08-10 04:00 54784 –sh–w- c:\windows\system32\msvcirt.dll
2004-08-10 04:00 413696 –sh–w- c:\windows\system32\msvcp60.dll
2004-08-10 04:00 343040 –sh–w- c:\windows\system32\msvcrt.dll
2007-12-04 18:38 550912 –sh–w- c:\windows\system32\oleaut32.dll
2004-08-10 04:00 83456 –sh–w- c:\windows\system32\olepro32.dll
2004-08-10 04:00 11776 –sh–w- c:\windows\system32\regsvr32.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"DISCover"="c:\program files\DISC\DISCover.exe" [2005-11-12 1064960]
"DiscUpdateManager"="c:\program files\DISC\DiscUpdateMgr.exe" [2005-11-12 61440]
"DMAScheduler"="c:\program files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe" [2005-11-01 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-09-17 52848]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-10 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]

c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\
Hewlett-Packard Recorder.lnk - c:\program files\Hewlett-Packard\AiO\hp officejet 7100 series\FRU\Remind32.exe [2000-8-24 67584]
TrueAssistant.lnk - c:\program files\TrueSwitchEsaya\TrueWizard.exe [2009-9-24 1077248]

c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Start Menu\Programs\Startup\
Hewlett-Packard Recorder.lnk - c:\program files\Hewlett-Packard\AiO\hp officejet 7100 series\FRU\Remind32.exe [2000-8-24 67584]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - c:\program files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-2-22 36903]
HPAiODevice(hp officejet 7100 series) - 2.lnk - c:\program files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe [2002-11-23 495682]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [11/24/2010 3:01 AM 583640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/27/2010 1:01 AM 102448]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST
*Deregistered* - azhjicc
.
Contents of the 'Scheduled Tasks' folder

2010-12-25 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 12:18]

2010-12-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]

2010-12-24 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]

2010-12-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 01:26]

2010-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 01:26]

2010-12-25 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Compaq_Administrator.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2005-10-07 20:13]

2010-12-26 c:\windows\Tasks\RMSchedule.job
- c:\program files\Registry Mechanic\RegMech.exe [2010-11-24 16:46]

2010-12-29 c:\windows\Tasks\RMSmartUpdate.job
- c:\program files\Registry Mechanic\Update.exe [2010-11-24 16:46]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.foxnews.com/
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
Trusted Zone: trymedia.com
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-PCDrProfiler - (no file)
HKLM-Run-Efakozececisuwa - c:\windows\omociwiq.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-29 19:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\azhjicc]

.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(540)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3360)
c:\docume~1\COMPAQ~1.YOU\LOCALS~1\Temp\IadHide5.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\arservice.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\windows\ARPWRMSG.EXE
c:\windows\system32\rundll32.exe
c:\program files\DISC\DiscGui.exe
c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\eHome\ehmsas.exe
c:\progra~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
c:\program files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
c:\windows\system32\hpoipm07.exe
c:\program files\DISC\DiscStreamHub.exe
c:\program files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
c:\program files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
c:\program files\Symantec\LiveUpdate\AUpdate.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
.
**************************************************************************
.
Completion time: 2010-12-29 19:35:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-30 00:35

Pre-Run: 162,905,645,056 bytes free
Post-Run: 163,298,344,960 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - 3CA7BD587126799475AB05C02F118EE9
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::

File::
c:\windows\system32\drivers\azhjicc.sys

Driver::
azhjicc

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\azhjicc]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
I forgot to disable Norton Internet Security before running combofix, but when combofix prompted me about it I disabled it before it started running proper. Hope it didn't screw with anything.

The computer is running pretty smoothly. No popups and the browsers don't seem to be redirecting.

Here's the log:

ComboFix 10-12-29.01 - Compaq_Administrator 12/29/2010 23:21:10.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.448 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Desktop\CFScript.txt
AV: Norton Internet Security 2006 *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security 2006 *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

FILE ::
"c:\windows\system32\drivers\azhjicc.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\azhjicc.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_AZHJICC
——-\Service_azhjicc


((((((((((((((((((((((((( Files Created from 2010-11-28 to 2010-12-30 )))))))))))))))))))))))))))))))
.

2010-12-27 19:37 . 2010-12-27 19:37 ——– d—–w- c:\windows\system32\LogFiles
2010-12-20 18:24 . 2010-12-20 18:24 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Application Data\HP
2010-12-20 18:24 . 2010-12-20 18:24 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\IsolatedStorage
2010-12-20 18:24 . 2010-12-20 18:24 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\HP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2004-08-10 04:00 94784 –sh–w- c:\windows\twain.dll
2004-08-10 04:00 50688 –sh–w- c:\windows\twain_32.dll
2004-08-10 04:00 1028096 –sh–w- c:\windows\system32\mfc42.dll
2004-08-10 04:00 54784 –sh–w- c:\windows\system32\msvcirt.dll
2004-08-10 04:00 413696 –sh–w- c:\windows\system32\msvcp60.dll
2007-12-04 18:38 550912 –sh–w- c:\windows\system32\oleaut32.dll
2004-08-10 04:00 11776 –sh–w- c:\windows\system32\regsvr32.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"DISCover"="c:\program files\DISC\DISCover.exe" [2005-11-12 1064960]
"DiscUpdateManager"="c:\program files\DISC\DiscUpdateMgr.exe" [2005-11-12 61440]
"DMAScheduler"="c:\program files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe" [2005-11-01 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-09-17 52848]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-10 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]

c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\
Hewlett-Packard Recorder.lnk - c:\program files\Hewlett-Packard\AiO\hp officejet 7100 series\FRU\Remind32.exe [2000-8-24 67584]
TrueAssistant.lnk - c:\program files\TrueSwitchEsaya\TrueWizard.exe [2009-9-24 1077248]

c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75\Start Menu\Programs\Startup\
Hewlett-Packard Recorder.lnk - c:\program files\Hewlett-Packard\AiO\hp officejet 7100 series\FRU\Remind32.exe [2000-8-24 67584]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - c:\program files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-2-22 36903]
HPAiODevice(hp officejet 7100 series) - 2.lnk - c:\program files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe [2002-11-23 495682]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [11/24/2010 3:01 AM 583640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/27/2010 1:01 AM 102448]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder

2010-12-25 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 12:18]

2010-12-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]

2010-12-24 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]

2010-12-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 01:26]

2010-12-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 01:26]

2010-12-25 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Compaq_Administrator.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2005-10-07 20:13]

2010-12-26 c:\windows\Tasks\RMSchedule.job
- c:\program files\Registry Mechanic\RegMech.exe [2010-11-24 16:46]

2010-12-30 c:\windows\Tasks\RMSmartUpdate.job
- c:\program files\Registry Mechanic\Update.exe [2010-11-24 16:46]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.foxnews.com/
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
Trusted Zone: trymedia.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-29 23:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(508)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(1712)
c:\docume~1\COMPAQ~1.YOU\LOCALS~1\Temp\IadHide5.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\arservice.exe
c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\progra~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\hpoipm07.exe
c:\program files\DISC\DiscStreamHub.exe
c:\program files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
c:\program files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
c:\program files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
c:\program files\Symantec\LiveUpdate\AUpdate.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2010-12-29 23:38:07 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-30 04:38
ComboFix2.txt 2010-12-30 00:35

Pre-Run: 163,217,227,776 bytes free
Post-Run: 163,155,865,600 bytes free

- - End Of File - - 133CCC059681AF360ECF0D67F08903B2

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI